Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium
A development team is integrating Prisma Cloud into their CI/CD pipeline to scan Infrastructure as Code (IaC) templates for misconfigurations before deployment. They need to use an API to programmatically submit IaC files for scanning and retrieve the results. Which API authentication method is most suitable for this automated, server-to-server interaction without user intervention?
- AOAuth 2.0 Client Credentials
- BBasic Authentication with username/password
- CSAML 2.0 Assertion
- DUser API Keys
Show answer & explanationAnswer & explanation
Correct answer: A. OAuth 2.0 Client Credentials
OAuth 2.0 Client Credentials flow is designed for server-to-server communication where a client (the CI/CD pipeline) authenticates itself to an authorization server (Prisma Cloud) to access protected resources without requiring a user's presence, making it ideal for automation.
Why the other options are wrong
- B. Basic Authentication is less secure and generally not recommended for API integrations, especially when more robust methods like OAuth 2.0 are available.
- C. SAML 2.0 is primarily for single sign-on (SSO) for human users, not for programmatic API access.
- D. User API Keys are tied to a specific user and may not be ideal for generic, long-lived service accounts in CI/CD.
OAuth 2.0 Client Credentials Flow
An OAuth 2.0 grant type where a client application authenticates itself directly to the authorization server using its client ID and client secret to obtain an access token.
- Used for machine-to-machine authentication.
- No end-user interaction required.
- Ideal for daemon services or backend applications.
Memory trick: For machines talking to machines, give them credentials, not a user's key.