A cloud security team is implementing a DevSecOps pipeline. Which TWO of the following are examples of shift-left security practices? (Select two.)
IaC scanning catches misconfigurations before resources are created.
Why this answer
Shift-left integrates security early in the SDLC. IaC scanning and SAST are performed before deployment, while DAST and RASP are later stages, and threat modeling is also early but not listed as a tool.