Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A security architect is designing a comprehensive secret detection strategy for a large organization that uses multiple source code repositories, including GitHub, GitLab, and Bitbucket. The organization has specific internal API keys and proprietary token formats that need to be identified and prevented from being committed. Which Prisma Cloud capability should the architect leverage to ensure these unique secrets are detected across all repositories?
- ACloud Security Posture Management (CSPM)
- BCustom secret detection rules
- CDefault secret patterns
- DContainer Image scanning
Show answer & explanationAnswer & explanation
Correct answer: B. Custom secret detection rules
While Prisma Cloud has default secret patterns, the requirement to detect 'specific internal API keys and proprietary token formats' necessitates the creation of custom secret detection rules. These rules, often defined using regular expressions, allow organizations to identify unique, sensitive information tailored to their environment across various code repositories.
Why the other options are wrong
- A. CSPM monitors cloud configurations for misconfigurations, not secrets embedded in source code.
- C. Default secret patterns cover common secrets but will not identify proprietary internal formats.
- D. Container Image scanning focuses on vulnerabilities in container images, not secrets in source code repositories.
Custom Secret Detection
Prisma Cloud's Custom Secret Detection allows users to define their own patterns (e.g., using regular expressions) to identify and prevent proprietary or organization-specific sensitive information from being committed to source code repositories.
- Extends beyond default secret patterns.
- Uses regex or other pattern matching for unique secrets.
- Crucial for identifying proprietary API keys, internal tokens.
- Applies across various SCM platforms.
Memory trick: Your unique keys need a unique eye.