• Post category:StudyBullet-7
  • Reading time:6 mins read


This course helps to implement DevSecOps in Google Cloud and integrates SAST, SCA security tools

What you will learn

Learn DevSecOps implementation with GCP

Learn SAST Integration with GCP

Learn SCA Integration with GCP

Learn False Positive Analysis of Security Issues

Learn GCP Cloud Build and trigger creation in it

Learn about moving tokens from YAML file to pipeline variables

Learn to integrate Sonar and Snyk in GCP Cloud Build

Description

This “DevSecOps in Google Cloud Platform” course is designed for Security Engineers, DevOps Engineers, SRE, QA Professionals and Freshers looking to find a job in the field of security. This is a focused GCP DevSecOps course with a special focus on integrating SAST/SCA tools in Build pipeline.

Learn and implement security in DevOps pipeline, get Hands On experience in using Security tools & technologies.

This course is for:

  • Developers
  • DevOps
  • Security Engineers
  • Aspiring professional in the Security domain
  • Quality Assurance Engineers
  • InfoSec/AppSec Professional

DevSecOps being the hot skill, will help you to secure a high-salaried job and stay informed on the latest market trends.

Why purchase this course?

This is only practical hands-on course available on the internet till now.


Get Instant Notification of New Courses on our Telegram channel.


DevSecOps enables rapid application development with agility, at the same time it secures your application with automated security checks integrated within the pipeline. It helps to increase productivity and security by integrating security stages in the pipeline.

Also, we have included practical examples to implement security in the DevOps pipeline through various tools.

By the end of the course, you will be able to successfully implement DevOps or DevSecOps pipeline and lead initiatives to create, build and maintain security pipelines in your project.

No Action required before taking this course. For any question or concerns, Please post your comments on discussions tab

Disclaimer: English subtitles are auto-generated so please ignore any grammar mistakes

English
language

Content

Introduction

Introduction & Course Agenda
About the Course
About Instructor
Optional: Security As a Career

Deep Dive into DevSecOps

Basic Security Terms – If new to security field
What is DevSecOps?
Tools used for DevSecOps Implementation in the market – Detailed discussion
Tools used for DevSecOps in GCP

Hands On – Implementing DevSecOps Pipeline in GCP

Create GCP Free Tier Account
Install Git on Windows Machine
Create Repo in GCP Cloud Source Repository and Clone it on local system with Git
Push vulnerable code to GCP Cloud Source Repo
Enable Cloud Build for GCP Project
Write CloudBuild YML file and push it to GCP Cloud Source Code Repo
Create Trigger in GCP CloudBuild
Trigger Build Automatically in GCP using CloudBuild

Implement SAST in GCP DevSecOps Pipeline using SonarCloud

What is SonarCloud and its benefits?
Create Account on SonarCloud
Create Organization and Project in SonarCloud for GCP DevSecOps Pipeline
Prerequisites for integrating SonarCloud within GCP DevSecOps pipeline
Write CloudBuild YAML file code for SonarCloud Integration in GCP DevSecOps
Push SonarCloud YAML code to GCP and execute SAST in GCP DevSecOps pipeline
Review SAST scan results on SonarCloud dashboard and perform FPA
Create Custom Quality Gates within SonarCloud
Prerequisites to populate Code Coverage on SonarCloud
Push Code Coverage changes in Source Code to GCP & Review changes on SonarCloud

Implement SCA in GCP DevSecOps Pipeline using Snyk

What is Snyk and its benefits?
Create Snyk Account
Create Snyk security token and store as a GCP Cloud Build Substitution variable
Write SCA Integration code in GCP CloudBuild YML & pom.xml
Push Snyk Code changes to GCP and review Snyk results and perform FPA

Next Steps and Bonus section

Sample DevSecOps Engineer CV
Bonus Lecture