Skip to content
CAS-005
Security Architecture
medium
Question 13 of 27

An organization is migrating workloads to a public cloud. The security team wants to ensure that infrastructure changes are reviewed for security misconfigurations before they reach production. Which approach integrates security checks directly into the CI/CD pipeline?

APerform monthly penetration tests against production cloud workloads
BIntegrate infrastructure-as-code (IaC) security scanning into the CI/CD pipeline
CConfigure the cloud provider's native WAF on all production endpoints
DDeploy a CASB to monitor all developer activity

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion