A financial services company is transitioning to a DevSecOps model to accelerate its software delivery. The Chief Information Security Officer (CISO) is concerned about introducing new risks and has been asked to recommend the single most effective strategy for securing the new CI/CD pipeline from end to end. The goal is to catch vulnerabilities as early as possible without impeding development velocity. Which of the following approaches BEST meets the CISO's objective?
Enforcing code signing with hardware security modules before artifact deployment
Isolating the build environment with ephemeral VMs
Automated security testing integrated at multiple stages of the pipeline
Implementing container image scanning and storing results in a tamper-evident database
The correct answer is automated security testing integrated at multiple stages of the pipeline. This approach ensures that security testing is performed consistently and frequently throughout the development process, allowing potential security issues to be identified and addressed early. Automation enables these checks to be performed on every code change without slowing down development.
Implementing container image scanning and storing results in a tamper-evident database is a valuable security practice but focuses on only one aspect of CI/CD security. While container scanning helps identify vulnerabilities in container images, it doesn't address other security concerns such as insecure configurations, secrets management, or application-level vulnerabilities across the entire pipeline.
Enforcing code signing with hardware security modules before artifact deployment ensures code integrity but represents just one security aspect of the CI/CD pipeline. Code signing verifies that code hasn't been tampered with but doesn't identify inherent vulnerabilities or insecure coding practices that might exist in properly signed code.
Isolating the build environment with ephemeral VMs provides good security isolation but addresses only the build environment aspect of CI/CD security. While this approach helps prevent persistent compromises of build systems, it doesn't implement security checks throughout the pipeline to identify vulnerabilities in the code being built and deployed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is automated security testing in CI/CD pipelines?
Open an interactive chat with Bash
Why is automated security testing more effective than container image scanning?
Open an interactive chat with Bash
What tools can be used for automated security testing in CI/CD pipelines?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .