Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A large enterprise is implementing a comprehensive DevSecOps strategy. They have multiple development teams, each using different CI/CD platforms (Jenkins, GitLab CI, Azure DevOps) and various IaC frameworks (Terraform, CloudFormation, Kubernetes manifests). The security team wants a unified view of all IaC security findings and a consistent way to enforce policies across these diverse environments. Which Prisma Cloud capability best addresses the need for a unified and consistent approach to IaC security across disparate tools and frameworks?
- AUnified Policy Engine for IaC
- BData Security
- CCloud Access Security Broker (CASB)
- DCloud Workload Protection Platform (CWPP)
Show answer & explanationAnswer & explanation
Correct answer: A. Unified Policy Engine for IaC
Prisma Cloud's unified policy engine for IaC allows organizations to define a single set of security policies (often using Rego) that can be applied consistently across different IaC frameworks and integrated into various CI/CD pipelines, providing a centralized view and enforcement mechanism.
Why the other options are wrong
- B. Data Security focuses on protecting sensitive data at rest and in transit, not IaC security.
- C. CASB typically provides visibility and control over cloud applications and data, not directly IaC scanning and policy enforcement within CI/CD.
- D. CWPP focuses on securing running workloads (hosts, containers, serverless), not IaC templates.
Unified IaC Policy Engine
A centralized system that enables the creation, management, and enforcement of consistent security and compliance policies across various Infrastructure as Code frameworks and CI/CD pipelines.
- Ensures consistent security posture across diverse environments.
- Reduces complexity by centralizing policy definition.
- Facilitates 'security as code' principles for IaC.
Memory trick: Many IaC pieces, one security glue.