← All SAFe® 5 DevOps Certification Flashcard Decks

SAFe 5 DevOps Security and Compliance Flashcards

6 cards from real SAFe® 5 DevOps Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 SAFe 5 DevOps Security and Compliance flashcards as text
  1. What does DevSecOps mean in the SAFe framework?

    Answer: Integrating security practices throughout the entire DevOps pipeline rather than as a separate phase

    DevSecOps integrates security throughout the development lifecycle — from design through deployment — making security a shared responsibility embedded in every pipeline stage rather than a gate at the end.

  2. What is shift-left security in the context of SAFe DevOps?

    Answer: Moving security testing and considerations earlier in the development lifecycle

    Shift-left security means incorporating security practices (static analysis, dependency scanning, threat modeling) early in the development process, catching vulnerabilities when they're cheaper and easier to fix.

  3. What is the purpose of static application security testing (SAST) in the CI/CD pipeline?

    Answer: To analyze source code for security vulnerabilities without executing the application

    SAST tools analyze source code, bytecode, or binary code to identify security vulnerabilities (SQL injection, XSS, buffer overflows) without running the application, enabling early detection during development.

  4. How should secrets management be handled in a DevOps pipeline?

    Answer: Using dedicated secrets management tools (Vault, AWS Secrets Manager) with encrypted storage and access controls

    Secrets (passwords, API keys, certificates) should be managed through dedicated tools that provide encrypted storage, access control, audit logging, automatic rotation, and dynamic secret generation.

  5. What is compliance as code in SAFe DevOps?

    Answer: Automating compliance verification through code that enforces policies and generates audit evidence

    Compliance as code automates the verification and enforcement of regulatory and organizational policies through executable code, automated tests, and continuous monitoring, producing auditable evidence at every pipeline stage.

  6. What is the role of container scanning in DevSecOps?

    Answer: Analyzing container images for known vulnerabilities, malware, and misconfigurations before deployment

    Container scanning examines container images and their layers for known CVEs, outdated packages, embedded secrets, and configuration issues before they are deployed to production environments.