Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A security engineer is configuring Prisma Cloud's Container Security module to protect a Kubernetes cluster. They need to ensure that all new container images deployed to the cluster are automatically scanned for critical vulnerabilities before they are allowed to run. Which Prisma Cloud feature must be configured to enforce this policy?
- AServerless Defender
- BHost Defender
- CRegistry Scan
- DAdmission Control
Show answer & explanationAnswer & explanation
Correct answer: D. Admission Control
Admission Control in Prisma Cloud integrates with Kubernetes admission controllers to intercept and evaluate requests to deploy new resources, including container images. This allows for policies to be enforced, such as blocking deployments of images with critical vulnerabilities.
Why the other options are wrong
- A. Serverless Defender is used for protecting serverless functions, not container images in a Kubernetes cluster.
- B. Host Defender inspects the host OS and running containers but does not prevent image deployment based on pre-runtime vulnerability scans.
- C. Registry Scan is for scanning images stored in registries, but it does not actively prevent a vulnerable image from being deployed if Admission Control is not also configured.
Prisma Cloud Admission Control
A feature that integrates with Kubernetes admission controllers to enforce policies on resource creation and updates, such as blocking vulnerable container images.
- Intercepts Kubernetes API requests.
- Enforces pre-defined security policies.
- Can block deployment of non-compliant images.
Memory trick: Admit only secure ships to the Kubernetes harbor.