A detection engineering team wants to use AI to automatically keep vulnerable code from reaching production. Which of the following is the most effective approach for accomplishing this task?
A Deploying an integrated development environment (IDE) plug-in that will warn developers of dangerous code before compiling B Using a security orchestration, automation, and response (SOAR) with a machine learning (ML) model to classify code C Implementing a large language model (LLM) in the continuous integration and continuous deployment (CI/CD) runner to examine code and pass or fail build jobs D Developing an agentic penetration testing tool to validate potential vulnerable code Show Answer Answer Explanation A code-analysis control executed in the CI/CD pipeline can enforce a release gate: when it identifies vulnerable code, it fails the build so the artifact cannot progress toward production. GitHub’s code-scanning documentation likewise describes code scanning as analyzable within CI/CD systems and supports blocking merges when required scans find vulnerabilities.
Learn more
Community Discussion