Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityHard

A security engineer is configuring Prisma Cloud for secret detection in a large codebase. The team uses various programming languages and often includes configuration files (e.g., .env, YAML) that might inadvertently contain sensitive data. Beyond common patterns like API keys and database credentials, the company also has custom secret formats specific to internal systems. Which Prisma Cloud capability is most effective for detecting both standard and organization-specific custom secrets across diverse file types and languages?

  1. ABuilt-in general secret patterns and customizable regex-based secret detectors.
  2. BOnly pre-defined secret patterns for common cloud providers.
  3. CRuntime memory analysis for sensitive data in deployed applications.
  4. DNetwork traffic analysis for secret exfiltration attempts.
Show answer & explanation

Correct answer: A. Built-in general secret patterns and customizable regex-based secret detectors.

Prisma Cloud's Code Security module includes a robust secret detection capability that leverages both built-in, general patterns for common secrets (like AWS keys, database connection strings) and allows for the creation of highly customizable regex-based detectors. This flexibility is crucial for identifying organization-specific custom secret formats across various file types and programming languages.

Why the other options are wrong

  • B. Limiting to only pre-defined patterns is insufficient for custom, organization-specific secrets.
  • C. Runtime memory analysis is for deployed applications, not for detecting secrets in source code or configuration files during development.
  • D. Network traffic analysis is for detecting exfiltration attempts, not for finding secrets hardcoded in repositories.

Custom Secret Detection

The ability of a security scanner to identify sensitive information based on user-defined patterns (e.g., regular expressions) in addition to its built-in detectors.

  • Essential for finding organization-specific credentials/tokens.
  • Increases the accuracy and coverage of secret scanning.
  • Complements built-in detectors for common secret types.

Memory trick: Secrets hide, but patterns find them wide.

More DevSecOps and Shift Left Security questions