Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A security team needs to ensure that all AWS S3 buckets created through Infrastructure as Code (IaC) templates are encrypted at rest with AWS Key Management Service (KMS) and are not publicly accessible. They want to integrate this check into their CI/CD pipeline, failing any build that attempts to provision non-compliant S3 buckets. Which Prisma Cloud feature would enforce this policy most effectively?
- AContainer Security for S3 access policies
- BCloud Security Posture Management (CSPM) for deployed resources
- CIaC Scan integrated with CI/CD
- DWeb Application Firewall (WAF) for S3 bucket access
Show answer & explanationAnswer & explanation
Correct answer: C. IaC Scan integrated with CI/CD
To enforce policies on IaC templates *before* deployment within a CI/CD pipeline, an IaC scan is the most effective feature. It identifies non-compliant resources in the code itself, failing the build and preventing the deployment of insecure infrastructure.
Why the other options are wrong
- A. Container Security focuses on container images and runtime, not IaC templates for S3 buckets.
- B. CSPM monitors *deployed* resources, not IaC templates in a pipeline.
- D. WAF protects web applications, not S3 bucket configuration within IaC.
IaC Scan
Automated analysis of Infrastructure as Code (IaC) templates (e.g., Terraform, CloudFormation) to detect security vulnerabilities, misconfigurations, and compliance violations before deployment.
- Integrates into CI/CD pipelines to 'shift left' security.
- Identifies issues like unencrypted storage, open network ports, weak IAM policies.
- Supports various IaC frameworks and provides remediation guidance.
Memory trick: IaC scans secure so deployments are clean.