Courseiva
Cloud SecurityhardMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner Cloud Security Practice Question

An administrator is investigating a security alert in Prisma Cloud where a container image in an Amazon ECR registry has a critical CVE. The engineering team wants to prevent CI/CD pipelines from building or pushing images that contain critical vulnerabilities. Which Prisma Cloud feature should be implemented?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Integrate the Prisma Cloud Compute CI/CD scanner plugin into the pipeline to block builds containing critical vulnerabilities.

Prisma Cloud Compute provides CI/CD scanner plugins (Jenkins, GitLab, GitHub Actions, etc.) that evaluate container images during the build phase and fail the build if vulnerabilities exceed a specified threshold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure an AWS CloudWatch alarm to trigger a Lambda function that deletes the ECR registry repository.

    Why it's wrong here

    Incorrect. Deleting repositories disrupts operations rather than preventing vulnerable builds.

  • Integrate the Prisma Cloud Compute CI/CD scanner plugin into the pipeline to block builds containing critical vulnerabilities.

    Why this is correct

    Correct. Prisma Cloud Compute CI/CD plugins scan images during build and can block builds if vulnerabilities exceed policy thresholds.

  • Enable Prisma Access Threat Prevention on the CI/CD runner network interface.

    Why it's wrong here

    Incorrect. Prisma Access inspects network traffic, not container image layers in CI/CD pipelines.

  • Configure Prisma Cloud CSPM to automatically revoke AWS IAM credentials for the CI/CD builder.

    Why it's wrong here

    Incorrect. Revoking IAM credentials stops all builds rather than selectively blocking vulnerable container images.

About these practice questions

This Cybersecurity-Practitioner question is part of Courseiva's 206-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.