Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityHard

A security team wants to enforce a 'policy as code' approach for their cloud infrastructure. They need to define security and compliance policies in a machine-readable format that can be version-controlled, automatically applied, and integrated into their CI/CD pipeline for Infrastructure as Code (IaC) templates. Which open-source policy language is commonly used and supported by Prisma Cloud for this purpose?

  1. APython
  2. BJSON
  3. CYAML
  4. DRego (Open Policy Agent)
Show answer & explanation

Correct answer: D. Rego (Open Policy Agent)

Rego, the policy language used by Open Policy Agent (OPA), is widely adopted for 'policy as code' due to its declarative nature and ability to evaluate complex policies across various data inputs, including IaC. Prisma Cloud integrates OPA/Rego for flexible policy definition.

Why the other options are wrong

  • A. Python is a general-purpose programming language, not a dedicated declarative policy language like Rego, though it could be used to implement policy logic, it's not 'policy as code' itself in this context.
  • B. JSON is a data interchange format, not a policy language.
  • C. YAML is a data serialization language, not a policy language for defining rules and logic.

Policy as Code (PaC)

The practice of defining, managing, and enforcing security, compliance, and operational policies using machine-readable code, allowing policies to be version-controlled, tested, and automated like application code.

  • Enables consistent policy enforcement across environments.
  • Facilitates 'shift-left' security by integrating into CI/CD.
  • Often uses declarative languages like Rego (OPA).

Memory trick: Rego's the rule, for policy's cool.

More DevSecOps and Shift Left Security questions