Palo Alto Networks Certified Cloud Security Engineer (PCCSE) flashcards
146 free flashcards. Tap a card to flip it.
Custom Secret Detection
Flip cardPrisma Cloud's Custom Secret Detection allows users to define their own patterns (e.g., using regular expressions) to identify and prevent proprietary or organization-specific sensitive information from being committed to source code repositories.
- Extends beyond default secret patterns.
- Uses regex or other pattern matching for unique secrets.
- Crucial for identifying proprietary API keys, internal tokens.
- Applies across various SCM platforms.
Memory trick: Your unique keys need a unique eye.
IaC Scan
Flip cardAutomated analysis of Infrastructure as Code (IaC) templates (e.g., Terraform, CloudFormation) to detect security vulnerabilities, misconfigurations, and compliance violations before deployment.
- Integrates into CI/CD pipelines to 'shift left' security.
- Identifies issues like unencrypted storage, open network ports, weak IAM policies.
- Supports various IaC frameworks and provides remediation guidance.
Memory trick: IaC scans secure so deployments are clean.
Contextualized IaC Remediation
Flip cardPrisma Cloud's Contextualized IaC Remediation provides specific, code-level suggestions and often automated fix snippets for identified Infrastructure as Code misconfigurations directly within the developer's workflow.
- Offers actionable fixes for IaC vulnerabilities.
- Integrates into CI/CD and IDEs for 'shift-left' effect.
- Reduces time to remediation by providing immediate guidance.
Memory trick: Fixing code, right where it's written.
RQL Tag Filtering
Flip cardResource Query Language (RQL) in Prisma Cloud allows filtering cloud resources based on their tags, including checking for existence and specific values.
- Use `tags.<tag_key> does not exist` to find resources missing a specific tag.
- Use `tags.<tag_key> IN ('value1', 'value2')` to find resources with specific tag values.
- Logical operators (`AND`, `OR`) and parentheses are crucial for combining conditions.
Memory trick: Remember 'Tag Exists, Value Lists, Logic Connects' for RQL tag queries.
Contextual IaC Remediation
Flip cardThe provision of specific, actionable code-level suggestions or automated fixes for security vulnerabilities and compliance violations detected in Infrastructure as Code (IaC) templates.
- Goes beyond simply identifying issues; it tells developers how to fix them.
- Accelerates remediation by providing precise code snippets or configuration changes.
- Integrates into developer workflows for a 'shift-left' approach.
Memory trick: IaC fix suggestions, compliance's best options.
GitOps Security with IaC Scanning
Flip cardIn a GitOps workflow, all operational configurations are stored as Infrastructure as Code (IaC) in Git. Prisma Cloud's IaC Security scanning is crucial for validating these configurations against security policies *before* they are merged and automatically deployed, ensuring 'shift-left' security for infrastructure changes.
- Treats all GitOps configurations as IaC.
- Scans configuration files (e.g., YAML, Helm) in Git.
- Enforces security policies before deployment.
- Integrates into CI/CD pipeline for automated checks.
Memory trick: Git's code is infra, scan it before it flies.
Container Image Compliance Scanning
Flip cardAutomated analysis of container images and their Dockerfiles against predefined security policies and best practices (e.g., allowed base images, exposed ports, root user usage).
- Ensures images adhere to organizational security standards.
- Complements vulnerability scanning by checking configuration.
- Can be integrated into CI/CD to prevent non-compliant images.
Memory trick: Build once, scan twice, deploy right.
Shift-Left in CI/CD
Flip cardIntegrating security practices and tools earlier in the software development lifecycle, particularly within the CI/CD pipeline, to detect and address vulnerabilities and misconfigurations at the earliest possible stage.
- Reduces the cost and effort of fixing security issues.
- Empowers developers with early feedback.
- Automates security checks, improving efficiency.
Memory trick: Build, test, deploy, then monitor to keep it tight and right.
Policy as Code (PaC)
Flip cardThe practice of defining, managing, and enforcing security, compliance, and operational policies using machine-readable code, allowing policies to be version-controlled, tested, and automated like application code.
