Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy

A security architect is designing a strategy to protect new container images from known vulnerabilities before they are deployed to production. The strategy requires scanning images immediately after they are built and stored in a private Docker registry. Which Prisma Cloud capability is best suited to achieve this goal?

  1. AHost Vulnerability Scanning
  2. BRuntime Defense
  3. CRegistry Scanning
  4. DServerless Function Protection
Show answer & explanation

Correct answer: C. Registry Scanning

Registry Scanning in Prisma Cloud is specifically designed to integrate with container registries, pulling and scanning images for vulnerabilities as soon as they are pushed, ensuring early detection before deployment.

Why the other options are wrong

  • A. Host Vulnerability Scanning targets the underlying operating systems of VMs, not container images in a registry.
  • B. Runtime Defense protects containers while they are running, not proactively in the registry.
  • D. Serverless Function Protection secures serverless applications, which is a different domain than container images.

Prisma Cloud Registry Scanning

Registry scanning automatically connects to container image registries to pull and analyze images for vulnerabilities, malware, and compliance issues, enabling 'shift-left' security.

  • Scans images in registries (Docker Hub, ECR, GCR, etc.)
  • Detects vulnerabilities, malware, secrets
  • Enables security earlier in the CI/CD pipeline

Memory trick: Registry Scanning is the gatekeeper for your container images.

More Cloud Workload Protection Platform (CWPP) questions