Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A software development team is adopting a 'shift-left' security approach and wants to integrate vulnerability scanning into their CI/CD pipeline for their container images. They are using GitLab CI for their pipelines and plan to leverage Prisma Cloud. At which stage of the CI/CD pipeline should the container image vulnerability scan be performed to maximize the 'shift-left' benefit while minimizing remediation costs?

  1. ADuring the 'release' stage, after all integration tests are complete.
  2. BAfter the 'build' stage, but before the 'test' stage.
  3. CDuring the 'deploy' stage, just before pushing to production.
  4. DIn the 'monitor' stage, on deployed images in the registry.
Show answer & explanation

Correct answer: B. After the 'build' stage, but before the 'test' stage.

Performing the container image vulnerability scan immediately after the 'build' stage ensures that any vulnerabilities are detected as early as possible after the image is created. This allows developers to address issues before extensive testing or deployment, significantly reducing the cost and effort of remediation, which is a core principle of 'shift-left' security.

Why the other options are wrong

  • A. Scanning after all integration tests is still relatively late in the pipeline, increasing remediation costs.
  • C. Scanning just before production is too late; issues found here are expensive to fix.
  • D. Monitoring deployed images is important but is a runtime control, not a 'shift-left' pipeline integration point for new builds.

Shift-Left in CI/CD

Integrating security practices and tools earlier in the software development lifecycle, particularly within the CI/CD pipeline, to detect and address vulnerabilities and misconfigurations at the earliest possible stage.

  • Reduces the cost and effort of fixing security issues.
  • Empowers developers with early feedback.
  • Automates security checks, improving efficiency.

Memory trick: Build, test, deploy, then monitor to keep it tight and right.

More DevSecOps and Shift Left Security questions