Cybersecurity-Practitioner Cloud Security Practice Question
An administrator is investigating a security alert in Prisma Cloud where a container image in an Amazon ECR registry has a critical CVE. The engineering team wants to prevent CI/CD pipelines from building or pushing images that contain critical vulnerabilities. Which Prisma Cloud feature should be implemented?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate the Prisma Cloud Compute CI/CD scanner plugin into the pipeline to block builds containing critical vulnerabilities.
Prisma Cloud Compute provides CI/CD scanner plugins (Jenkins, GitLab, GitHub Actions, etc.) that evaluate container images during the build phase and fail the build if vulnerabilities exceed a specified threshold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an AWS CloudWatch alarm to trigger a Lambda function that deletes the ECR registry repository.
Why it's wrong here
Incorrect. Deleting repositories disrupts operations rather than preventing vulnerable builds.
- ✓
Integrate the Prisma Cloud Compute CI/CD scanner plugin into the pipeline to block builds containing critical vulnerabilities.
Why this is correct
Correct. Prisma Cloud Compute CI/CD plugins scan images during build and can block builds if vulnerabilities exceed policy thresholds.
- ✗
Enable Prisma Access Threat Prevention on the CI/CD runner network interface.
Why it's wrong here
Incorrect. Prisma Access inspects network traffic, not container image layers in CI/CD pipelines.
- ✗
Configure Prisma Cloud CSPM to automatically revoke AWS IAM credentials for the CI/CD builder.
Why it's wrong here
Incorrect. Revoking IAM credentials stops all builds rather than selectively blocking vulnerable container images.
About these practice questions
This Cybersecurity-Practitioner question is part of Courseiva's 206-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.