Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A security architect wants to implement a robust runtime defense strategy for containers within a Kubernetes cluster using Prisma Cloud. They need to define policies that automatically detect and prevent container processes from executing arbitrary commands or making unexpected outbound network connections. Which Prisma Cloud runtime defense mechanism is best suited for defining these behavioral policies?
- AProcess and Network Policies
- BAnomaly Detection Policies
- CVulnerability Policies
- DCompliance Policies
Show answer & explanationAnswer & explanation
Correct answer: A. Process and Network Policies
Prisma Cloud's Process and Network Policies allow administrators to define granular rules for what processes are allowed to run inside a container and what network connections they can establish, effectively preventing unauthorized execution and communication.
Why the other options are wrong
- B. Anomaly Detection Policies identify deviations from learned baselines but may not proactively prevent specific unauthorized actions without explicit rules.
- C. Vulnerability Policies focus on known software flaws, not runtime behavior.
- D. Compliance Policies ensure configuration adherence, not dynamic process/network control.
Prisma Cloud Process & Network Policies
Runtime defense policies that define allowed processes, file access, and network connections for containers, preventing unauthorized actions.
- Granular control over container behavior.
- Prevents execution of unauthorized binaries.
- Restricts outbound network connections.
Memory trick: For containers, define processes and networks to keep them in line.