Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A security auditor is reviewing a company's DevSecOps practices and notes that sensitive information, such as API keys and database credentials, are sometimes accidentally committed to Git repositories. The auditor recommends implementing a preventative measure that scans code *before* it is even pushed to the remote repository. Which Prisma Cloud integration point would best fulfill this recommendation?
- AScheduled scan of remote Git repositories
- BPost-receive Git hook integration
- CCI/CD pipeline scan on merge request
- DPre-commit Git hook integration
Show answer & explanationAnswer & explanation
Correct answer: D. Pre-commit Git hook integration
A pre-commit Git hook integrates directly into the developer's local workflow, scanning code *before* it is committed. This is the earliest possible point to detect and prevent sensitive information from entering the Git history, aligning with the auditor's recommendation for a *preventative* measure before pushing.
Why the other options are wrong
- A. Scheduled scans are reactive and run periodically on remote repositories, not proactively before a push.
- B. Post-receive hooks run after the push, meaning the sensitive information is already in the remote repository's history.
- C. CI/CD pipeline scans run after the code is pushed to the remote repository, which is too late for preventive pre-push detection.
Pre-commit Hook Security
A client-side Git hook that executes a script (like a security scanner) before a commit is finalized, allowing for checks and potential rejection of the commit if security policies are violated.
- Operates on the developer's local machine.
- Prevents insecure code or secrets from entering Git history.
- Enables the earliest 'shift-left' security enforcement for code commits.
Memory trick: Pre-commit checks, no code regrets.