Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityHard

A large enterprise is adopting a GitOps workflow for managing their Kubernetes clusters. All infrastructure and application configurations are stored as code in Git repositories, and changes are applied to the clusters automatically via a CI/CD pipeline triggered by Git commits. The security team needs to ensure that all proposed changes to these configurations in Git are automatically validated against security policies before they are merged and applied to production. Which Prisma Cloud capability is most appropriate for enforcing security and compliance within this GitOps model?

  1. ARuntime Defense for Kubernetes
  2. BWeb Application and API Security (WAAS)
  3. CInfrastructure as Code (IaC) Security scanning
  4. DCloud Security Posture Management (CSPM)
Show answer & explanation

Correct answer: C. Infrastructure as Code (IaC) Security scanning

In a GitOps model, all configurations are treated as IaC. Therefore, validating proposed changes against security policies before merging and applying them to production directly aligns with IaC Security scanning. This capability allows Prisma Cloud to analyze the configuration files (e.g., Kubernetes YAMLs, Helm charts) in Git for misconfigurations, policy violations, and vulnerabilities early in the development lifecycle.

Why the other options are wrong

  • A. Runtime Defense protects running Kubernetes clusters, but the requirement is to validate *proposed changes in Git* before they are applied.
  • B. WAAS protects live web applications, which is not the focus of securing Git-managed infrastructure configurations.
  • D. CSPM monitors deployed cloud resources and configurations, not the IaC source files in Git.

GitOps Security with IaC Scanning

In a GitOps workflow, all operational configurations are stored as Infrastructure as Code (IaC) in Git. Prisma Cloud's IaC Security scanning is crucial for validating these configurations against security policies *before* they are merged and automatically deployed, ensuring 'shift-left' security for infrastructure changes.

  • Treats all GitOps configurations as IaC.
  • Scans configuration files (e.g., YAML, Helm) in Git.
  • Enforces security policies before deployment.
  • Integrates into CI/CD pipeline for automated checks.

Memory trick: Git's code is infra, scan it before it flies.

More DevSecOps and Shift Left Security questions