Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityHard
A large organization with a complex cloud environment uses multiple cloud providers (AWS, Azure, GCP) and manages thousands of cloud accounts. They want to ensure consistent security policy enforcement across all their Infrastructure as Code (IaC) templates, regardless of the cloud provider or IaC framework (Terraform, CloudFormation, ARM templates). Which Prisma Cloud feature provides a unified approach to define and enforce these policies?
- AUnified IaC Policy Engine
- BCloud Workload Protection Platform (CWPP) for runtime security
- CNetwork Security groups and ACLs
- DCloud Security Posture Management (CSPM) for deployed assets
Show answer & explanationAnswer & explanation
Correct answer: A. Unified IaC Policy Engine
A Unified IaC Policy Engine is designed to provide a single platform for defining and enforcing security policies across diverse IaC frameworks and multiple cloud providers. This enables consistent 'shift-left' security across the entire cloud estate.
Why the other options are wrong
- B. CWPP focuses on runtime security of workloads, not static analysis of IaC templates.
- C. Network Security Groups/ACLs are cloud provider-specific network controls, not a unified policy engine for IaC.
- D. CSPM monitors *deployed* assets for misconfigurations, not IaC templates across multiple frameworks.
Unified IaC Policy Engine
A centralized system that allows defining and enforcing security and compliance policies across various Infrastructure as Code (IaC) frameworks (e.g., Terraform, CloudFormation) and multiple cloud providers (AWS, Azure, GCP) from a single platform.
- Ensures consistent policy application regardless of IaC syntax or cloud provider.
- Reduces complexity in multi-cloud, multi-framework environments.
- Facilitates 'policy as code' and 'shift-left' security at scale.
Memory trick: One policy engine, all IaC it's keen.