nerdexam
Isaca

CCAK · Question #34

Which of the following would be a logical starting point for an auditor who has been engaged to assess the security of an organization's DevOps pipeline?

The correct answer is C. Review the CI/CD pipeline audit logs. improve-business-value-10e81a2a6fd5

Cloud Security Auditing

Question

Which of the following would be a logical starting point for an auditor who has been engaged to assess the security of an organization's DevOps pipeline?

Options

  • AVerify the inclusion of security gates in the pipeline.
  • BConduct an architectural assessment.
  • CReview the CI/CD pipeline audit logs.
  • DVerify separation of development and production pipelines.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    80% (20)
  • D
    12% (3)

Explanation

improve-business-value-10e81a2a6fd5

Topics

#DevOps security auditing#CI/CD pipeline security#Audit evidence#Audit methodology

Community Discussion

No community discussion yet for this question.

Full CCAK Practice