- Enables consistent policy enforcement across environments.
- Facilitates 'shift-left' security by integrating into CI/CD.
- Often uses declarative languages like Rego (OPA).
Memory trick: Rego's the rule, for policy's cool.
Pre-commit Hook
Flip cardA client-side Git hook that executes scripts before a commit is finalized, allowing for checks and validations to prevent unwanted code from being committed.
- Runs on the developer's local machine.
- Can enforce coding standards, run linters, or detect secrets.
- Blocks the commit if the script fails.
Memory trick: Controls protect code at every stage, from local to live.
IaC Scan in CI/CD
Flip cardAutomated scanning of Infrastructure as Code templates for security misconfigurations and vulnerabilities directly within the Continuous Integration/Continuous Delivery pipeline.
- Shifts security left by finding issues early.
- Prevents insecure infrastructure from being deployed.
- Integrates with popular CI/CD tools like Jenkins, GitLab CI, GitHub Actions.
Memory trick: Pipeline checks code before it goes to the cloud.
Container Image Vulnerability Scan
Flip cardAutomated analysis of container images to identify known security vulnerabilities (CVEs) in their operating system packages, libraries, and application components.
- Leverages public vulnerability databases.
- Generates a Software Bill of Materials (SBOM).
- Integrates into CI/CD pipelines and registries.
Memory trick: Containers are safe because their guts are scanned.
Contextual Vulnerability Prioritization
Flip cardThe process of ranking vulnerabilities for remediation based on their severity combined with real-world factors like internet exposure, exploitability, and whether the vulnerable component is actively used in production.
- Moves beyond simple CVSS scores.
- Leverages runtime data, network topology, and cloud configuration.
- Helps security teams focus on the most critical risks, reducing noise.
Memory trick: Context's key, to prioritize with glee.
Code Security in CI/CD
Flip cardAutomated static analysis of application source code within the CI/CD pipeline to detect vulnerabilities, security flaws, and compliance issues.
- Integrates with popular CI/CD platforms (e.g., GitHub Actions, Jenkins).
- Can be configured to break builds or block PRs based on policy violations.
- Provides early feedback to developers, enabling shift-left security.
Memory trick: If code is bad, the merge gets sad.
Unified IaC Policy Engine
Flip cardA centralized system that enables the creation, management, and enforcement of consistent security and compliance policies across various Infrastructure as Code frameworks and CI/CD pipelines.
- Ensures consistent security posture across diverse environments.
- Reduces complexity by centralizing policy definition.
- Facilitates 'security as code' principles for IaC.
Memory trick: Many IaC pieces, one security glue.
Code Security (SAST)
Flip cardStatic Application Security Testing (SAST) is a white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Identifies vulnerabilities early in the SDLC (Shift Left).
- Scans non-running code.
- Finds issues like SQL injection, XSS, buffer overflows.
Memory trick: Code's journey secure, from commit to deploy.
Code Security Scanning
Flip cardThe process of analyzing source code, Infrastructure as Code (IaC), and configuration files to identify security vulnerabilities, misconfigurations, and compliance violations early in the development lifecycle.
- Performed on uncompiled or compiled code.
- Identifies issues like OWASP Top 10, CWEs, secrets, and IaC misconfigurations.
- Integrates with SCMs (Git) and CI/CD pipelines.
Memory trick: Code's early scan, security's best plan.
Pre-commit Hook Security
Flip cardA client-side Git hook that executes a script (like a security scanner) before a commit is finalized, allowing for checks and potential rejection of the commit if security policies are violated.
- Operates on the developer's local machine.
- Prevents insecure code or secrets from entering Git history.
- Enables the earliest 'shift-left' security enforcement for code commits.
Memory trick: Pre-commit checks, no code regrets.
IDE Plugin for IaC Security
Flip cardAn extension for Integrated Development Environments that provides real-time or on-demand scanning of Infrastructure as Code for security misconfigurations and vulnerabilities.
- Enables immediate security feedback to developers.
