Join the discussion
Question 103/162
Which three actions are available for the container image scanning compliance rule? (Choose three.)
Correct Answer: C,D,E
The Prisma Cloud documentation specifies the actions that can be taken for container image scanning compliance rules as:
C). Block: This action prevents the use of a container image if it fails to meet the defined compliance criteria.
D). Ignore: This action allows the image to bypass the compliance check, effectively overlooking the identified issues.
E). Alert: This action triggers an alert to notify the relevant stakeholders about the compliance status of the container image.
These actions are integral to Prisma Cloud's governance capabilities, allowing organizations to enforce their security and compliance policies effectively. By setting up these rules, teams can ensure that only images that comply with their standards are deployed, while also having the flexibility to ignore certain images or receive alerts for further investigation.
C). Block: This action prevents the use of a container image if it fails to meet the defined compliance criteria.
D). Ignore: This action allows the image to bypass the compliance check, effectively overlooking the identified issues.
E). Alert: This action triggers an alert to notify the relevant stakeholders about the compliance status of the container image.
These actions are integral to Prisma Cloud's governance capabilities, allowing organizations to enforce their security and compliance policies effectively. By setting up these rules, teams can ensure that only images that comply with their standards are deployed, while also having the flexibility to ignore certain images or receive alerts for further investigation.
Add Comments
- Other Question (162q)
- Q1. A customer finds that an open alert from the previous day has been resolved. No auto- reme...
- Q2. The security team wants to protect a web application container from an SQLi attack. Which ...
- Q3. Which Prisma Cloud policy type can protect against malware?...
- Q4. Which method should be used to authenticate to Prisma Cloud Enterprise programmatically?...
- Q5. Which two CI/CD plugins are supported by Prisma Cloud as part of its Code Security? (Choos...
- Q6. Which three incident types will be reflected in the Incident Explorer section of Runtime D...
- Q7. A manager informs the SOC that one or more RDS instances have been compromised and the SOC...
- Q8. Which method should be used to authenticate to Prisma Cloud Enterprise programmatically?...
- Q9. The security auditors need to ensure that given compliance checks are being run on the hos...
- Q10. Which of the following is displayed in the asset inventory?...
- Q11. What are two ways to scan container images in Jenkins pipelines? (Choose two.)...
- Q12. What are the three states of the Container Runtime Model? (Choose three.)...
- Q13. Which intensity setting for anomaly alerts is used for the measurement of 100 events over ...
- Q14. Per security requirements, an administrator needs to provide a list of people who are rece...
- Q15. Based on the following information, which RQL query will satisfy the requirement to identi...
- Q16. While writing a custom RQL with array objects in the investigate page, which type of auto-...
- Q17. A developer writes a serverless application to extract a field from a file in an S3 bucket...
- Q18. A company has an Amazon S3 bucket containing personally identifiable information (PII) dat...
- Q19. In which two ways can Prisma Cloud images be retrieved in Prisma Cloud Compute Self-Hosted...
- Q20. Which action must be taken to enable a user to interact programmatically with the Prisma C...
- Q21. Which Cortex Cloud management module will show all non-human identities that have access t...
- Q22. Which two services require external notifications to be enabled for policy violations in t...
- Q23. Which step is included when configuring Kubernetes to use Prisma Cloud Compute as an admis...
- Q24. Which data security default policy is able to scan for vulnerabilities?...
- Q25. Drag and Drop Question Move the steps to the correct order to set up and execute a serverl...
- Q26. Which three types of classifications are available in the Data Security module? (Choose th...
- Q27. How are the following categorized? Backdoor account access Hijacked processes Lateral move...
- Q28. A customer has a requirement to scan serverless functions for vulnerabilities. Which three...
- Q29. Which ROL query is used to detect certain high-risk activities executed by a root user in ...
- Q30. In a cloud environment, what does Palo Alto Networks' Identity and Access Management (IAM)...
- Q31. A large hospitality chain reduces 100 runtime misconfigurations to only 10 with each new r...
- Q32. An administrator has added a Cloud account on Prisma Cloud and then deleted it. What will ...
- Q33. Which three fields are mandatory when authenticating the Prisma Cloud plugin in the Intell...
- Q34. Which two statements are true about the differences between build and run config policies?...
- Q35. Which options show the steps required to upgrade Console when using projects?...
- Q36. Prisma Cloud supports which three external systems that allow the import of vulnerabilitie...
- Q37. Which statement applies to Adoption Advisor?
- Q38. Which two roles have access to view the Prisma Cloud policies? (Choose two.)...
- Q39. Anomaly policy uses which two logs to identify unusual network and user activity? (Choose ...
- Q40. Given this information: The Console is located at https://prisma-console.mydomain.local Th...
- Q41. Which two statements explain differences between build and run config policies? (Choose tw...
- Q42. Which command correctly outputs scan results to stdout in tabular format and writes scan r...
- Q43. Drag and Drop Question What is the order of steps to create a custom network policy? (Drag...
- Q44. A customer has a requirement to automatically protect all Lambda functions with runtime pr...
- Q45. Which two processes ensure that builds can function after a Console upgrade? (Choose two.)...
