Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A security auditor is reviewing a company's DevSecOps practices and notes that sensitive information, such as API keys and database credentials, are sometimes accidentally committed to Git repositories. The auditor recommends implementing a preventative measure that scans code *before* it is even pushed to the remote repository. Which Prisma Cloud integration point would best fulfill this recommendation?

  1. AScheduled scan of remote Git repositories
  2. BPost-receive Git hook integration
  3. CCI/CD pipeline scan on merge request
  4. DPre-commit Git hook integration
Show answer & explanation

Correct answer: D. Pre-commit Git hook integration

A pre-commit Git hook integrates directly into the developer's local workflow, scanning code *before* it is committed. This is the earliest possible point to detect and prevent sensitive information from entering the Git history, aligning with the auditor's recommendation for a *preventative* measure before pushing.

Why the other options are wrong

  • A. Scheduled scans are reactive and run periodically on remote repositories, not proactively before a push.
  • B. Post-receive hooks run after the push, meaning the sensitive information is already in the remote repository's history.
  • C. CI/CD pipeline scans run after the code is pushed to the remote repository, which is too late for preventive pre-push detection.

Pre-commit Hook Security

A client-side Git hook that executes a script (like a security scanner) before a commit is finalized, allowing for checks and potential rejection of the commit if security policies are violated.

  • Operates on the developer's local machine.
  • Prevents insecure code or secrets from entering Git history.
  • Enables the earliest 'shift-left' security enforcement for code commits.

Memory trick: Pre-commit checks, no code regrets.

More DevSecOps and Shift Left Security questions