- Integrates security directly into the developer's workflow.
- Helps prevent insecure code from being committed.
Memory trick: Code security starts where the code's at.
Container Image Security Gate
Flip cardA control point in a CI/CD pipeline that automatically scans container images for vulnerabilities, malware, and compliance violations, blocking non-compliant images from proceeding to deployment.
- Crucial for 'shift-left' security in containerized environments.
- Leverages vulnerability databases and compliance benchmarks.
- Prevents insecure images from reaching production, reducing attack surface.
Memory trick: Image scan gate, for deployment's fate.
GitOps Security
Flip cardApplying security best practices and tools to a GitOps workflow, where Git is the single source of truth for declarative infrastructure and application configuration, ensuring all changes are compliant and secure before deployment.
- Leverages SCM integration for security scans.
- Focuses on policy enforcement at the pull request/commit stage.
- Ensures security is 'shifted left' in the GitOps pipeline.
Memory trick: Git's truth secure, Kubernetes pure.
CI/CD Pipeline Gates
Flip cardAutomated checks or conditions within a CI/CD pipeline that must be met for the pipeline to proceed to the next stage, often used for quality, security, or compliance enforcement.
- Can be based on test results, scan findings, or policy violations.
- Often implemented via exit codes or specific status checks.
- Essential for 'shift-left' and 'fail-fast' strategies.
Memory trick: Gates ensure only good code gets to run free.
IDE Plugin for Security
Flip cardA tool that integrates security scanning and feedback directly into a developer's Integrated Development Environment (IDE), enabling real-time or on-demand identification of vulnerabilities and misconfigurations during code development.
- Provides immediate feedback to developers.
- Enables 'shift-left' security by catching issues at the earliest stage.
- Reduces context switching for developers and accelerates remediation.
Memory trick: IDE's security, code's early clarity.
Attack Path Analysis
Flip cardAttack Path Analysis in Prisma Cloud identifies and visualizes potential sequences of actions an attacker could take to compromise critical assets, starting from an initial point of entry.
- Maps relationships between cloud resources and configurations.
- Highlights vulnerabilities and misconfigurations that can be exploited.
- Helps prioritize remediation efforts by showing the 'blast radius' of a compromise.
Memory trick: Think 'Attack Path' for 'Impact Analysis' of a breach.
Identity Exposure Analysis
Flip cardA CIEM capability that maps all potential access paths an identity has to resources, including direct, indirect, and inherited permissions.
- Identifies effective permissions
- Uncovers hidden access paths
- Critical for least privilege enforcement
Memory trick: CIEM's core is knowing who can touch what, even indirectly.
Least Privilege Enforcement
Flip cardThe security principle and CIEM capability of granting identities only the minimum permissions necessary to perform their intended functions, and no more.
- Reduces attack surface and blast radius.
- Often implemented through fine-grained policies.
- Requires continuous monitoring and adjustment.
Memory trick: Least Privilege: Only what you need, nothing more.
Continuous Identity Posture Validation
Flip cardThe ongoing process of assessing and enforcing least privilege for all identities by combining regular checks of assigned permissions with advanced analysis of potential privilege escalation paths.
- Ensures least privilege over time
- Detects privilege creep
- Integrates multiple CIEM capabilities
Memory trick: Stay lean, stay safe – always checking identity posture.
Policy-as-Code (PaC)
Flip cardThe practice of defining and managing security policies in a structured, machine-readable code format, allowing for automation, version control, and consistent deployment across cloud environments.
- Enables automation of policy deployment and enforcement.
- Provides version control and auditability for policies.
- Ensures consistency and reduces human error in policy management.
Memory trick: Policy-as-Code is like a blueprint for your security rules, ensuring every building (cloud account) is built to the same safe standard.
Usage-based Rightsizing
Flip cardA CIEM capability that automatically analyzes identity activity to determine actual permission usage and then recommends or enforces policies that grant only the necessary permissions.
- Automates least privilege enforcement
- Reduces attack surface
- Continuously adapts to changing usage patterns
Memory trick: Rightsizing means giving just enough, based on what's used.
'Break Glass' Role Auditing
Flip cardThe process of rigorously monitoring and logging the activation and activity of emergency administrative roles to ensure their use is justified and compliant.
- Critical for incident response
- Requires real-time monitoring
- Demands comprehensive audit trails
Memory trick: Emergency access needs sharp eyes and a clear history.
Shadow IT Identity Detection
Flip cardThe process of identifying and flagging identities (users, roles, service accounts) that have been created or configured outside of approved processes, often with excessive or unmonitored permissions.
- Reduces unauthorized access risk
- Requires comprehensive identity visibility
- Leverages policy and anomaly detection
Memory trick: Ghost identities lurk; see them, define normal, flag anomalies.
CIEM-SIEM Integration
Flip cardThe process of feeding identity-related security logs and alerts from a CIEM solution into a SIEM system for centralized monitoring, correlation, and incident response.
- Enables comprehensive security visibility
- Facilitates faster incident detection
- Correlates identity events with other security data
Memory trick: SIEM thrives on events – CIEM provides identity events.
Identity Discovery
Flip cardThe process of automatically identifying and cataloging all human and non-human identities present across various cloud environments.
- Establishes a comprehensive inventory of all cloud identities.
- Includes users, service accounts, roles, and managed identities.
- Foundational for other CIEM capabilities like least privilege.
Memory trick: Discovering cloud identities is like finding all the actors backstage before the show.
Context-aware Access Control
Flip cardAn advanced security capability that evaluates multiple contextual attributes (e.g., identity, location, device, time, behavior) in real-time to make granular access decisions.
- Enhances Zero Trust principles
- Reduces unauthorized access risks
- Requires integration with various security data sources
Memory trick: Context is king: who, where, when, and how are you trying to access?
Identity Graph Analysis
Flip cardA CIEM capability that uses graph database technology to visualize and analyze the intricate relationships between identities, permissions, and resources, revealing hidden access paths and privilege escalation risks.
- Uncovers multi-hop access paths
- Identifies privilege escalation vectors
- Provides visual representation of identity relationships
Memory trick: Graph analysis maps the 'who can jump to what' in a complex web.
Identity-based Microsegmentation
Flip cardA security approach that uses identity as the primary factor for defining and enforcing granular network access policies between workloads and services, often abstracting away underlying network constructs.
- Controls network flow based on 'who' or 'what' is communicating.
- Essential for zero-trust architectures.
- Simplifies network security in dynamic cloud environments.
Memory trick: Microsegment: Identity is the key to network walls.
Automated Remediation (CIEM)
Flip cardThe capability within a CIEM solution to automatically take corrective actions, such as revoking permissions or modifying policies, based on detected policy violations or security risks.
- Reduces manual security overhead
- Ensures continuous compliance
- Accelerates incident response
Memory trick: Remediation means fixing problems, especially automatically.
Inactive Identity Remediation
Flip cardThe automated process of identifying identities (users, roles, service accounts) that have not been active for a defined period and subsequently revoking or suspending their permissions to reduce attack surface.
- Reduces dormant accounts risk
- Automates least privilege enforcement
- Improves security posture over time
Memory trick: If it's not used, lose the access.
Zero Trust (CIEM Context)
Flip cardA security model where no identity (user or workload) is inherently trusted, and all access requests are explicitly verified based on identity, context, and least privilege principles.
- Requires continuous verification.
- Identity is the new perimeter.
- Often implemented with microsegmentation and strong IAM.
Memory trick: Zero Trust: Never trust, always verify.
Anomaly Detection (CIEM)
Flip cardThe CIEM capability that monitors identity activity, establishes baselines of normal behavior, and flags deviations as potential threats or misconfigurations.
- Uses machine learning to identify unusual patterns.
- Detects compromised credentials or insider threats.
- Alerts on deviations in time, location, resource, or action.
Memory trick: Anomaly: Something's off, it's not normal!
