Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy
A security architect is designing a strategy to protect new container images from known vulnerabilities before they are deployed to production. The strategy requires scanning images immediately after they are built and stored in a private Docker registry. Which Prisma Cloud capability is best suited to achieve this goal?
- AHost Vulnerability Scanning
- BRuntime Defense
- CRegistry Scanning
- DServerless Function Protection
Show answer & explanationAnswer & explanation
Correct answer: C. Registry Scanning
Registry Scanning in Prisma Cloud is specifically designed to integrate with container registries, pulling and scanning images for vulnerabilities as soon as they are pushed, ensuring early detection before deployment.
Why the other options are wrong
- A. Host Vulnerability Scanning targets the underlying operating systems of VMs, not container images in a registry.
- B. Runtime Defense protects containers while they are running, not proactively in the registry.
- D. Serverless Function Protection secures serverless applications, which is a different domain than container images.
Prisma Cloud Registry Scanning
Registry scanning automatically connects to container image registries to pull and analyze images for vulnerabilities, malware, and compliance issues, enabling 'shift-left' security.
- Scans images in registries (Docker Hub, ECR, GCR, etc.)
- Detects vulnerabilities, malware, secrets
- Enables security earlier in the CI/CD pipeline
Memory trick: Registry Scanning is the gatekeeper for your container images.