Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard
A security engineer has configured Prisma Cloud to monitor for critical vulnerabilities in their container images. They've identified several images with high-severity CVEs that are currently running in production. Due to operational constraints, these images cannot be immediately updated. The engineer needs to apply a temporary mitigation to prevent exploitation of these known vulnerabilities at runtime. Which Prisma Cloud feature allows for such a virtual patching mechanism?
- ABehavioral Anomaly Detection (BAD)
- BVulnerability Shielding
- CRegistry Scanning
- DAdmission Control
Show answer & explanationAnswer & explanation
Correct answer: B. Vulnerability Shielding
Vulnerability Shielding (also known as virtual patching) is a Prisma Cloud runtime defense feature that allows administrators to apply a protective layer to running containers, preventing the exploitation of known vulnerabilities without requiring the underlying image to be immediately patched or redeployed.
Why the other options are wrong
- A. BAD detects anomalous behavior, not a direct mitigation for known vulnerabilities.
- C. Registry Scanning identifies vulnerabilities in images at rest, but doesn't provide runtime protection.
- D. Admission Control prevents deployment, but doesn't protect already running vulnerable images.
Vulnerability Shielding (Virtual Patching)
A Prisma Cloud runtime defense capability that virtually patches known vulnerabilities in running containers, preventing their exploitation.
- Mitigates risks from unpatched CVEs in production.
- Does not require immediate image rebuild or redeployment.
- Acts as a temporary measure until a permanent fix can be applied.
Memory trick: Shielding: Like a temporary force field for known weaknesses.