Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy
A security engineer is tasked with ensuring that all container images stored in their private Docker registry comply with organizational security policies before they are ever pulled and deployed. They need Prisma Cloud to automatically scan these images for vulnerabilities and compliance issues. Which Prisma Cloud capability provides this proactive security for images at rest in the registry?
- ARegistry Scan
- BHost Defender
- CAdmission Control
- DServerless Defender
Show answer & explanationAnswer & explanation
Correct answer: A. Registry Scan
Registry Scan in Prisma Cloud is specifically designed to connect to image registries (like Docker Hub, Amazon ECR, Azure Container Registry) and automatically scan stored images for vulnerabilities, malware, and compliance violations, providing proactive security before deployment.
Why the other options are wrong
- B. Host Defender protects the underlying host, not images in a registry.
- C. Admission Control enforces policies at deployment time, not for images at rest in a registry.
- D. Serverless Defender protects serverless functions, not container images in a registry.
Prisma Cloud Registry Scan
A feature that connects to container image registries to automatically scan stored images for vulnerabilities, malware, and compliance issues.
- Proactive security for images at rest.
- Scans Docker, OCI, and other registries.
- Identifies vulnerabilities and compliance violations.
Memory trick: Scan the registry to find hidden image dangers before they deploy.