Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A financial services company is mandated to ensure that all cloud resources provisioned via Infrastructure as Code (IaC) templates adhere to strict regulatory compliance standards. They need a mechanism to not only detect non-compliant resources in IaC but also to automatically generate code-level fixes that developers can easily apply. Which Prisma Cloud capability best facilitates this workflow?

  1. AWeb Application and API Security (WAAS) policies
  2. BIaC Scan with contextualized remediation guidance
  3. CCloud Network Security (CNS) for traffic filtering
  4. DRuntime compliance monitoring with auto-remediation
Show answer & explanation

Correct answer: B. IaC Scan with contextualized remediation guidance

IaC Scan with contextualized remediation guidance directly addresses the need to detect non-compliant resources in IaC and, critically, to provide code-level fixes. This 'shift-left' approach empowers developers to correct issues before deployment, ensuring compliance from the start.

Why the other options are wrong

  • A. WAAS focuses on application-layer security for deployed applications, not IaC compliance.
  • C. CNS is for network traffic filtering and protection, unrelated to IaC template compliance.
  • D. Runtime auto-remediation acts after deployment, which is not 'shift-left' for IaC templates.

Contextual IaC Remediation

The provision of specific, actionable code-level suggestions or automated fixes for security vulnerabilities and compliance violations detected in Infrastructure as Code (IaC) templates.

  • Goes beyond simply identifying issues; it tells developers how to fix them.
  • Accelerates remediation by providing precise code snippets or configuration changes.
  • Integrates into developer workflows for a 'shift-left' approach.

Memory trick: IaC fix suggestions, compliance's best options.

More DevSecOps and Shift Left Security questions