A cloud security team is implementing a DevSecOps pipeline. Which TWO of the following are examples of shift-left security practices? (Select two.)
Scanning Infrastructure as Code with Checkov before deployment catches misconfigurations at the source, satisfying the shift-left requirement to detect flaws before resources reach production. Checkov statically analyses Terraform, CloudFormation and Kubernetes manifests, so defects are remediated in version control rather than after provisioning, when fixes cost more and expose live environments.
Why this answer
Shift-left security means moving security activities earlier in the software development lifecycle, before code reaches production. Option B is correct because scanning Infrastructure as Code with Checkov before deployment catches misconfigurations in Terraform, CloudFormation, or Kubernetes manifests at the earliest possible stage, preventing insecure infrastructure from ever being provisioned. Option D is correct because running SAST during code commit analyzes source code for vulnerabilities like injection flaws or insecure patterns as developers write it, giving immediate feedback before the code is merged or built.
Option A is not shift-left because penetration testing after deployment is a late-stage, post-release activity. Option C is not shift-left because DAST tests a running application, which occurs after the code is deployed to a test or staging environment. Option E is not shift-left because RASP operates at runtime in production, protecting the application only after it is live.
Exam trap
CCSP often tests whether candidates can distinguish 'shift-left' (pre-deployment, code/IaC analysis) from 'shift-right' (runtime, production monitoring) — DAST and RASP are the classic distractors.