- Q46. Which two statements are true about the differences between build and run config policies?...
- Q47. What should be used to associate Prisma Cloud policies with compliance frameworks?...
- Q48. A customer wants to monitor the company's AWS accounts via Prisma Cloud, but only needs th...
- Q49. The security auditors need to ensure that given compliance checks are being run on the hos...
- Q50. Which two IDE plugins are supported by Prisma Cloud as part of its DevOps Security? (Choos...
- Q51. The administrator wants to review the Console audit logs from within the Console. Which pa...
- Q52. Which three serverless runtimes are supported by Prisma Cloud for vulnerability and compli...
- Q53. Which of the following is not a supported external integration for receiving Prisma Cloud ...
- Q54. In which two instances is it appropriate to implement the Kubernetes Connector instead of ...
- Q55. Where are Top Critical CVEs for deployed images found?...
- Q56. Which action should be taken to investigate multiple log sources when researching a known ...
- Q57. A security engineer needs to transfer dashboard configurations between the company's Corte...
- Q58. Which two proper agentless scanning modes are supported with Prisma Cloud? (Choose two)....
- Q59. Which two bot categories belong to unknown bots under Web-Application and API Security (WA...
- Q60. Which of the following is not a supported external integration for receiving Prisma Cloud ...
- Q61. Which options show the steps required after upgrade of Console?...
- Q62. Which IAM RQL query would correctly generate an output to view users who enabled console a...
- Q63. Which two proper agentless scanning modes are supported with Prisma Cloud? (Choose two)....
- Q64. Which "kind" of Kubernetes object is configured to ensure that Defender is acting as the a...
- Q65. A customer wants to harden its environment from misconfiguration. Prisma Cloud Compute Com...
- Q66. Which two CI/CD plugins are supported by Prisma Cloud as part of its DevOps Security? (Cho...
- Q67. Which of the following is a key benefit of using Palo Alto Networks' Next-Generation Firew...
- Q68. What is the default namespace created by Defender DaemonSet during deployment?...
- Q69. You are tasked with configuring a Prisma Cloud build policy for Terraform. What type of qu...
- Q70. A user notices new Amazon EKS cluster endpoints connected to the Cortex Cloud console and ...
- Q71. Which statement is true about obtaining Console images for Prisma Cloud Compute Edition?...
- Q72. Given a default deployment of Console, a customer needs to identify the alerted compliance...
- Q73. What is the function of the external ID when onboarding a new Amazon Web Services (AWS) ac...
- Q74. A security team is deploying Cloud Native Application Firewall (CNAF) on a containerized w...
- Q75. Which three AWS policy types and identities are used to calculate the net effective permis...
- Q76. Which data storage type is supported by Prisma Cloud Data Security?...
- Q77. How can CVEs be prioritized using a data-driven approach in the Vulnerability Management t...
- Q78. Which Defender type performs registry scanning?...
- Q79. What are two key requirements for integrating Okta with Prisma Cloud when multiple Amazon ...
- Q80. Which RQL will trigger the following audit event activity?...
- Q81. Which of the following is a reason for alert dismissal?...
- Q82. An administrator has added a Cloud account on Prisma Cloud and then deleted it. What will ...
- Q83. What is the correct method for ensuring key-sensitive data related to SSNs and credit card...
- Q84. Under which tactic is "Exploit Public-Facing Application" categorized in the ATT&CK fr...
- Q85. Which two bot types are part of Web Application and API Security (WAAS) bot protection? (C...
- Q86. When an alert notification from the alarm center is deleted, how many hours will a similar...
- Q87. The development team wants to block Cross Site Scripting attacks from pods in its environm...
- Q88. Which three AWS policy types and identities are used to calculate the net effective permis...
- Q89. An administrator of Prisma Cloud wants to enable role-based access control for Docker engi...
- Q90. How is the scope of each rule determined in the Prisma Cloud Compute host runtime policy?...
- Q91. Which three Orchestrator types are supported when deploying Defender? (Choose three.)...
- Q92. What happens when a role is deleted in Prisma Cloud?...
- Q93. Prisma Cloud supports which three external systems that allow the import of vulnerabilitie...
- Q94. Where can a user submit an external new feature request?...
- Q95. Which three types of buckets exposure are available in the Data Security module? (Choose t...
- Q96. A Systems Engineer is the administrator of a self-hosted Prisma Cloud console. They upgrad...
- Q97. Which action can cloud workload protection (CWP) prevent?...
- Q98. The Prisma Cloud administrator has configured a new policy. Which steps should be used to ...
- Q99. How can a company use Cortex XSIAM to automate security operations and enhance threat dete...
- Q100. Which statement applies to Adoption Advisor?
- Q101. The security team wants to target a CNAF policy for specific running Containers. How shoul...
- Q102. Which option identifies the Prisma Cloud Compute Edition?...
- Q103. Which three actions are available for the container image scanning compliance rule? (Choos...
- Q104. A customer has Prisma Cloud Enterprise and host Defenders deployed. What are two options t...
- Q105. What is the most reliable and extensive source for documentation on Prisma Cloud APIs?...
