Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A security architect is designing a strategy to protect a highly sensitive web application deployed on Kubernetes. They need to ensure that any new processes started within the application's containers are legitimate and that network connections are restricted to only approved destinations, even if the application code is compromised. Which Prisma Cloud Container Security feature is BEST suited to enforce these granular runtime controls?
- ARuntime Process and Network Policies
- BImage Vulnerability Scanning
- CRegistry Image Assurance
- DHost Compliance Scanning
Show answer & explanationAnswer & explanation
Correct answer: A. Runtime Process and Network Policies
Runtime Process and Network Policies in Prisma Cloud allow for granular control over what processes can run and where containers can connect, providing a strong defense against compromised applications. These policies are enforced at runtime, offering protection even if vulnerabilities are exploited.
Why the other options are wrong
- B. Image Vulnerability Scanning identifies issues before deployment but doesn't protect against runtime exploits.
- C. Registry Image Assurance ensures images meet security standards prior to deployment, but not runtime behavior.
- D. Host Compliance Scanning focuses on the underlying host's configuration, not granular container behavior.
Prisma Cloud Runtime Process and Network Policies
These policies define and enforce permitted process execution and network connections within containers during runtime.
- Enforce granular controls within running containers.
- Prevent unauthorized processes and network communication.
- Crucial for containing exploits and maintaining application integrity.
Memory trick: Runtime policies are like a container's personal bodyguard, watching every move and connection.