Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy
A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security team wants to integrate security best practices directly into the DevOps pipeline, ensuring that security vulnerabilities are identified and remediated early in the development process, before deployment to production. This includes scanning code for vulnerabilities, checking for misconfigurations in infrastructure-as-code (IaC) templates, and scanning container images for known weaknesses. Which Microsoft Defender for Cloud capability should the architect recommend to achieve this 'shift-left' security approach in Azure DevOps?
- AMicrosoft Defender for Cloud - SQL
- BMicrosoft Defender for Cloud - DevOps Security
- CMicrosoft Defender for Cloud - Servers
- DMicrosoft Defender for Cloud - Key Vault
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Defender for Cloud - DevOps Security
Microsoft Defender for Cloud - DevOps Security is specifically designed to integrate security into the development process. It provides capabilities for scanning code, IaC, and container images within Azure DevOps pipelines, enabling 'shift-left' security by identifying and remediating vulnerabilities early.
Why the other options are wrong
- A. Microsoft Defender for Cloud - SQL protects Azure SQL databases and SQL Servers on machines, focusing on database security at runtime, not CI/CD pipeline security.
- C. Microsoft Defender for Cloud - Servers protects virtual machines and physical servers, focusing on runtime protection, not 'shift-left' security in the DevOps pipeline.
- D. Microsoft Defender for Cloud - Key Vault protects Azure Key Vault resources, focusing on secrets management security, not code or pipeline security.
Microsoft Defender for Cloud - DevOps Security
A capability within Microsoft Defender for Cloud that integrates security into the development process, enabling 'shift-left' security by scanning code, infrastructure-as-code, and container images within CI/CD pipelines.
- Identifies vulnerabilities early in the SDLC.
- Integrates with Azure DevOps and GitHub.
- Scans source code, IaC templates, and container images.
Memory trick: Defender for DevOps acts like a security guard for your code, catching problems before they even leave the building.