PSE-PRISMACLOUD · Question #37
Which statement applies to vulnerability management policies?
The correct answer is B. Rules explain the necessary actions when vulnerabilities are found in the resources of a customer. Option B is correct because vulnerability management policies are fundamentally defined by their rules, and those rules specify what actions should be taken (alert, block, ignore, etc.) when vulnerabilities are detected in customer resources - this is the core purpose of a…
Question
Which statement applies to vulnerability management policies?
Options
- AHost and serverless rules support blocking, whereas container rules do not.
- BRules explain the necessary actions when vulnerabilities are found in the resources of a customer
- CPolicies for containers, hosts, and serverless functions are not separate.
- DRules are evaluated in an undefined order.
How the community answered
(37 responses)- A3% (1)
- B92% (34)
- C5% (2)
Explanation
Option B is correct because vulnerability management policies are fundamentally defined by their rules, and those rules specify what actions should be taken (alert, block, ignore, etc.) when vulnerabilities are detected in customer resources - this is the core purpose of a policy.
Why the distractors are wrong:
- A is incorrect because blocking support varies by implementation, but it's not universally true that host/serverless support blocking while containers do not - this reverses or misrepresents actual capability parity.
- C is incorrect because container, host, and serverless policies are managed separately, each with their own distinct rule sets tailored to the resource type.
- D is incorrect because rules in vulnerability management policies are evaluated in a defined, deterministic order - typically top-down - which is essential for predictable enforcement.
Memory tip: Think of a policy as a rulebook for response: when a vulnerability is found, the rules tell you what to do about it. "Rules = Required Actions" - the R's match.
Topics
Community Discussion
No community discussion yet for this question.