Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard

A security analyst is reviewing a Prisma Cloud alert for a container that has suddenly started exhibiting high CPU usage and making numerous outbound connections to unknown IP addresses. The analyst suspects a cryptocurrency mining malware infection. Which Prisma Cloud feature would be most effective in detecting this type of behavioral anomaly without relying solely on known signatures?

  1. AStatic Code Analysis
  2. BCompliance Policy Enforcement
  3. CImage Vulnerability Scanning
  4. DBehavioral Anomaly Detection (BAD)
Show answer & explanation

Correct answer: D. Behavioral Anomaly Detection (BAD)

Prisma Cloud's Behavioral Anomaly Detection (BAD) capability establishes a baseline of normal container behavior and then alerts on significant deviations, such as unexpected high CPU usage or new outbound connections, which is highly effective for detecting zero-day threats or malware like crypto miners.

Why the other options are wrong

  • A. Static Code Analysis examines code before execution, not runtime behavior.
  • B. Compliance Policy Enforcement checks against predefined rules, not dynamic behavioral shifts.
  • C. Image Vulnerability Scanning identifies known CVEs before runtime, not behavioral anomalies.

Prisma Cloud Behavioral Anomaly Detection (BAD)

Learns the normal behavior of containers and alerts on significant deviations, providing protection against unknown threats and zero-day exploits.

  • Establishes baselines for processes, network, and file activity.
  • Detects unusual resource consumption, network patterns, or system calls.
  • Effective against novel malware and insider threats.

Memory trick: BAD detects when a container acts 'bad' by learning what's 'good'.

More Cloud Workload Protection Platform (CWPP) questions