Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy

A security engineer is tasked with ensuring that all container images used in their Kubernetes clusters comply with internal security policies before they are deployed. Specifically, images must not contain any critical or high-severity vulnerabilities, and they must originate from approved registries. Which Prisma Cloud feature, when integrated into the Kubernetes admission controller, can enforce these checks?

  1. AAdmission Control
  2. BContainer Runtime Defense
  3. CServerless Protection
  4. DImage Vulnerability Exploitability eXchange (VEX)
Show answer & explanation

Correct answer: A. Admission Control

Prisma Cloud's Admission Control integrates with Kubernetes to intercept deployment requests and enforce policies (like vulnerability thresholds and approved registries) before pods are created. This prevents non-compliant images from ever running in the cluster.

Why the other options are wrong

  • B. Container Runtime Defense protects running containers, but Admission Control prevents non-compliant containers from starting.
  • C. Serverless Protection is for serverless functions, not container images in Kubernetes.
  • D. VEX helps manage identified vulnerabilities but doesn't enforce deployment policies directly.

Prisma Cloud Admission Control

Prisma Cloud's Admission Control integrates with Kubernetes to enforce security policies on container images and deployments before they are allowed to run in the cluster.

  • Intercepts Kubernetes deployment requests.
  • Enforces policies like vulnerability thresholds and approved registries.
  • Prevents non-compliant images/deployments from running.

Memory trick: Admission Control guards the Kubernetes gate, preventing bad images from their fate.

More Cloud Workload Protection Platform (CWPP) questions