Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A developer is working on a new feature and wants to quickly check their Infrastructure as Code (IaC) changes for common misconfigurations before committing them. They are using Terraform and an IDE that supports plugins. Which Prisma Cloud integration method provides the most immediate feedback to the developer in this scenario, enabling them to 'shift left' their security checks directly within their coding environment?
- AConfiguring Prisma Cloud to scan the remote Git repository after every push.
- BUtilizing a Prisma Cloud IDE plugin for real-time IaC scanning.
- CRunning a full cloud environment compliance scan with CSPM after deployment.
- DIntegrating Prisma Cloud IaC scan into a nightly CI/CD build.
Show answer & explanationAnswer & explanation
Correct answer: B. Utilizing a Prisma Cloud IDE plugin for real-time IaC scanning.
A Prisma Cloud IDE plugin provides real-time or on-demand scanning of IaC directly within the developer's integrated development environment. This offers the most immediate feedback, allowing developers to catch and fix misconfigurations as they write code, which is the epitome of 'shifting left' security.
Why the other options are wrong
- A. Scanning the remote Git repository after every push is still a step removed from the developer's immediate coding environment.
- C. CSPM scans deployed resources, which is far too late for 'shift-left' development feedback.
- D. Nightly CI/CD builds provide feedback too late for immediate developer workflow.
IDE Plugin for IaC Security
An extension for Integrated Development Environments that provides real-time or on-demand scanning of Infrastructure as Code for security misconfigurations and vulnerabilities.
- Enables immediate security feedback to developers.
- Integrates security directly into the developer's workflow.
- Helps prevent insecure code from being committed.
Memory trick: Code security starts where the code's at.