Instiq

4Develop a Security and Compliance Plan

Practice questions →Glossary →
  • 4.1Integrating Security into Pipelines (DevSecOps)

    Understand shifting security left—SAST/DAST, dependency scanning, container image scanning, IaC scanning, and GitHub Advanced Security. Detect vulnerabilities early in the pipeline.

  • 4.2Managing Secrets and Credentials

    Understand handling secrets safely—Key Vault, variable groups/secret variables, managed identity/workload identity federation, secret scanning, and least privilege. Prevent credential leakage.

  • 4.3Compliance and Governance

    Understand control and trails—approvals/audit logs, Azure Policy, environment protection (checks), license/compliance management, and separation of duties. Meet regulatory requirements while shipping fast.