A retail company migrates its customer-facing web application to a cloud environment. The security team wants to ensure that security testing is integrated throughout the software development lifecycle (SDLC) rather than only before production deployment. Which approach best aligns with this goal?
A DevSecOps approach integrates security automatically into every stage of the CI/CD pipeline, enabling early detection and remediation of vulnerabilities. This aligns with the goal of continuous security testing throughout the SDLC. Automated tools like SAST, DAST, and dependency scanning run with each build, providing rapid feedback to developers. This reduces risk and cost compared to late-stage testing, and fosters a security-first culture.
Why this answer
Integrating security testing into the CI/CD pipeline through a DevSecOps approach ensures that vulnerabilities are identified and addressed continuously as code is developed and deployed. This shifts security left, reduces remediation costs, and aligns with modern cloud application security best practices. Other options either delay testing or rely solely on human training, which does not provide the continuous automated assurance required.
Exam trap
The trap here is assuming that periodic security gates or annual training are sufficient for continuous security, when the goal requires automated, integrated testing throughout the SDLC.