Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
During the 'testing' phase of the Cloud Application Development Lifecycle, a security architect wants to integrate automated checks to identify common security vulnerabilities in the application's code and dependencies before deployment. Which of the following security practices is most suitable for this purpose within a CI/CD pipeline?
- ADynamic Application Security Testing (DAST).
- BRuntime Application Self-Protection (RASP).
- CPenetration testing by an external security firm.
- DSoftware Composition Analysis (SCA).
Show answer & explanationAnswer & explanation
Correct answer: D. Software Composition Analysis (SCA).
Software Composition Analysis (SCA) specifically focuses on identifying known vulnerabilities in third-party libraries and open-source components used by an application. This is crucial for automated checks in a CI/CD pipeline during the testing phase, as many applications rely heavily on external dependencies.
Why the other options are wrong
- A. DAST tests a running application from the outside, identifying runtime vulnerabilities, but doesn't focus on code or dependency vulnerabilities directly in the code/build phase.
- B. RASP protects a running application by instrumenting it to detect and block attacks in real-time; it's a runtime protection mechanism, not a testing tool for code/dependencies.
- C. Penetration testing is a manual, in-depth process typically performed later in the lifecycle or periodically, not for automated checks in a CI/CD pipeline.
Software Composition Analysis (SCA)
SCA is an automated process that identifies and inventories open-source and third-party components in a codebase and checks for known vulnerabilities in those components.
- Focuses on dependencies, not custom code.
- Integrated into CI/CD pipelines.
- Helps manage supply chain security risks.
Memory trick: SCA checks software components for problems.