Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard

A development team is using Prisma Cloud's Image Security to scan their container images. They have identified several high-severity vulnerabilities in a third-party base image that cannot be immediately patched due to vendor limitations. To prevent these known vulnerabilities from blocking their Continuous Integration/Continuous Deployment (CI/CD) pipeline while still tracking them, which Prisma Cloud feature should the security engineer configure?

  1. ADisable image scanning for the affected repository.
  2. BCreate a custom compliance policy to ignore the vulnerabilities.
  3. CUtilize the Vulnerability Exploitability eXchange (VEX) document feature.
  4. DImplement a runtime defense policy to block image deployment.
Show answer & explanation

Correct answer: C. Utilize the Vulnerability Exploitability eXchange (VEX) document feature.

The VEX document feature in Prisma Cloud allows organizations to formally declare the exploitability status of identified vulnerabilities, including justifications for why a vulnerability might not be exploitable or cannot be remediated immediately. This enables the team to track and manage the risk without halting the CI/CD pipeline.

Why the other options are wrong

  • A. Disabling image scanning would remove visibility into all vulnerabilities, which is not ideal for tracking and managing risk.
  • B. Custom compliance policies can ignore vulnerabilities, but VEX provides a more standardized and auditable way to manage the 'why' behind ignoring them.
  • D. A runtime defense policy would block deployment, which is contrary to the goal of not blocking the pipeline while tracking the vulnerabilities.

Vulnerability Exploitability eXchange (VEX)

VEX is a mechanism to communicate the exploitability status of identified vulnerabilities in software components, providing context for risk management decisions.

  • Provides a formal way to declare vulnerability exploitability.
  • Helps manage vulnerabilities that cannot be immediately remediated.
  • Integrates with vulnerability management workflows for nuanced risk assessment.

Memory trick: VEX provides the context to flex past unpatchable defects.

More Cloud Workload Protection Platform (CWPP) questions