Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A security engineer is configuring Prisma Cloud's Runtime Defense for a critical containerized application. They want to ensure that if a specific, known malicious file (e.g., a reverse shell executable) is ever created or modified within the container's filesystem, an alert is immediately triggered. Which runtime defense capability is designed to monitor for such file system events?
- AProcess Sandboxing
- BFile Integrity Monitoring (FIM)
- CNetwork Flow Analytics
- DContainer Firewall
Show answer & explanationAnswer & explanation
Correct answer: B. File Integrity Monitoring (FIM)
File Integrity Monitoring (FIM) is a core component of Prisma Cloud's runtime defense that specifically monitors for unauthorized creation, modification, or deletion of files within a container's filesystem, which is crucial for detecting malicious activity like the introduction of malware.
Why the other options are wrong
- A. Process Sandboxing isolates processes but doesn't specifically monitor file system changes.
- C. Network Flow Analytics monitors network connections, not file system activity.
- D. Container Firewall controls network traffic, not file system events.
File Integrity Monitoring (FIM)
A security control that monitors critical system and application files for unauthorized modifications, creations, or deletions.
- Detects changes to sensitive files.
- Crucial for detecting malware and tampering.
- Part of runtime defense strategies.
Memory trick: To protect container files, integrity monitoring is the watchful eye.