Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard

A large enterprise is migrating its legacy applications to a cloud-native architecture using Kubernetes. They need a robust solution to detect anomalous behavior within their containers, such as unexpected process execution or network connections, and automatically apply countermeasures. Which two Prisma Cloud capabilities are best suited to address these requirements?

  1. AServerless Protection and Registry Scanning
  2. BImage Assurance and Admission Control
  3. CVulnerability Management and Compliance Scanning
  4. DBehavioral Anomaly Detection (BAD) and Automated Network Quarantine
Show answer & explanation

Correct answer: D. Behavioral Anomaly Detection (BAD) and Automated Network Quarantine

Behavioral Anomaly Detection (BAD) is designed to learn and identify deviations from normal container behavior (like unexpected processes or network connections). Automated Network Quarantine is the appropriate countermeasure to isolate a compromised container when such anomalies are detected.

Why the other options are wrong

  • A. Serverless Protection is for serverless functions, and Registry Scanning is for pre-deployment image analysis, neither addresses container runtime anomalies and automated response.
  • B. Image Assurance and Admission Control focus on preventing vulnerable images from being deployed, not on detecting runtime anomalies or applying countermeasures.
  • C. Vulnerability Management and Compliance Scanning identify known issues pre-deployment or misconfigurations, not real-time behavioral anomalies.

Behavioral Anomaly Detection (BAD) & Automated Network Quarantine

Prisma Cloud's BAD learns normal container behavior to detect deviations, and Automated Network Quarantine isolates compromised containers by modifying network policies in response to detected threats.

  • BAD identifies unexpected processes, network connections, file access.
  • Quarantine isolates affected workloads to prevent lateral movement.
  • Provides real-time runtime defense against zero-day and sophisticated attacks.

Memory trick: Spot the bad, then lock it down fast!

More Cloud Workload Protection Platform (CWPP) questions