Q: 20
HOTSPOT You need to recommend a security methodology for a DevOps development process based on the Microsoft Cloud Adoption Framework for Azure. During which stage of a continuous integration and continuous deployment (CI/CD) DevOps process should each security-related task be performed? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point
Your Answer
Discussion
Threat modeling fits in plan and develop, DAST should happen in build and test, actionable intelligence lines up with operate. That's how the CAF for Azure maps it. Pretty sure this is how MS expects it to be sequenced.
Plan and develop for threat modeling, build and test for DAST, operate for actionable intelligence. Saw a similar scenario in some practice sets.
Be respectful. No spam.
