Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityEasy

A DevSecOps team is implementing Prisma Cloud into their CI/CD pipeline. They want to ensure that any new code committed to the repository is automatically scanned for common security vulnerabilities like SQL injection and cross-site scripting before it is merged into the main branch. Which Prisma Cloud capability directly addresses this requirement?

  1. AContainer Security
  2. BCode Security (SAST)
  3. CCloud Security Posture Management (CSPM)
  4. DWeb Application and API Security (WAAS)
Show answer & explanation

Correct answer: B. Code Security (SAST)

Code Security (Static Application Security Testing - SAST) is specifically designed to analyze source code for vulnerabilities early in the development lifecycle, matching the requirement to scan committed code for common security flaws before merging.

Why the other options are wrong

  • A. Container Security focuses on vulnerabilities within container images and runtime, not the application source code itself.
  • C. CSPM focuses on cloud resource misconfigurations and compliance, not direct code vulnerabilities.
  • D. WAAS protects live web applications from attacks, it does not scan source code pre-deployment.

Code Security (SAST)

Static Application Security Testing (SAST) is a white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Identifies vulnerabilities early in the SDLC (Shift Left).
  • Scans non-running code.
  • Finds issues like SQL injection, XSS, buffer overflows.

Memory trick: Code's journey secure, from commit to deploy.

More DevSecOps and Shift Left Security questions