350-201 exam dumps

350-201 practice question 87 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 87

Select 3

Your organization is adopting a DevSecOps approach to integrate security into the software development lifecycle. As a cybersecurity engineer, you are tasked with recommending practices to enhance security within the CI/CD pipeline. Which of the following recommendations align with DevSecOps principles?

  1. A

    Implement automated security testing as part of the CI/CD pipeline.

  2. B

    Perform manual security assessments only after deployment to production.

  3. C

    Use Infrastructure as Code (IaC) to enforce security baselines.

  4. D

    Ensure security tools are integrated early in the development lifecycle.

  5. E

    Restrict collaboration between development, operations, and security teams to minimize risks.

Show answer and explanation

Correct answers: A, C, D

Explanation

DevSecOps emphasizes integrating security throughout the software development lifecycle, promoting automation, collaboration across teams, and early detection of vulnerabilities. Automated security testing, IaC for security baselines, and early integration of security tools are fundamental practices. Delayed manual assessments and restricting collaboration go against these principles.

  • A. Correct.

    Automated security testing is a key DevSecOps practice to continuously identify vulnerabilities as part of the CI/CD process.

  • B. Incorrect.

    Manual security assessments after deployment do not align with DevSecOps principles, as they delay security feedback and introduce risks.

  • C. Correct.

    Using Infrastructure as Code (IaC) to enforce security baselines improves consistency and ensures secure configurations are applied automatically.

  • D. Correct.

    Integrating security tools early in the development lifecycle aligns with the 'shift-left' principle of DevSecOps, enabling faster detection and remediation of vulnerabilities.

  • E. Incorrect.

    Restricting collaboration contradicts core DevSecOps principles, which emphasize cross-team communication and shared responsibility for security.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam