Graduate Capstone Task 2
CI/CD Pipeline Security for Cloud-Native Applications in AWS
140 Questions with Complete Solutions
DevSecOps, AWS Security, IaC, Containers, Supply Chain, & Incident Response
2026/2027 Update with Complete Solution
Western Governors University
Master of Science, Cybersecurity and Information Assurance (MSCIA)
D490 Capstone Task 2 — Cloud-Native Application Security
8 Sections · AWS DevSecOps & Cloud Security
TOTAL QUESTIONS 140
SECTIONS 8
FORMAT Multiple Choice (A-D) with Complete Solutions
COGNITIVE LEVELS 25% Recall / 50% Application / 25% Analysis
STYLE 75% Scenario-Based / 25% Direct Recall
CONTENT 2026/2027 Updated AWS Security, SLSA, DevSecOps
This comprehensive test bank covers the WGU D490 MSCIA Capstone Task 2 competencies for CI/CD pipeline security
in AWS cloud-native applications. Content includes DevSecOps principles, AWS security foundations (IAM, VPC,
Well-Architected Framework), pipeline security controls (SAST, secret scanning, artifact signing), Infrastructure as Code
security (Terraform, CloudFormation, Policy as Code), container and serverless security (ECS/EKS, Lambda), supply
chain security (SBOM, SLSA, Sigstore), monitoring and incident response (GuardDuty, Security Hub), and capstone
documentation. Each question includes detailed rationales with AWS service capabilities, security control principles,
WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 1
140 Questions | 2026/2027 Update | Complete Solutions
, pipeline stage requirements, and integration best practices.
WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 2
140 Questions | 2026/2027 Update | Complete Solutions
, Table of Contents
Section 1: CI/CD Fundamentals and DevSecOps Principles
Pipeline Stages, Continuous Integration/Delivery/Deployment, & Shift-Left Security
Q1-Q22
Section 2: AWS Cloud-Native Architecture and Security Foundations
Shared Responsibility Model, IAM, VPC, & Well-Architected Framework
Q23-Q45
Section 3: CI/CD Pipeline Security Controls
Source Code Security, Build Security, Artifact Security, & Deployment Security
Q46-Q70
Section 4: Infrastructure as Code (IaC) Security
Terraform, CloudFormation, Policy as Code, & Drift Detection
Q71-Q90
Section 5: Container and Serverless Security
Docker, ECS/EKS, Lambda, Container Scanning, & Runtime Protection
Q91-Q110
Section 6: Supply Chain Security and Software Composition Analysis
SBOM, Dependency Scanning, & Third-Party Risk
Q111-Q125
Section 7: Monitoring, Detection, and Incident Response in CI/CD
CloudWatch, GuardDuty, Security Hub, & Automated Remediation
Q126-Q135
Section 8: Capstone Documentation and Professional Practice
Architecture Diagrams, Risk Assessment, & Stakeholder Communication
Q136-Q140
Note: All 140 questions are sequentially numbered Q1 through Q140 with detailed rationales including CI/CD
security reasoning, AWS service capabilities, security control principles, pipeline stage requirements, and
integration best practices aligned with the 2026/2027 WGU D490 MSCIA Capstone Task 2 requirements.
WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 3
140 Questions | 2026/2027 Update | Complete Solutions
, Section 1: CI/CD Fundamentals and DevSecOps Principles
Pipeline Stages, Continuous Integration/Delivery/Deployment, & Shift-Left Security
Q1-Q22
Q1: A DevSecOps team designs a pipeline where every change that passes automated tests is
automatically released to production with no human approval. Which deployment model does this
describe?
A. Continuous Integration
B. Continuous Delivery
C. Continuous Deployment [CORRECT]
D. Continuous Inspection
Correct Answer: C
Rationale: Continuous Deployment automatically releases every change that passes automated tests to
production without a manual approval gate. Continuous Delivery also automates the pipeline but stops at
a manual approval gate before production. Continuous Integration focuses on frequent merging and
automated builds, not deployment, and Continuous Inspection is not a recognized deployment model.
Q2: A security engineer wants to reduce the cost of fixing vulnerabilities by detecting them earlier in
the development lifecycle. Which practice directly supports this goal?
A. Shift-right testing in production
B. Shift-left security in the SDLC [CORRECT]
C. Runtime patching after deployment
D. Annual penetration testing only
Correct Answer: B
Rationale: Shift-left security integrates controls earlier in the SDLC where vulnerabilities are cheaper
and easier to fix before code is built or deployed. Shift-right testing emphasizes production observability
and runtime protection, which occurs too late to reduce remediation cost. Runtime patching and annual
penetration testing are reactive controls that do not catch issues during development.
Q3: A team must detect SQL injection flaws in source code before it is compiled. Which testing
approach should be applied?
A. Dynamic Application Security Testing (DAST)
B. Runtime Application Self-Protection (RASP)
C. Static Application Security Testing (SAST) [CORRECT]
D. Interactive Application Security Testing (IAST)
Correct Answer: C
Rationale: SAST analyzes source code without executing it, making it ideal for finding injection flaws
before compilation. DAST tests a running application from the outside and cannot inspect source code
directly. IAST combines static and dynamic techniques but requires instrumented runtime execution, and
RASP blocks attacks in production rather than scanning code.
WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 4
140 Questions | 2026/2027 Update | Complete Solutions