A cloud-native security platform protects cloud-native applications across their lifecycle, including runtime. Runtime protection means monitoring and securing workloads while they are actively running, such as containers, microservices, serverless functions, Kubernetes clusters, and cloud workloads. This can include detecting suspicious process behavior, enforcing workload policies, identifying misconfigurations, controlling network connections, and responding to active threats. Cost analysis may exist in cloud management platforms, but it is not a core CNSP security function. Sandboxing ransomware is a malware analysis technique, not the defining role of a cloud-native security platform. Penetration testing may be part of security assessment, but CNSP is designed for continuous visibility, posture, identity, workload, and runtime security rather than one-time offensive testing. CNSP matters because cloud-native environments are dynamic: workloads scale, containers are replaced, APIs interact continuously, and identities drive access. Security must therefore be integrated into build, deploy, and runtime phases. Reference/topics: Cloud Security 5.5, CNSP; Cloud Security 5.4, containers, microservices, APIs.