Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A development team is using GitHub for their source code management and GitHub Actions for their CI/CD pipelines. They have integrated Prisma Cloud to scan their application code for vulnerabilities. To enforce a 'no high-severity vulnerability' policy, they want to ensure that any pull request (PR) that introduces a new high-severity vulnerability is automatically blocked from being merged. Which specific integration point and configuration in Prisma Cloud and GitHub Actions would best facilitate this policy enforcement?

  1. AConfiguring a post-merge GitHub Action to scan the main branch and send alerts.
  2. BRunning a DAST scan against the application in a staging environment after deployment.
  3. CUtilizing Prisma Cloud's CSPM to monitor deployed resources and revert non-compliant changes.
  4. DImplementing a Prisma Cloud 'Code Security' scan in a GitHub Action workflow, configured to fail the build on high-severity findings.
Show answer & explanation

Correct answer: D. Implementing a Prisma Cloud 'Code Security' scan in a GitHub Action workflow, configured to fail the build on high-severity findings.

Integrating Prisma Cloud's Code Security (SAST) scan as part of a GitHub Action workflow allows for automated scanning of code changes within a PR. By configuring the scan to fail the build if high-severity vulnerabilities are found, the PR merge can be effectively blocked, enforcing the 'no high-severity vulnerability' policy directly in the developer's workflow.

Why the other options are wrong

  • A. Scanning post-merge is too late to block the PR merge; it only detects issues after they are introduced.
  • B. DAST runs against a deployed application and does not prevent a PR from merging.
  • C. CSPM monitors deployed resources, not code in PRs, and doesn't block merges.

Code Security in CI/CD

Automated static analysis of application source code within the CI/CD pipeline to detect vulnerabilities, security flaws, and compliance issues.

  • Integrates with popular CI/CD platforms (e.g., GitHub Actions, Jenkins).
  • Can be configured to break builds or block PRs based on policy violations.
  • Provides early feedback to developers, enabling shift-left security.

Memory trick: If code is bad, the merge gets sad.

More DevSecOps and Shift Left Security questions