nerdexam
Palo_Alto_Networks

PSE-PRISMACLOUD · Question #46

Which statement reflects the default vulnerability management policy?

The correct answer is D. Prisma Cloud ships all vulnerability policy with a default alert for containers, hosts, and serverless. Prisma Cloud ships its vulnerability policies with a default alert rule that covers containers, hosts, and serverless out of the box - meaning protection is broadly pre-configured across all major compute types without requiring manual setup. This makes D correct. Why the…

Workload Protection

Question

Which statement reflects the default vulnerability management policy?

Options

  • APolicy rule order has little impact on optimization.
  • BPrisma Cloud scans images in all containers immediately upon policy activation.
  • CThe default vulnerability policy rule has an alert threshold to critical.
  • DPrisma Cloud ships all vulnerability policy with a default alert for containers, hosts, and serverless

How the community answered

(59 responses)
  • A
    3% (2)
  • B
    2% (1)
  • C
    2% (1)
  • D
    93% (55)

Explanation

Prisma Cloud ships its vulnerability policies with a default alert rule that covers containers, hosts, and serverless out of the box - meaning protection is broadly pre-configured across all major compute types without requiring manual setup. This makes D correct.

Why the distractors are wrong:

  • A is incorrect because rule order does matter - policies are evaluated top-down, and rule order directly affects which rule fires and how findings are handled.
  • B is incorrect because Prisma Cloud does not immediately scan all running containers upon policy activation; scanning follows its scheduled or triggered cycles, not an instant sweep.
  • C is incorrect because the default alert threshold is set to high, not critical - critical-only thresholds would miss a significant class of vulnerabilities.

Memory tip: Think of D as Prisma Cloud's "batteries included" approach - the default policy casts the widest net possible (containers + hosts + serverless) with alerts ready to go, so you don't have to configure coverage from scratch.

Topics

#vulnerability management#default policy#alert threshold#Prisma Cloud policy

Community Discussion

No community discussion yet for this question.

Full PSE-PRISMACLOUD Practice