Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard

A security engineer is analyzing a container's behavior in production using Prisma Cloud. They observe an outbound network connection from the container to an IP address that is known to be associated with command-and-control (C2) servers. Which aspect of Prisma Cloud's runtime defense would flag this specific type of suspicious activity?

  1. AImage Vulnerability Scan
  2. BCompliance Check
  3. CHost Firewall Configuration
  4. DThreat Intelligence Feed Integration
Show answer & explanation

Correct answer: D. Threat Intelligence Feed Integration

Prisma Cloud's runtime defense integrates with threat intelligence feeds. When a container attempts to communicate with an IP address or domain identified as malicious (e.g., a known C2 server) by these feeds, it triggers an alert, indicating a potential compromise.

Why the other options are wrong

  • A. Image Vulnerability Scan identifies flaws in the image, not runtime C2 communication.
  • B. Compliance Check assesses configuration against benchmarks, not active malicious network connections.
  • C. Host Firewall Configuration controls network access at the host level but doesn't inherently know about C2 server IPs without specific rules or integration.

Prisma Cloud Threat Intelligence

Integration of external threat intelligence feeds into Prisma Cloud's runtime defense to identify and alert on communication with known malicious IP addresses, domains, or other indicators of compromise.

  • Leverages external security data.
  • Detects communication with C2 servers, malware domains.
  • Enhances real-time threat detection.

Memory trick: Smart defense uses threat intelligence to spot known bad guys.

More Cloud Workload Protection Platform (CWPP) questions