Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy

A security operations center (SOC) analyst receives an alert from Prisma Cloud indicating unusual outbound network connections from a critical containerized application. The container is part of a Kubernetes deployment. The analyst needs to quickly determine the source process within the container that initiated these connections and gather detailed network activity. Which Prisma Cloud feature would provide this specific information?

  1. ARegistry Scan Results
  2. BRuntime Forensics for Containers
  3. CHost Vulnerability Scan Report
  4. DCompliance Explorer Report
Show answer & explanation

Correct answer: B. Runtime Forensics for Containers

Runtime Forensics in Prisma Cloud is specifically designed to capture and analyze activity within containers and hosts, including process execution, network connections, and file system changes, which is crucial for investigating unusual behavior like unauthorized outbound connections.

Why the other options are wrong

  • A. Registry Scan Results provide information about vulnerabilities in container images, not live runtime behavior.
  • C. Host Vulnerability Scan Reports focus on security flaws, not runtime network activity.
  • D. Compliance Explorer Reports assess adherence to security standards, not real-time incident investigation.

Prisma Cloud Runtime Forensics

Prisma Cloud's Runtime Forensics captures and provides detailed historical data on process execution, network activity, and file system changes within protected containers and hosts.

  • Records container and host runtime events.
  • Aids in post-incident analysis and threat hunting.
  • Provides granular details on process, network, and file system activities.

Memory trick: When a container acts strange, forensics helps rearrange the facts.

More Cloud Workload Protection Platform (CWPP) questions