Palo Alto Networks Certified Cloud Security Engineer (PCCSE) flashcards
146 free flashcards. Tap a card to flip it.
Prisma Cloud Runtime Process and Network Policies
Flip cardThese policies define and enforce permitted process execution and network connections within containers during runtime.
- Enforce granular controls within running containers.
- Prevent unauthorized processes and network communication.
- Crucial for containing exploits and maintaining application integrity.
Memory trick: Runtime policies are like a container's personal bodyguard, watching every move and connection.
Prisma Cloud Threat Intelligence
Flip cardIntegration of external threat intelligence feeds into Prisma Cloud's runtime defense to identify and alert on communication with known malicious IP addresses, domains, or other indicators of compromise.
- Leverages external security data.
- Detects communication with C2 servers, malware domains.
- Enhances real-time threat detection.
Memory trick: Smart defense uses threat intelligence to spot known bad guys.
Registry Scanning
Flip cardPrisma Cloud feature that scans container images residing in registries for vulnerabilities, malware, and compliance issues.
- Scans images at rest in registries (e.g., Docker Hub, ECR, GCR).
- Identifies known CVEs, malware, and sensitive data.
- Provides a continuous view of image security posture before deployment.
Memory trick: Registry Scanning: Think of it as a 'customs check' for images arriving in your port.
Prisma Cloud Registry Scanning
Flip cardRegistry scanning automatically connects to container image registries to pull and analyze images for vulnerabilities, malware, and compliance issues, enabling 'shift-left' security.
- Scans images in registries (Docker Hub, ECR, GCR, etc.)
- Detects vulnerabilities, malware, secrets
- Enables security earlier in the CI/CD pipeline
Memory trick: Registry Scanning is the gatekeeper for your container images.
Prisma Cloud Host Compliance Explorer
Flip cardPrisma Cloud's Host Compliance Explorer continuously assesses host configurations against security benchmarks and regulatory standards.
- Supports industry benchmarks (e.g., CIS, PCI DSS).
- Provides detailed reports on compliance posture.
- Offers remediation recommendations for identified deviations.
Memory trick: Check your hosts against the rules, then fix what's broken.
Prisma Cloud Auditor Role
Flip cardA built-in role in Prisma Cloud that grants read-only access to security posture, vulnerability, and compliance reports.
- Provides visibility without modification privileges.
- Ideal for compliance officers, auditors, or non-security developers.
- Ensures least privilege for reporting and monitoring.
Memory trick: Roles define what you can 'do' in Prisma Cloud: Admin commands, Operator acts, Auditor observes, DevSecOps builds secure.
Prisma Cloud Serverless Defender
Flip cardA specialized Defender designed to secure serverless functions, monitoring configuration, runtime behavior, and identifying threats unique to serverless environments.
- Protects AWS Lambda, Azure Functions, Google Cloud Functions.
- Monitors function configuration and execution.
- Detects runtime anomalies and policy violations.
Memory trick: Each cloud workload needs its own defensive shield.
Prisma Cloud File Integrity Monitoring (FIM)
Flip cardFile Integrity Monitoring (FIM) in Prisma Cloud allows defining policies to monitor specific files and directories within containers and hosts for unauthorized access, modification, or deletion, alerting on any deviations.
- Monitors critical files and directories
- Detects unauthorized changes, access, or deletion
- Key component of runtime defense
Memory trick: FIM is the vigilant guardian of your container's files.
Prisma Cloud Admission Control
Flip cardA feature that integrates with Kubernetes admission controllers to enforce policies on resource creation and updates, such as blocking vulnerable container images.
- Intercepts Kubernetes API requests.
- Enforces pre-defined security policies.
- Can block deployment of non-compliant images.
Memory trick: Admit only secure ships to the Kubernetes harbor.
Prisma Cloud Registry Scan
Flip cardA feature that connects to container image registries to automatically scan stored images for vulnerabilities, malware, and compliance issues.
- Proactive security for images at rest.
- Scans Docker, OCI, and other registries.
- Identifies vulnerabilities and compliance violations.
Memory trick: Scan the registry to find hidden image dangers before they deploy.
Prisma Cloud Compliance Explorer
Flip cardCompliance Explorer provides continuous monitoring and reporting of cloud resource configurations against industry benchmarks (e.g., CIS, PCI DSS) and custom compliance policies.
- Continuous compliance assessment
- Supports industry benchmarks (CIS, PCI, etc.)
- Reports on deviations from policies
Memory trick: Compliance Explorer leads the way to audit-ready cloud resources.
Vulnerability Shielding (Virtual Patching)
Flip cardA Prisma Cloud runtime defense capability that virtually patches known vulnerabilities in running containers, preventing their exploitation.
- Mitigates risks from unpatched CVEs in production.
- Does not require immediate image rebuild or redeployment.
- Acts as a temporary measure until a permanent fix can be applied.
Memory trick: Shielding: Like a temporary force field for known weaknesses.
Defender DaemonSet Deployment
Flip cardPrisma Cloud's recommended method for deploying Defenders in Kubernetes, ensuring a Defender runs on every worker node.
- Provides comprehensive host and container visibility.
- Automatically scales with the Kubernetes cluster.
- Simplifies management and ensures consistent policy enforcement.
Memory trick: DaemonSet: Every node gets a Defender, like a personal bodyguard.
Prisma Cloud Exception Policies
Flip cardA feature that allows administrators to define controlled and auditable bypasses for specific security policies or compliance rules for designated resources.
- Permits deviations from standard policies.
