> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/admin-guide/32/compliance/vm-image-scanning.md).

# VM image scanning

Prisma Cloud can scan the virtual machine (VM) images in your cloud environment for the following types of vulnerabilities:

* **Host configuration**: Vulnerabilities in the VM image setup.
* **Docker daemon configuration**: Vulnerabilities that stem from misconfiguring your Docker daemon. The Docker daemon derives its configuration from various files, including `/etc/sysconfig/docker` or `/etc/default/docker`.
* **Docker daemon configuration files**: Vulnerabilities that arise from setting incorrect permissions on critical configuration files.
* **Docker security operations**: Recommendations and reminders for extending your current security best practices to include containers.
* **Linux configuration**: Compliance of Linux hosts. For example, ensure mounting of the `hfs` filesystem is disabled.

## Reviewing VM image scan reports

To view the health of the VM images in your environment:

1. Open Console, then go to **Monitor > Compliance > Hosts > VM images**.
2. Click on a VM image on the list.

   A report for the compliance issues on the VM image is shown.

   <figure><img src="/files/ZfVA3wn4a85yRFbUsvMb" alt="vm image scanning report"><figcaption></figcaption></figure>

   Select **CSV** to export a list of all the compliance issues identified in the latest VM image scan to a CSV file.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/admin-guide/32/compliance/vm-image-scanning.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
