Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard

A security engineer has configured Prisma Cloud to monitor for critical vulnerabilities in their container images. They've identified several images with high-severity CVEs that are currently running in production. Due to operational constraints, these images cannot be immediately updated. The engineer needs to apply a temporary mitigation to prevent exploitation of these known vulnerabilities at runtime. Which Prisma Cloud feature allows for such a virtual patching mechanism?

  1. ABehavioral Anomaly Detection (BAD)
  2. BVulnerability Shielding
  3. CRegistry Scanning
  4. DAdmission Control
Show answer & explanation

Correct answer: B. Vulnerability Shielding

Vulnerability Shielding (also known as virtual patching) is a Prisma Cloud runtime defense feature that allows administrators to apply a protective layer to running containers, preventing the exploitation of known vulnerabilities without requiring the underlying image to be immediately patched or redeployed.

Why the other options are wrong

  • A. BAD detects anomalous behavior, not a direct mitigation for known vulnerabilities.
  • C. Registry Scanning identifies vulnerabilities in images at rest, but doesn't provide runtime protection.
  • D. Admission Control prevents deployment, but doesn't protect already running vulnerable images.

Vulnerability Shielding (Virtual Patching)

A Prisma Cloud runtime defense capability that virtually patches known vulnerabilities in running containers, preventing their exploitation.

  • Mitigates risks from unpatched CVEs in production.
  • Does not require immediate image rebuild or redeployment.
  • Acts as a temporary measure until a permanent fix can be applied.

Memory trick: Shielding: Like a temporary force field for known weaknesses.

More Cloud Workload Protection Platform (CWPP) questions