- Requires explicit definition and approval.
- Maintains an audit trail of all exceptions.
Memory trick: When the policy is too rigid, an exception can bridge the gap.
Prisma Cloud Image & Registry Scanning
Flip cardAutomated scanning of container images in registries, CI/CD pipelines, and deployed containers for vulnerabilities and misconfigurations.
- Identifies known CVEs and compliance issues.
- Integrates into CI/CD for shift-left security.
- Provides continuous monitoring of image security.
Memory trick: Scan every image, everywhere, all the time, to catch threats before they run.
Prisma Cloud Kubernetes Compliance Explorer
Flip cardThe Kubernetes Compliance Explorer in Prisma Cloud provides continuous assessment of Kubernetes cluster configurations (e.g., API server, controllers, network policies, pod security) against industry benchmarks (like CIS Kubernetes Benchmark) and custom organizational policies, reporting on deviations.
- Monitors Kubernetes cluster configurations
- Checks against CIS Kubernetes Benchmark and custom policies
- Covers API server, network policies, and more
- Provides continuous compliance reporting
Memory trick: Kubernetes Compliance Explorer is the auditor for your K8s setup.
Automated Defender Deployment
Flip cardUtilizing configuration management tools or orchestration platforms to deploy and manage Prisma Cloud Defenders efficiently across large infrastructures.
- Reduces manual effort and errors.
- Ensures consistent configurations.
- Facilitates scalable updates and maintenance.
Memory trick: For many hosts, automation is the only way to go.
Prisma Cloud Automated Network Quarantine
Flip cardAn automated response capability that isolates compromised containers by blocking their network access to prevent further damage or data exfiltration.
- Real-time containment of active threats.
- Prevents lateral movement and data exfiltration.
- Configurable to respond to specific alert types.
Memory trick: When trouble strikes, automated quarantine locks down the network to stop the spread.
Vulnerability Exploitability Exchange (VEX)
Flip cardVEX is a form of security advisory that provides additional context about vulnerabilities, specifically whether a product is affected by a known vulnerability and if it's exploitable.
- Reduces 'alert fatigue' by clarifying actual risk.
- Allows security teams to focus on truly exploitable vulnerabilities.
- Can be used to mark vulnerabilities as 'not affected', 'fixed', or 'under investigation'.
Memory trick: Don't just scan, understand and act on what truly matters.
RQL for Azure Storage Account Security
Flip cardRQL queries can target specific Azure resource types like 'azure.storage.storageAccount' and inspect their properties to identify security misconfigurations, such as public access and encryption status.
- Resource Type: 'azure.storage.storageAccount'.
- Public Access Property: 'properties.publicNetworkAccess'.
- Encryption Key Source Property: 'properties.encryption.keySource'.
Memory trick: Azure Storage security: Public + no KeyVault = Red flag!
'Break Glass' Role Auditing (CIEM)
Flip cardThe process of monitoring and managing emergency access roles ('break glass') in a CIEM solution, specifically focusing on immediate auditing upon activation and automated or semi-automated remediation (e.g., permission revocation) once the emergency is over.
- For emergency, high-privilege access
- Requires immediate auditing upon activation
- Needs automated/prompt remediation post-use
Memory trick: After breaking the glass, the automated cleanup crew immediately comes to secure the scene.
Usage-based Rightsizing (CIEM)
Flip cardA CIEM capability that analyzes actual identity usage patterns to recommend and enforce permissions that align with observed activity, reducing excessive or unused access.
- Reduces unused or excessive permissions
- Based on actual identity activity/usage
- Helps enforce least privilege without disruption
Memory trick: Rightsize your permissions, right-wing a bird to fly with only what it needs.
Policy-as-Code (PaC) in CIEM
Flip cardThe practice of defining, storing, and managing cloud identity and access management (IAM) policies as machine-readable code within a version control system (e.g., Git), enabling automation, consistency, auditability, and collaborative policy development.
- Policies defined as code (e.g., JSON, YAML)
- Stored in version control (Git)
- Enables automation, consistency, auditability
Memory trick: Policy-as-Code is like writing the rulebook for your cloud in a programming language, keeping it in a digital library.
Host Auto-Defend
Flip cardPrisma Cloud's Host Auto-Defend feature automates the deployment of Defenders to hosts (e.g., EC2 instances) in cloud environments, ensuring consistent security coverage.
- Automates Defender deployment on cloud hosts.
- Integrates with cloud-native deployment tools like CloudFormation.
- Ensures widespread security coverage without manual intervention.
Memory trick: Auto-Defend is the cloud's best friend for host protection.
Prisma Cloud Process Control Policy
Flip cardA Prisma Cloud runtime defense feature that allows administrators to define and enforce rules for process execution within containers, preventing unauthorized or malicious binaries from running.
- Monitors and controls process execution in containers.
- Can be configured with whitelists (only allowed processes) or blacklists (denied processes).
- Generates alerts and can prevent execution based on policy violations.
Memory trick: Runtime defense is like a bouncer at the container club, checking who gets in and what they do.
Automated Remediation Prerequisites (GCP BigQuery)
Flip cardFor Prisma Cloud to perform automated remediation on GCP BigQuery datasets, the associated service principal must possess the necessary IAM roles to modify dataset access controls.
- Requires specific GCP IAM roles.
- Role must allow modification of BigQuery dataset permissions.
- Example role: 'BigQuery Admin' or a custom role with equivalent permissions.
Memory trick: Remediation needs the right keys to fix the locks.