Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A security auditor is reviewing a company's DevSecOps practices and notes that sensitive API keys are occasionally found hardcoded within application repositories. To prevent this, the company wants to implement a mechanism that automatically detects and blocks commits containing secrets before they are pushed to the remote repository. Which type of security control is best suited for this scenario?

  1. AStatic Application Security Testing (SAST)
  2. BDynamic Application Security Testing (DAST)
  3. CRuntime Application Self-Protection (RASP)
  4. DPre-commit Hook
Show answer & explanation

Correct answer: D. Pre-commit Hook

A pre-commit hook is a client-side Git hook that runs scripts before a commit is finalized. This allows for immediate detection and blocking of sensitive information like API keys directly on the developer's machine, preventing them from ever reaching the remote repository.

Why the other options are wrong

  • A. SAST analyzes source code for vulnerabilities but typically runs later in the CI/CD pipeline or as a separate scan, not as an immediate block on commit.
  • B. DAST tests applications by executing them and observing their behavior, which is a runtime activity, not a pre-commit check.
  • C. RASP protects applications at runtime from attacks, not during code commit.

Pre-commit Hook

A client-side Git hook that executes scripts before a commit is finalized, allowing for checks and validations to prevent unwanted code from being committed.

  • Runs on the developer's local machine.
  • Can enforce coding standards, run linters, or detect secrets.
  • Blocks the commit if the script fails.

Memory trick: Controls protect code at every stage, from local to live.

More DevSecOps and Shift Left Security questions