Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard
A development team is using Prisma Cloud's Image Security to scan their container images. They have identified several high-severity vulnerabilities in a third-party base image that cannot be immediately patched due to vendor limitations. To prevent these known vulnerabilities from blocking their Continuous Integration/Continuous Deployment (CI/CD) pipeline while still tracking them, which Prisma Cloud feature should the security engineer configure?
- ADisable image scanning for the affected repository.
- BCreate a custom compliance policy to ignore the vulnerabilities.
- CUtilize the Vulnerability Exploitability eXchange (VEX) document feature.
- DImplement a runtime defense policy to block image deployment.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilize the Vulnerability Exploitability eXchange (VEX) document feature.
The VEX document feature in Prisma Cloud allows organizations to formally declare the exploitability status of identified vulnerabilities, including justifications for why a vulnerability might not be exploitable or cannot be remediated immediately. This enables the team to track and manage the risk without halting the CI/CD pipeline.
Why the other options are wrong
- A. Disabling image scanning would remove visibility into all vulnerabilities, which is not ideal for tracking and managing risk.
- B. Custom compliance policies can ignore vulnerabilities, but VEX provides a more standardized and auditable way to manage the 'why' behind ignoring them.
- D. A runtime defense policy would block deployment, which is contrary to the goal of not blocking the pipeline while tracking the vulnerabilities.
Vulnerability Exploitability eXchange (VEX)
VEX is a mechanism to communicate the exploitability status of identified vulnerabilities in software components, providing context for risk management decisions.
- Provides a formal way to declare vulnerability exploitability.
- Helps manage vulnerabilities that cannot be immediately remediated.
- Integrates with vulnerability management workflows for nuanced risk assessment.
Memory trick: VEX provides the context to flex past unpatchable defects.