Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A financial services company is mandated to ensure that all cloud resources provisioned via Infrastructure as Code (IaC) templates adhere to strict regulatory compliance standards. They need a mechanism to not only detect non-compliant resources in IaC but also to automatically generate code-level fixes that developers can easily apply. Which Prisma Cloud capability best facilitates this workflow?
- AWeb Application and API Security (WAAS) policies
- BIaC Scan with contextualized remediation guidance
- CCloud Network Security (CNS) for traffic filtering
- DRuntime compliance monitoring with auto-remediation
Show answer & explanationAnswer & explanation
Correct answer: B. IaC Scan with contextualized remediation guidance
IaC Scan with contextualized remediation guidance directly addresses the need to detect non-compliant resources in IaC and, critically, to provide code-level fixes. This 'shift-left' approach empowers developers to correct issues before deployment, ensuring compliance from the start.
Why the other options are wrong
- A. WAAS focuses on application-layer security for deployed applications, not IaC compliance.
- C. CNS is for network traffic filtering and protection, unrelated to IaC template compliance.
- D. Runtime auto-remediation acts after deployment, which is not 'shift-left' for IaC templates.
Contextual IaC Remediation
The provision of specific, actionable code-level suggestions or automated fixes for security vulnerabilities and compliance violations detected in Infrastructure as Code (IaC) templates.
- Goes beyond simply identifying issues; it tells developers how to fix them.
- Accelerates remediation by providing precise code snippets or configuration changes.
- Integrates into developer workflows for a 'shift-left' approach.
Memory trick: IaC fix suggestions, compliance's best options.