A financial institution is implementing a new CI/CD pipeline for its critical applications. The security team mandates that all code changes must undergo static application security testing (SAST) before being deployed to production. The pipeline uses AWS CodeCommit for source control, AWS CodeBuild for building, and AWS CodeDeploy for deployment. How can the DevOps team integrate SAST into this pipeline to meet the security requirement?
- AUtilize AWS WAF to inspect traffic to the application and block requests that exploit known vulnerabilities.
- BConfigure AWS Config rules to monitor deployed resources for security compliance post-deployment.
- CAdd a build step in AWS CodeBuild that invokes a SAST tool and configure it to fail the build if vulnerabilities are found.
- DImplement a Lambda function triggered by CodeCommit pushes to scan the code and notify the security team.
Show answer & explanationAnswer & explanation
Correct answer: C. Add a build step in AWS CodeBuild that invokes a SAST tool and configure it to fail the build if vulnerabilities are found.
Integrating SAST into the CodeBuild phase allows for automated security analysis of the code during the build process, directly aligning with the requirement to perform testing BEFORE deployment to production. Failing the build on vulnerabilities prevents insecure code from progressing.
Why the other options are wrong
- A. AWS WAF provides runtime protection against web exploits and is not a SAST tool; it operates post-deployment and focuses on network traffic, not source code analysis.
- B. AWS Config monitors resource compliance POST-deployment and is not a SAST tool; it ensures deployed resources adhere to security policies, not that the source code itself is secure prior to deployment.
- D. A Lambda function triggered by CodeCommit could scan code, but it would typically run asynchronously and might not directly prevent deployment without additional integration into the pipeline's pass/fail criteria.
SAST in CI/CD
Static Application Security Testing (SAST) integrated into a Continuous Integration/Continuous Delivery (CI/CD) pipeline involves analyzing application source code, bytecode, or binary code for security vulnerabilities without executing the code.
- Identifies vulnerabilities early in the development lifecycle.
- Performed on non-running code.
- Can be automated within build or test stages of a pipeline.
Memory trick: Build Secure, Deploy Secure: SAST finds flaws before they fly.