Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard

A security analyst is investigating an incident where unauthorized access to a cloud-based application occurred. The investigation reveals that the application's API keys were hardcoded into a public code repository. Which cloud security best practice was violated?

  1. ASecure Software Development Lifecycle (SSDLC)
  2. BData Encryption at Rest
  3. CPrinciple of Least Privilege
  4. DRegular Security Audits
Show answer & explanation

Correct answer: A. Secure Software Development Lifecycle (SSDLC)

Hardcoding API keys into a public repository is a critical flaw in the secure software development lifecycle (SSDLC), specifically in the 'secure coding' phase, as it exposes sensitive credentials during development and deployment.

Why the other options are wrong

  • B. Data encryption at rest protects stored data, but doesn't prevent the exposure of API keys in code.
  • C. While related to access, the direct violation is how the secret was handled during development, not necessarily the scope of permissions.
  • D. Regular security audits might detect this, but the initial violation is the insecure development practice itself.

Secure Software Development Lifecycle (SSDLC)

Integrating security practices and considerations into every phase of the software development lifecycle, from requirements gathering to deployment and maintenance.

  • Includes threat modeling, secure coding, security testing.
  • Aims to minimize vulnerabilities from the start.
  • Prevents common security flaws like hardcoded credentials.

Memory trick: SSDLC builds security 'into' the code, not just 'around' it.

More Cloud Security questions