🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 13 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization is containerizing a payroll application and deploying it to Amazon ECS through a CI/CD workflow that uses CodeCommit for source control, CodeBuild for builds, and CodeDeploy for releases. As the SSCP responsible for secure development practices, which action should you recommend to embed security early in the lifecycle, minimize cost, and prevent vulnerable code from ever reaching any runtime environment?

  • Hire an external firm to perform authenticated penetration tests against production on a quarterly schedule.

  • Require the security team to conduct manual code reviews only after the application is deployed to the staging environment.

  • Add an automated SAST job to the CodeBuild stage that scans every pull request before it is merged.

  • Enable AWS WAF with managed rule groups on the production Application Load Balancer after the first release.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot