Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A global software development company uses GitHub for source code management and Azure DevOps for CI/CD pipelines. They are implementing a Zero Trust strategy and need to ensure that all code pushed to repositories is scanned for secrets, vulnerabilities, and misconfigurations before it can be integrated into the main branch. This scanning must be automated and integrated directly into the development workflow. Which type of security control is essential for implementing this continuous security validation in the DevOps pipeline?

  1. APrivileged Identity Management (PIM) for GitHub administrators
  2. BEndpoint Detection and Response (EDR) on developer workstations
  3. CNetwork Security Groups (NSGs) for Azure DevOps agents
  4. DStatic Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
Show answer & explanation

Correct answer: D. Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)

Static Application Security Testing (SAST) analyzes application source code, bytecode, or binary code for security vulnerabilities, secrets, and misconfigurations without executing the application. Dynamic Application Security Testing (DAST) analyzes applications in their running state. Integrating both SAST and DAST into the CI/CD pipeline ensures continuous security validation of code before it reaches production, aligning with Zero Trust for applications.

Why the other options are wrong

  • A. PIM for GitHub administrators manages elevated access for specific roles but does not directly implement code scanning for vulnerabilities.
  • B. EDR on developer workstations protects the endpoints but doesn't specifically scan code within the repository or pipeline for vulnerabilities and secrets.
  • C. Network Security Groups (NSGs) control network traffic to Azure resources and are not used for scanning source code for vulnerabilities or secrets within a CI/CD pipeline.

SAST and DAST (DevSecOps Zero Trust)

Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) are crucial for implementing Zero Trust in DevSecOps. SAST analyzes code for vulnerabilities and secrets before execution, while DAST tests running applications for security flaws. Integrating both into CI/CD pipelines ensures continuous security validation of applications throughout their lifecycle.

  • SAST: Scans code before execution
  • DAST: Tests running applications
  • Integrated into CI/CD pipelines
  • Continuous security validation for applications

Memory trick: Don't trust the code until SAST and DAST give it the all-clear.

More Design a Zero Trust strategy and architecture questions