🔥 3-day streak
Cisco CCNP Security SCOR (350-701)27 / 146
Question 27 of 146
A DevSecOps team deploys cloud infrastructure using Terraform templates through their CI/CD pipeline. During a recent audit, several production storage buckets were found configured with public read access, and a security group was discovered allowing SSH (TCP 22) from 0.0.0.0/0. The team wants to catch these misconfigurations automatically before resources are ever provisioned, without waiting for a running-environment posture scan. Which practice should they add to the pipeline?
Reviewed for accuracy · Report an issueNext question