Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A security engineer is tasked with establishing a policy enforcement strategy for IaC templates within a multi-cloud environment using Prisma Cloud. The goal is to prevent the deployment of cloud resources that do not meet specific compliance standards, such as disallowing public S3 buckets. The engineer needs to define a policy that checks for this condition and then automatically blocks the deployment if violated. Which component of Prisma Cloud is primarily responsible for defining and enforcing such a policy for IaC?

  1. AWeb Application and API Security (WAAS)
  2. BContainer Security
  3. CCloud Security Posture Management (CSPM)
  4. DPolicy as Code (PaC) engine
Show answer & explanation

Correct answer: D. Policy as Code (PaC) engine

Prisma Cloud's Policy as Code (PaC) engine, powered by OPA/Rego, allows security teams to define granular policies that can be applied to IaC templates. This enables automated validation and enforcement of compliance standards, blocking non-compliant deployments before they reach the cloud environment.

Why the other options are wrong

  • A. WAAS focuses on runtime protection of web applications and APIs.
  • B. Container Security deals with vulnerabilities and compliance of container images and runtime.
  • C. CSPM primarily monitors deployed resources, not pre-deployment IaC.

Policy as Code (PaC)

The practice of defining security and compliance policies in machine-readable code, enabling automated enforcement throughout the software development lifecycle, especially for Infrastructure as Code.

  • Policies are version-controlled, testable, and auditable.
  • Enables consistent policy enforcement across environments.
  • Often implemented using tools like Open Policy Agent (OPA) and Rego.

Memory trick: Policies written as code, govern the cloud's flow.

More DevSecOps and Shift Left Security questions