Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

A security analyst is investigating a potential compromise on a Linux host protected by Prisma Cloud's Host Defender. They need to review a chronological sequence of all system calls and network connections made by a suspicious process. Which specific feature of Host Defender provides this detailed audit trail?

  1. ARuntime Forensics
  2. BImage Assurance
  3. CVulnerability Explorer
  4. DCompliance Explorer
Show answer & explanation

Correct answer: A. Runtime Forensics

Runtime Forensics in Prisma Cloud's Host Defender captures and stores detailed information about process activity, network connections, and system calls, making it invaluable for incident response and post-mortem analysis.

Why the other options are wrong

  • B. Image Assurance evaluates the security posture of container images, not running host processes.
  • C. Vulnerability Explorer focuses on identifying software vulnerabilities, not runtime process activity.
  • D. Compliance Explorer assesses adherence to security benchmarks, not dynamic process behavior.

Prisma Cloud Runtime Forensics

A Host Defender capability that records detailed runtime activity, including system calls and network connections, for incident investigation and security analysis.

  • Captures process execution details.
  • Records network communication events.
  • Aids in post-incident analysis and threat hunting.

Memory trick: To solve the host mystery, forensics reveals the runtime story.

More Cloud Workload Protection Platform (CWPP) questions