- Q106. Which two frequency options are available to create a compliance report within the console...
- Q107. How can a security team use Data Security Posture Management (DSPM) to ensure that the AI-...
- Q108. Which three public cloud providers are supported for VM image scanning? (Choose three.)...
- Q109. The security team wants to target a CNAF policy for specific running Containers. How shoul...
- Q110. A customer has serverless functions that are deployed in multiple clouds. Which serverless...
- Q111. An administrator has been tasked with a requirement by your DevSecOps team to write a scri...
- Q112. Which two required request headers interface with Prisma Cloud API? (Choose two.)...
- Q113. An administrator of Prisma Cloud wants to enable role-based access control for Docker engi...
- Q114. A company operationalizing Cortex Cloud Data Security Posture Management (DSPM) experience...
- Q115. What is the primary purpose of the Palo Alto Networks' Cortex XDR for cloud environments?...
- Q116. Put the steps of integrating Okta with Prisma Cloud in the right order in relation to CIEM...
- Q117. What are the three states of the Container Runtime Model? (Choose three.)...
- Q118. Which role does Prisma Cloud play when configuring SSO?...
- Q119. An administrator has a requirement to ingest all Console and Defender logs to Splunk. Whic...
- Q120. Which Cortex Cloud report is most appropriate for a cybersecurity director to receive crit...
- Q121. Which report includes an executive summary and a list of policy violations, including a pa...
- Q122. What is the purpose of Incident Explorer in Prisma Cloud Compute under the "Monitor" secti...
- Q123. Which file extension type is supported for Malware scanning in Prisma Cloud Data Security ...
- Q124. What will happen when a Prisma Cloud Administrator has configured agentless scanning in an...
- Q125. A customer has multiple violations in the environment including: User namespace is enabled...
- Q126. What is the primary purpose of Prisma Cloud Code Security?...
- Q127. A customer has a requirement to scan serverless functions for vulnerabilities. What is the...
- Q128. An administrator sees that a runtime audit has been generated for a host. The audit messag...
- Q129. Prisma Cloud supports sending audit event records to which three targets? (Choose three.)...
- Q130. Which step should a SecOps engineer implement in order to create a network exposure policy...
- Q131. Which resource and policy type are used to calculate AWS Net Effective Permissions? (Choos...
- Q132. Which alert deposition severity must be chosen to generate low and high severity alerts in...
- Q133. Which three actions are available for the container image scanning compliance rule? (Choos...
- Q134. Which three options are selectable in a CI policy for image scanning with Jenkins or twist...
- Q135. A customer has a large environment that needs to upgrade Console without upgrading all Def...
- Q136. Which security model does Palo Alto Networks Prisma Cloud use for multi-cloud environments...
- Q137. Where are Top Critical CVEs for deployed images found?...
- Q138. A customer wants to monitor its Amazon Web Services (AWS) accounts via Prisma Cloud, but o...
- Q139. You are an existing customer of Prisma Cloud Enterprise. You want to onboard a public clou...
- Q140. What is an automatically correlated set of individual events generated by the firewall and...
- Q141. A Systems Engineer is the administrator of a self-hosted Prisma Cloud console. They upgrad...
- Q142. When is it advantageous to deploy a Cortex XDR agent with advanced endpoint protection for...
- Q143. Review this admission control policy: match[{"msg": msg}] { input.request.operation == "CR...
- Q144. Which set of steps is the correct process for obtaining Console images for Prisma Cloud Co...
- Q145. Prisma Cloud cannot integrate which of the following secrets managers?...
- Q146. Which two required request headers interface with Prisma Cloud API? (Choose two.)...
- Q147. The exclamation mark on the resource explorer page would represent?...
- Q148. Which two statements apply to the Defender type Container Defender - Linux?...
- Q149. Which three options are selectable in a CI policy for image scanning with Jenkins or twist...
- Q150. Given the following audit event activity snippet: (Exhibit) Which RQL will be triggered by...
- Q151. Which of the following are correct statements regarding the use of access keys? (Choose tw...
- Q152. Which two actions are required in order to use the automated method within Amazon Web Serv...
- Q153. What improves product operationalization by adding visibility into feature utilization and...
- Q154. An administrator sees that a runtime audit has been generated for a container. The audit m...
- Q155. A customer has a large environment that needs to upgrade Console without upgrading all Def...
- Q156. A customer has a requirement to terminate any Container from image topSecret:latest when a...
- Q157. Which command should be used in the Prisma Cloud twistcli tool to scan the nginx:latest im...
- Q158. Given the following RQL: event from cloud.audit_logs where operation IN (`CreateCryptoKey'...
- Q159. A customer has configured the JIT, and the user created by the process is trying to log in...
- Q160. Which three options for hardening a customer environment against misconfiguration are incl...
- Q161. In addition to risks on an AI model, what other information presented in AI Security Postu...
- Q162. One of the resources on the network has triggered an alert for a Default Config policy. Gi...
[×]
Download PDF File
Enter your email address to download PaloAltoNetworks.CloudSec-Pro.v2026-09-10.q162.pdf
