Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard

A security engineer is configuring Prisma Cloud to monitor for deviations from established security best practices on Kubernetes clusters. Beyond basic vulnerability scanning, they need to ensure that Kubernetes API server configurations, network policies, and pod security policies adhere to organizational standards and industry benchmarks like CIS Kubernetes Benchmark. Which Prisma Cloud capability directly addresses this comprehensive compliance monitoring for Kubernetes resources?

  1. AKubernetes Compliance Explorer
  2. BServerless Compliance Dashboard
  3. CHost Defender Compliance
  4. DVulnerability Explorer for Images
Show answer & explanation

Correct answer: A. Kubernetes Compliance Explorer

Prisma Cloud's Kubernetes Compliance Explorer (often part of the broader Compliance Explorer but with specific Kubernetes focus) is designed to scan and report on the compliance posture of Kubernetes cluster configurations and deployed resources against various benchmarks and custom policies.

Why the other options are wrong

  • B. Serverless Compliance Dashboard is for serverless functions, not Kubernetes clusters.
  • C. Host Defender Compliance is for the underlying hosts/VMs, not Kubernetes-specific configurations like API server or network policies.
  • D. Focuses only on image vulnerabilities, not broader Kubernetes cluster configurations.

Prisma Cloud Kubernetes Compliance Explorer

The Kubernetes Compliance Explorer in Prisma Cloud provides continuous assessment of Kubernetes cluster configurations (e.g., API server, controllers, network policies, pod security) against industry benchmarks (like CIS Kubernetes Benchmark) and custom organizational policies, reporting on deviations.

  • Monitors Kubernetes cluster configurations
  • Checks against CIS Kubernetes Benchmark and custom policies
  • Covers API server, network policies, and more
  • Provides continuous compliance reporting

Memory trick: Kubernetes Compliance Explorer is the auditor for your K8s setup.

More Cloud Workload Protection Platform (CWPP) questions