Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityEasy
A development team is integrating Prisma Cloud into their CI/CD pipeline. They want to ensure that any new code committed to the repository is automatically scanned for vulnerabilities and misconfigurations before it can be merged into the main branch. Which Prisma Cloud capability is most effective for this requirement?
- ANetwork protection for runtime environments
- BCompliance scan of deployed cloud resources
- CVulnerability Explorer for cloud assets
- DCode Security scan in a Git repository
Show answer & explanationAnswer & explanation
Correct answer: D. Code Security scan in a Git repository
To scan new code committed to a repository before merging, a Code Security scan integrated directly with the Git repository is the most effective and 'shift-left' approach, catching issues early in the development lifecycle.
Why the other options are wrong
- A. Network protection is a runtime security feature, not a code scanning feature for pre-merge checks.
- B. Compliance scanning of deployed resources happens after deployment, not before code merge.
- C. Vulnerability Explorer is for finding vulnerabilities in already deployed cloud assets, not for code in a repository.
Code Security Scanning
The process of analyzing source code, Infrastructure as Code (IaC), and configuration files to identify security vulnerabilities, misconfigurations, and compliance violations early in the development lifecycle.
- Performed on uncompiled or compiled code.
- Identifies issues like OWASP Top 10, CWEs, secrets, and IaC misconfigurations.
- Integrates with SCMs (Git) and CI/CD pipelines.
Memory trick: Code's early scan, security's best plan.