Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium

A security engineer is configuring Prisma Cloud to detect secrets in source code, specifically looking for API keys, database credentials, and private keys. The organization uses a mix of standard and proprietary formats for these secrets. Which Prisma Cloud capability allows for the most flexible and comprehensive detection of both known and custom secret patterns?

  1. AContainer image vulnerability scanning
  2. BStatic Application Security Testing (SAST) for logic flaws
  3. CCustom regex-based secret detection policies
  4. DPre-defined vulnerability rulesets
Show answer & explanation

Correct answer: C. Custom regex-based secret detection policies

To detect both standard and proprietary secret formats, custom regex-based secret detection policies are essential. Pre-defined rulesets might miss proprietary formats, while SAST and container image scanning focus on different security aspects.

Why the other options are wrong

  • A. Container image scanning analyzes dependencies and binaries within an image, not source code for embedded secrets.
  • B. SAST focuses on code logic and structural vulnerabilities, not specifically on embedded secrets.
  • D. Pre-defined vulnerability rulesets are good for common issues but likely won't cover proprietary secret formats.

Custom Secret Detection

The ability to define specific patterns (e.g., using regular expressions) to identify sensitive information like API keys, credentials, or private keys within source code, configuration files, or other assets.

  • Supplements pre-built secret detection rules.
  • Crucial for proprietary or organization-specific secret formats.
  • Helps prevent accidental exposure of sensitive data in code repositories.

Memory trick: Regex rules unlock all secrets, known and new.

More DevSecOps and Shift Left Security questions