Palo Alto Networks Certified Cloud Security Engineer (PCCSE)DevSecOps and Shift Left SecurityMedium
A developer is writing a Dockerfile for a new microservice. Due to a tight deadline, they inadvertently include an insecure base image with known critical vulnerabilities and expose an unnecessary port (22) for SSH, which is not required for the application's function. The organization's policy mandates that only approved base images are used and no unnecessary ports are exposed. Which Prisma Cloud feature, when integrated into the CI/CD pipeline, would detect both of these specific issues within the Dockerfile and the resulting image?
- ACSPM for cloud resource misconfigurations.
- BData Security for sensitive data exfiltration.
- CContainer Security (Image Vulnerability and Compliance Scanning).
- DWAAS for runtime application protection.
Show answer & explanationAnswer & explanation
Correct answer: C. Container Security (Image Vulnerability and Compliance Scanning).
Prisma Cloud's Container Security module specifically addresses these issues. It performs image vulnerability scanning to detect known CVEs in the base image and compliance scanning against policies (e.g., custom rules for allowed base images or disallowed open ports) within the Dockerfile and the resulting container image. This ensures both security and compliance for containerized applications.
Why the other options are wrong
- A. CSPM focuses on deployed cloud resources, not Dockerfiles or container images.
- B. Data Security deals with sensitive data protection, not container image security and compliance.
- D. WAAS protects web applications at runtime, not the build process of container images.
Container Image Compliance Scanning
Automated analysis of container images and their Dockerfiles against predefined security policies and best practices (e.g., allowed base images, exposed ports, root user usage).
- Ensures images adhere to organizational security standards.
- Complements vulnerability scanning by checking configuration.
- Can be integrated into CI/CD to prevent non-compliant images.
Memory trick: Build once, scan twice, deploy right.