IAM Visibility (CIEM)
Flip cardThe capability within CIEM to discover, map, and analyze all identities (human and machine) and their effective permissions across multi-cloud environments.
- Foundation for all other CIEM capabilities.
- Identifies who has access to what, and how.
- Uncovers 'Shadow Admins' and permission sprawl.
Memory trick: CIEM sees all, secures all.
Policy-as-Code (CIEM)
Flip cardThe practice of defining and managing identity and access policies in a machine-readable format, allowing for version control, automation, and consistent deployment across cloud environments.
- Enables policy standardization
- Facilitates automation and version control
- Reduces human error in policy management
Memory trick: Code makes policies consistent, not chaotic.
CIEM-SOAR Integration
Flip cardThe integration of a Cloud Infrastructure Entitlement Management (CIEM) solution with a Security Orchestration, Automation, and Response (SOAR) platform to automate incident response processes for identity-related security events.
- Automates response to identity threats
- Requires real-time alert and context exchange
- Accelerates incident resolution
Memory trick: SOAR needs CIEM's alerts and details to act fast.
Vulnerability Shielding (Virtual Patching)
Flip cardA Prisma Cloud runtime defense capability that virtually patches known vulnerabilities in running containers, preventing their exploitation.
- Mitigates risks from unpatched CVEs in production.
- Does not require immediate image rebuild or redeployment.
- Acts as a temporary measure until a permanent fix can be applied.
Memory trick: Shielding: Like a temporary force field for known weaknesses.
Prisma Cloud Behavioral Anomaly Detection
Flip cardBehavioral Anomaly Detection in Prisma Cloud's runtime defense automatically learns the normal operational patterns of containers, processes, and network activity. It then identifies and flags or blocks any deviations from this baseline, helping to detect zero-day threats and insider attacks.
- Learns normal behavior baseline
- Detects deviations (anomalies)
- Protects against zero-days and unknown threats
- Part of runtime defense
Memory trick: Behavioral Anomaly Detection is the smart guard, knowing what's 'normal'.
Prisma Cloud VEX
Flip cardVulnerability Exploitability Index (VEX) provides context on whether a detected vulnerability is actually exploitable in a specific environment, helping to prioritize remediation.
- Goes beyond CVE scores.
- Considers runtime context and mitigations.
- Helps prioritize true risks.
Memory trick: Don't just scan, use VEX to understand the real 'bang' of a vulnerability.
Prisma Cloud Host Defender
Flip cardThe Host Defender is an agent deployed on virtual machines or physical hosts to provide comprehensive security, including vulnerability management, compliance, and runtime protection.
- Agent-based deployment
- Protects VMs and physical servers
- Performs vulnerability scanning and compliance checks
Memory trick: Host, Container, Serverless: Each Defender knows its place.
Prisma Cloud Admission Control Compliance Checks
Flip cardEnforces security and compliance policies at the Kubernetes admission controller level, preventing non-compliant container deployments.
- Blocks risky deployments before they start.
- Can check for 'run as root', host path mounts, privileged containers, etc.
- Integrates with Kubernetes API server for enforcement.
Memory trick: Admission control is the bouncer for your cluster, checking IDs and rules before entry.
Prisma Cloud Built-In Roles
Flip cardPre-defined roles in Prisma Cloud that provide different levels of access and permissions to various features and data.
- Simplifies access management.
- Follows principle of least privilege.
- Includes roles like Administrator, Auditor, Operator.
Memory trick: Each role in Prisma Cloud has a specific job to do.
File Integrity Monitoring (FIM)
Flip cardA security control that monitors critical operating system and application files for unauthorized changes.
- Detects modifications, deletions, and additions to monitored files.
- Essential for maintaining system integrity and detecting tampering.
- Often used for compliance requirements like PCI DSS.
Memory trick: FIM is the 'Watchdog' for your critical files.
Kubernetes DaemonSet
Flip cardA Kubernetes object that ensures a copy of a Pod is running on all (or some) nodes in a cluster.
- Guarantees node-level agent deployment.
- Automatically deploys to new nodes.
