Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A development team is deploying a new set of microservices to a Kubernetes cluster. They want to ensure that no container in the cluster attempts to run as the root user or access sensitive host paths. Which Prisma Cloud Container Security control should be implemented within an admission control policy to prevent these risky deployments?
- ARuntime Process Baselines
- BCompliance Checks (e.g., 'Run as Root' or 'Host Path Mount')
- CImage Vulnerability Thresholds
- DNetwork Egress Rules
Show answer & explanationAnswer & explanation
Correct answer: B. Compliance Checks (e.g., 'Run as Root' or 'Host Path Mount')
Prisma Cloud's admission control can enforce compliance checks, such as preventing containers from running as root or mounting host paths, directly at the point of deployment into Kubernetes, thus blocking risky configurations before they become active threats.
Why the other options are wrong
- A. Runtime Process Baselines are for monitoring running containers, not preventing deployment.
- C. Image Vulnerability Thresholds focus on CVEs, not runtime user/path configurations.
- D. Network Egress Rules control outbound traffic from running containers, not deployment policies.
Prisma Cloud Admission Control Compliance Checks
Enforces security and compliance policies at the Kubernetes admission controller level, preventing non-compliant container deployments.
- Blocks risky deployments before they start.
- Can check for 'run as root', host path mounts, privileged containers, etc.
- Integrates with Kubernetes API server for enforcement.
Memory trick: Admission control is the bouncer for your cluster, checking IDs and rules before entry.