Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

A security engineer is configuring Prisma Cloud's Runtime Defense for a critical containerized application. They want to ensure that if a specific, known malicious file (e.g., a reverse shell executable) is ever created or modified within the container's filesystem, an alert is immediately triggered. Which runtime defense capability is designed to monitor for such file system events?

  1. AProcess Sandboxing
  2. BFile Integrity Monitoring (FIM)
  3. CNetwork Flow Analytics
  4. DContainer Firewall
Show answer & explanation

Correct answer: B. File Integrity Monitoring (FIM)

File Integrity Monitoring (FIM) is a core component of Prisma Cloud's runtime defense that specifically monitors for unauthorized creation, modification, or deletion of files within a container's filesystem, which is crucial for detecting malicious activity like the introduction of malware.

Why the other options are wrong

  • A. Process Sandboxing isolates processes but doesn't specifically monitor file system changes.
  • C. Network Flow Analytics monitors network connections, not file system activity.
  • D. Container Firewall controls network traffic, not file system events.

File Integrity Monitoring (FIM)

A security control that monitors critical system and application files for unauthorized modifications, creations, or deletions.

  • Detects changes to sensitive files.
  • Crucial for detecting malware and tampering.
  • Part of runtime defense strategies.

Memory trick: To protect container files, integrity monitoring is the watchful eye.

More Cloud Workload Protection Platform (CWPP) questions