- Used for infrastructure-level services.
Memory trick: DaemonSets are like security guards on every node's beat.
Prisma Cloud Container Runtime Forensics
Flip cardCaptures and analyzes detailed runtime events within containers, including process activity, network connections, and file changes, to aid in incident investigation.
- Provides a historical record of container behavior.
- Helps identify malicious activity and root causes.
- Essential for post-incident analysis and threat hunting.
Memory trick: When a container screams 'alert!', forensics pieces together the 'who, what, where'.
Prisma Cloud Serverless Function Protection
Flip cardProvides runtime security for serverless functions (e.g., AWS Lambda, Azure Functions) by monitoring execution, identifying threats, and enforcing policies.
- Protects against OWASP Top 10 for serverless.
- Detects and prevents malicious injections and data exfiltration.
- Integrates directly with cloud provider serverless platforms.
Memory trick: Serverless protection keeps your functions safe while they fly through the cloud.
Prisma Cloud Process & Network Policies
Flip cardRuntime defense policies that define allowed processes, file access, and network connections for containers, preventing unauthorized actions.
- Granular control over container behavior.
- Prevents execution of unauthorized binaries.
- Restricts outbound network connections.
Memory trick: For containers, define processes and networks to keep them in line.
Prisma Cloud Runtime Forensics
Flip cardRuntime Forensics in Prisma Cloud captures and stores detailed runtime events within containers and hosts, such as process execution, network activity, and file system changes, enabling in-depth incident investigation and root cause analysis.
- Records granular runtime events
- Aids in incident response and root cause analysis
- Covers processes, network, file system activities
Memory trick: Runtime Forensics is your detailed crime scene report for containers.
Behavioral Anomaly Detection (BAD) & Automated Network Quarantine
Flip cardPrisma Cloud's BAD learns normal container behavior to detect deviations, and Automated Network Quarantine isolates compromised containers by modifying network policies in response to detected threats.
- BAD identifies unexpected processes, network connections, file access.
- Quarantine isolates affected workloads to prevent lateral movement.
- Provides real-time runtime defense against zero-day and sophisticated attacks.
Memory trick: Spot the bad, then lock it down fast!
Prisma Cloud Behavioral Anomaly Detection (BAD)
Flip cardLearns the normal behavior of containers and alerts on significant deviations, providing protection against unknown threats and zero-day exploits.
- Establishes baselines for processes, network, and file activity.
- Detects unusual resource consumption, network patterns, or system calls.
- Effective against novel malware and insider threats.
Memory trick: BAD detects when a container acts 'bad' by learning what's 'good'.
Prisma Cloud Host Defender Golden Image Deployment
Flip cardDeploying Prisma Cloud Host Defenders via Golden Images (e.g., AMIs in AWS, custom images in Azure/GCP) involves pre-installing the Defender agent into a base VM image. This enables automated and scalable deployment, as all new VMs provisioned from that image will include the Defender.
- Automated and scalable deployment
- Defender is pre-installed in the base image
- Suitable for dynamically provisioned VMs
- Reduces operational overhead
Memory trick: Golden Images are the blueprint for automated Defender deployment.
Prisma Cloud Host and Container Compliance Scanning
Flip cardAutomated assessment of virtual machines and container hosts against industry-standard compliance benchmarks like CIS, across multi-cloud environments.
- Ensures OS and runtime configurations meet security best practices.
- Supports various compliance standards (e.g., CIS, PCI DSS).
- Provides unified visibility and reporting across diverse environments.
Memory trick: Compliance across clouds means scanning every host and container for rules.
Prisma Cloud Host Defender Deployment
Flip cardPrisma Cloud Host Defenders are agents installed on virtual machines or bare-metal servers to provide security for the host OS, applications, and files.
- Monitors for vulnerabilities, compliance, and runtime threats on the host.
- Can be deployed manually, via automation tools, or integrated into golden images.
- Essential for CWPP on VMs and physical servers.
Memory trick: Defend all your clouds, from host to serverless, with the right agent.