Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy
A security team is implementing a robust vulnerability management program for their containerized applications. They need to ensure that all container images, both new and existing, are continuously scanned for known vulnerabilities and misconfigurations, and that developers are immediately notified of critical issues. Which Prisma Cloud feature is essential for automating this process across their entire image lifecycle?
- AHost Security Defender
- BServerless Function Protection
- CContainer Runtime Defense
- DImage & Registry Scanning
Show answer & explanationAnswer & explanation
Correct answer: D. Image & Registry Scanning
Image and Registry Scanning in Prisma Cloud automates the process of identifying vulnerabilities and misconfigurations in container images, both in registries and during the build process, enabling continuous monitoring and timely remediation.
Why the other options are wrong
- A. Host Security Defender protects the underlying hosts, not the container images themselves.
- B. Serverless Function Protection focuses on serverless environments, not container images.
- C. Container Runtime Defense protects running containers, not the static images.
Prisma Cloud Image & Registry Scanning
Automated scanning of container images in registries, CI/CD pipelines, and deployed containers for vulnerabilities and misconfigurations.
- Identifies known CVEs and compliance issues.
- Integrates into CI/CD for shift-left security.
- Provides continuous monitoring of image security.
Memory trick: Scan every image, everywhere, all the time, to catch threats before they run.