Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard
A large enterprise is migrating its legacy applications to a cloud-native architecture using Kubernetes. They require real-time protection against zero-day attacks and anomalous behavior within their running containers, including unauthorized process execution and privilege escalation attempts. Which Prisma Cloud CWPP capability is designed to learn normal container behavior and then detect and prevent deviations at runtime?
- ACompliance Policy
- BStatic Analysis Policy
- CDynamic Analysis Policy
- DBehavioral Anomaly Detection
Show answer & explanationAnswer & explanation
Correct answer: D. Behavioral Anomaly Detection
Prisma Cloud's Behavioral Anomaly Detection capability, part of its runtime defense, observes and learns the normal operational baseline for containers. It then uses this baseline to identify and alert on or block any deviations that could indicate a zero-day attack or malicious activity.
Why the other options are wrong
- A. Compliance Policy checks configurations against standards, not runtime behavior.
- B. Static Analysis Policy scans code/images without running them, not for runtime behavior.
- C. Dynamic Analysis Policy typically involves running code in a sandbox, but the question specifies 'learn normal container behavior' and 'detect and prevent deviations at runtime' in production.
Prisma Cloud Behavioral Anomaly Detection
Behavioral Anomaly Detection in Prisma Cloud's runtime defense automatically learns the normal operational patterns of containers, processes, and network activity. It then identifies and flags or blocks any deviations from this baseline, helping to detect zero-day threats and insider attacks.
- Learns normal behavior baseline
- Detects deviations (anomalies)
- Protects against zero-days and unknown threats
- Part of runtime defense
Memory trick: Behavioral Anomaly Detection is the smart guard, knowing what's 'normal'.