ExamGecko
Question list
Search
Search

List of questions

Search

Question 165 - CCAK discussion

Report
Export

From the perspective of a senior cloud security audit practitioner in an organization with a mature security program and cloud adoption, which of the following statements BEST describes the DevSecOps concept?

A.

Process of security integration using automation in software development

Answers
A.

Process of security integration using automation in software development

B.

Operational framework that promotes software consistency through automation

Answers
B.

Operational framework that promotes software consistency through automation

C.

Development standards for addressing integration, testing, and deployment issues

Answers
C.

Development standards for addressing integration, testing, and deployment issues

D.

Making software development simpler, faster, and easier using automation

Answers
D.

Making software development simpler, faster, and easier using automation

Suggested answer: A

Explanation:

DevSecOps is an approach that integrates security practices into every phase of the software development lifecycle. It emphasizes the incorporation of security from the beginning, rather than as an afterthought, and utilizes automation to ensure security measures are consistently applied throughout the development process. This method allows for early detection and resolution of security issues, making it an essential practice for organizations with mature security programs and cloud adoption.

Reference The definition and best practices of DevSecOps are well-documented in resources provided by leading industry authorities such as Microsoft1and IBM2, which describe DevSecOps as a framework that automates the integration of security into the software development lifecycle.

asked 17/11/2024
Andrew Carver
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first