Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy
A security analyst is investigating a suspected supply chain attack targeting their container images. They need to quickly identify if any images in their private registry contain software components with known vulnerabilities that have recent exploits. Which Prisma Cloud feature should the analyst leverage for this task?
- AHost Security
- BCompliance Explorer
- CServerless Security
- DRegistry Scanning
Show answer & explanationAnswer & explanation
Correct answer: D. Registry Scanning
Registry Scanning specifically targets container images stored in registries, analyzing them for vulnerabilities, malware, and compliance issues. This is the direct feature for identifying vulnerable components within images in a private registry.
Why the other options are wrong
- A. Host Security protects virtual machines and physical servers, not container images in a registry.
- B. Compliance Explorer evaluates configurations against benchmarks, it doesn't scan images for vulnerabilities directly.
- C. Serverless Security focuses on protecting serverless functions, not container images.
Registry Scanning
Prisma Cloud feature that scans container images residing in registries for vulnerabilities, malware, and compliance issues.
- Scans images at rest in registries (e.g., Docker Hub, ECR, GCR).
- Identifies known CVEs, malware, and sensitive data.
- Provides a continuous view of image security posture before deployment.
Memory trick: Registry Scanning: Think of it as a 'customs check' for images arriving in your port.