ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityHard

A company is developing a new cloud-native application that will handle sensitive customer data. They want to ensure that the application's runtime environment is constantly monitored for security policy violations and anomalous behavior. Which security control is best suited for this requirement?

  1. AIntegrating SAST into the CI/CD pipeline.
  2. BUtilizing Runtime Application Self-Protection (RASP).
  3. CConducting periodic penetration tests.
  4. DImplementing a robust vulnerability management program.
Show answer & explanation

Correct answer: B. Utilizing Runtime Application Self-Protection (RASP).

Runtime Application Self-Protection (RASP) directly addresses the requirement of monitoring and protecting the application's runtime environment from security policy violations and anomalous behavior. RASP instruments the application itself to detect and block attacks in real-time.

Why the other options are wrong

  • A. SAST is for compile-time code analysis, not runtime monitoring.
  • C. Penetration tests are point-in-time assessments, not continuous runtime monitoring and protection.
  • D. Vulnerability management identifies and remediates flaws but doesn't provide real-time runtime protection against active attacks or policy violations.

Runtime Application Self-Protection (RASP)

A security technology that is integrated into an application or its runtime environment to detect and block attacks in real-time from within the application itself.

  • Protects applications during execution
  • Detects and blocks attacks from within
  • Provides real-time visibility and defense

Memory trick: RASP protects the app while it runs, blocking attacks before they're done.

More Software Development Security questions