Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A DevOps team is adopting a GitOps workflow where all infrastructure and application configurations are stored in Git. They want to ensure that every change pushed to the main branch is automatically reviewed for security compliance before it can be applied to the Kubernetes clusters. Which Prisma Cloud feature provides the most direct and automated way to achieve this policy enforcement for GitOps?
- ARuntime Defense for Kubernetes clusters
- BIaC Security integrated with Git repository scans
- CData Loss Prevention (DLP) for Kubernetes secrets
- DCloud Security Posture Management (CSPM) for Kubernetes API
Show answer & explanationAnswer & explanation
Correct answer: B. IaC Security integrated with Git repository scans
For a GitOps workflow, where configurations are in Git and applied to Kubernetes, IaC Security integrated with Git repository scans is the most direct method. It allows scanning of the configuration files (which are essentially IaC) in the Git repository before they are synchronized to the clusters, ensuring compliance at the source.
Why the other options are wrong
- A. Runtime Defense protects running applications and containers, not the configurations in Git.
- C. DLP is for sensitive data detection, not for general security compliance of infrastructure configurations.
- D. CSPM monitors the *state* of deployed resources, not configurations *before* they are applied via GitOps.
GitOps Security
Applying security best practices and tools to a GitOps workflow, where Git is the single source of truth for declarative infrastructure and application configuration, ensuring all changes are compliant and secure before deployment.
- Leverages SCM integration for security scans.
- Focuses on policy enforcement at the pull request/commit stage.
- Ensures security is 'shifted left' in the GitOps pipeline.
Memory trick: Git's truth secure, Kubernetes pure.