Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

A security engineer is configuring Prisma Cloud's Container Security module to perform runtime defense for their Kubernetes clusters. They want to ensure that any attempt to execute an unapproved or malicious binary within a container immediately triggers an alert and prevents the execution. Which Prisma Cloud runtime defense capability should the engineer configure to achieve this?

  1. ANetwork Firewall Policy
  2. BFile Integrity Monitoring (FIM)
  3. CProcess Control Policy
  4. DVulnerability Shielding
Show answer & explanation

Correct answer: C. Process Control Policy

Process Control Policies in Prisma Cloud are designed to monitor and control process execution within containers. By configuring a 'blacklist' or 'whitelist' for binaries, the engineer can prevent unauthorized execution and generate alerts, directly addressing the requirement.

Why the other options are wrong

  • A. Network Firewall Policies control network traffic, not process execution within a container.
  • B. File Integrity Monitoring (FIM) detects unauthorized changes to files but does not prevent process execution.
  • D. Vulnerability Shielding (Virtual Patching) protects against known vulnerabilities by applying virtual patches, not by controlling arbitrary process execution.

Prisma Cloud Process Control Policy

A Prisma Cloud runtime defense feature that allows administrators to define and enforce rules for process execution within containers, preventing unauthorized or malicious binaries from running.

  • Monitors and controls process execution in containers.
  • Can be configured with whitelists (only allowed processes) or blacklists (denied processes).
  • Generates alerts and can prevent execution based on policy violations.

Memory trick: Runtime defense is like a bouncer at the container club, checking who gets in and what they do.

More Cloud Workload Protection Platform (CWPP) questions