Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy

A development team is using Prisma Cloud's Image Security to scan their container images. They frequently encounter situations where certain vulnerabilities reported by Prisma Cloud are known to be non-exploitable in their specific application context. To prevent these known non-issues from cluttering reports and to focus on critical findings, which feature should the team utilize?

  1. ARuntime Defense Policies
  2. BVulnerability Explorer
  3. CAdmission Control Policies
  4. DVulnerability Exploitability Exchange (VEX)
Show answer & explanation

Correct answer: D. Vulnerability Exploitability Exchange (VEX)

Vulnerability Exploitability Exchange (VEX) allows teams to mark specific vulnerabilities as not exploitable, not applicable, or fixed in their context, reducing noise in reports and focusing on actionable findings.

Why the other options are wrong

  • A. Runtime Defense Policies monitor and protect running containers, not for managing vulnerability scan results.
  • B. Vulnerability Explorer is a tool to view and analyze vulnerabilities, not to suppress known non-issues.
  • C. Admission Control Policies enforce rules at deployment time, not for filtering vulnerability reports.

Vulnerability Exploitability Exchange (VEX)

VEX is a form of security advisory that provides additional context about vulnerabilities, specifically whether a product is affected by a known vulnerability and if it's exploitable.

  • Reduces 'alert fatigue' by clarifying actual risk.
  • Allows security teams to focus on truly exploitable vulnerabilities.
  • Can be used to mark vulnerabilities as 'not affected', 'fixed', or 'under investigation'.

Memory trick: Don't just scan, understand and act on what truly matters.

More Cloud Workload Protection Platform (CWPP) questions