Certified Cloud Security Professional (CCSP)Cloud Security OperationsHard
A cloud security architect is tasked with ensuring the continuous security of a highly dynamic microservices architecture deployed on a Kubernetes cluster in a public cloud. Given the ephemeral nature of containers and the frequent deployments, which security monitoring approach is most effective for identifying runtime anomalies and policy violations?
- APeriodic vulnerability scanning of container images.
- BHost-based intrusion detection systems (HIDS) on worker nodes.
- CRuntime application self-protection (RASP) integrated into microservices.
- DStatic Application Security Testing (SAST) in the CI/CD pipeline.
Show answer & explanationAnswer & explanation
Correct answer: C. Runtime application self-protection (RASP) integrated into microservices.
RASP provides continuous, real-time protection by instrumenting the application itself, detecting and blocking attacks from within the application at runtime, which is crucial for dynamic, ephemeral microservices.
Why the other options are wrong
- A. Periodic vulnerability scanning of images identifies issues before deployment but doesn't detect runtime anomalies or attacks against running services.
- B. HIDS on worker nodes monitors the underlying host and might not have deep visibility into the specific behavior and policy violations within individual containers or microservices.
- D. SAST analyzes code during development (static analysis) and doesn't provide runtime protection or anomaly detection.
Runtime Application Self-Protection (RASP)
A security technology that integrates into an application's runtime environment, continuously monitoring its execution and detecting/blocking attacks in real-time from within the application itself.
- Provides immediate, in-application protection.
- Effective against zero-day attacks and sophisticated threats.
- Low false-positive rates due to deep context of application logic.
Memory trick: RASP is like a bodyguard *inside* the application, always watching.