Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global software development company is adopting a DevSecOps approach within its Zero Trust architecture. They use GitHub for source code management and Azure DevOps for CI/CD pipelines. The security team needs to integrate security testing early and continuously into the development lifecycle to identify vulnerabilities in both custom code and deployed applications before they reach production. Which two types of security testing are crucial for implementing this strategy?

  1. AStatic Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
  2. BNetwork Vulnerability Scanning and Penetration Testing
  3. CPenetration Testing and Red Teaming
  4. DUser Acceptance Testing (UAT) and Performance Testing
Show answer & explanation

Correct answer: A. Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)

SAST analyzes source code for vulnerabilities during development (shift left), while DAST tests running applications for vulnerabilities, often during staging or QA. Together, they provide comprehensive application security testing crucial for a DevSecOps Zero Trust strategy.

Why the other options are wrong

  • B. Network Vulnerability Scanning focuses on infrastructure, not application code or runtime vulnerabilities, and penetration testing is typically less frequent than continuous DevSecOps testing.
  • C. Penetration Testing and Red Teaming are typically performed later in the lifecycle or after deployment, not continuously and early in the DevSecOps pipeline for all code.
  • D. UAT and Performance Testing are functional and non-functional testing types, not primarily security testing.

Static Application Security Testing (SAST) & Dynamic Application Security Testing (DAST)

SAST analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the code. DAST analyzes the running application for vulnerabilities by attacking it from the outside.

  • SAST: 'Shift left' security, identifies vulnerabilities early in development.
  • DAST: Tests applications in their running state, identifies runtime vulnerabilities.
  • Together, they provide comprehensive coverage for application security in DevSecOps.

Memory trick: SAST/DAST: 'Static And Dynamic Security Tools', catch bugs early and live.

More Design a Zero Trust strategy and architecture questions