Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy

An organization is deploying a critical internal application using AWS Lambda functions. They need to ensure that these serverless functions are protected from common vulnerabilities, malicious injections, and unauthorized data exfiltration attempts. Which Prisma Cloud capability directly addresses the runtime security requirements for these Lambda functions?

  1. AHost Security Defender
  2. BContainer Image Scanning
  3. CServerless Function Protection
  4. DKubernetes Admission Control
Show answer & explanation

Correct answer: C. Serverless Function Protection

Prisma Cloud's Serverless Function Protection is specifically designed to provide runtime defense for serverless functions like AWS Lambda, protecting them from various threats including injections and unauthorized data access.

Why the other options are wrong

  • A. Host Security Defender protects virtual machines or physical servers, not serverless functions.
  • B. Container Image Scanning focuses on container images, which are different from serverless functions.
  • D. Kubernetes Admission Control applies to container deployments in Kubernetes, not serverless functions.

Prisma Cloud Serverless Function Protection

Provides runtime security for serverless functions (e.g., AWS Lambda, Azure Functions) by monitoring execution, identifying threats, and enforcing policies.

  • Protects against OWASP Top 10 for serverless.
  • Detects and prevents malicious injections and data exfiltration.
  • Integrates directly with cloud provider serverless platforms.

Memory trick: Serverless protection keeps your functions safe while they fly through the cloud.

More Cloud Workload Protection Platform (CWPP) questions