Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityEasy
A development team is integrating Prisma Cloud into their CI/CD pipeline. They want to ensure that every pull request (PR) for Infrastructure as Code (IaC) templates is automatically scanned for misconfigurations before merging. Which of the following Prisma Cloud features should be primarily configured to achieve this goal?
- ACloud Security Posture Management (CSPM)
- BIaC Scan in CI/CD
- CContainer Security
- DWeb Application and API Security (WAAS)
Show answer & explanationAnswer & explanation
Correct answer: B. IaC Scan in CI/CD
IaC Scan in CI/CD directly addresses the requirement of scanning Infrastructure as Code templates within the continuous integration/continuous delivery pipeline for misconfigurations before deployment, aligning with DevSecOps principles.
Why the other options are wrong
- A. CSPM focuses on scanning deployed cloud resources, not pre-deployment IaC templates.
- C. Container Security focuses on vulnerabilities and compliance for container images and runtime, not IaC templates.
- D. WAAS protects web applications and APIs at runtime, not IaC templates during development.
IaC Scan in CI/CD
Automated scanning of Infrastructure as Code templates for security misconfigurations and vulnerabilities directly within the Continuous Integration/Continuous Delivery pipeline.
- Shifts security left by finding issues early.
- Prevents insecure infrastructure from being deployed.
- Integrates with popular CI/CD tools like Jenkins, GitLab CI, GitHub Actions.
Memory trick: Pipeline checks code before it goes to the cloud.