Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityHard
A development team is using GitHub for their source code management and GitHub Actions for their CI/CD pipeline. They want to integrate Prisma Cloud to scan their code for security vulnerabilities and misconfigurations as part of their automated build process. Which method allows them to run Prisma Cloud code security scans directly within their GitHub Actions workflow?
- AIntegrating the Prisma Cloud `checkov` action or CLI in GitHub Actions
- BManually uploading code bundles to the Prisma Cloud console for scanning
- CConfiguring a webhook from Prisma Cloud to trigger GitHub Actions
- DDeploying a Prisma Cloud Defender agent to GitHub's infrastructure
Show answer & explanationAnswer & explanation
Correct answer: A. Integrating the Prisma Cloud `checkov` action or CLI in GitHub Actions
To run Prisma Cloud code security scans directly within a GitHub Actions workflow, the team should leverage the `checkov` action or CLI. This allows for native integration, enabling automated scanning as part of the CI/CD pipeline step.
Why the other options are wrong
- B. Manually uploading code is not an automated integration into a CI/CD pipeline.
- C. A webhook from Prisma Cloud would typically *receive* events, not *trigger* a scan *within* GitHub Actions.
- D. Prisma Cloud Defender agents are for runtime protection of hosts/containers, not for scanning code in GitHub Actions.
Code Security in CI/CD
The practice of embedding security scanning tools and processes directly into the Continuous Integration/Continuous Delivery (CI/CD) pipeline to automatically identify and address vulnerabilities and misconfigurations in code, IaC, and dependencies.
- Automates security checks at every code change.
- Prevents insecure code from reaching production.
- Integrates with popular CI/CD platforms like GitHub Actions, GitLab CI, Jenkins.
Memory trick: GitHub's action, Checkov's reaction.