Palo Alto Networks Certified Cloud Security Engineer (PCCSE) flashcards
146 free flashcards. Tap a card to flip it.
RQL Logical Operator: AND
Flip cardThe 'AND' logical operator in Resource Query Language (RQL) is used to combine multiple conditions, requiring all specified conditions to be true for a resource to be included in the query results.
- Requires all combined conditions to be met.
- Used for narrowing down results based on multiple criteria.
- Essential for precise filtering in custom policies.
Memory trick: For 'both' conditions, use 'AND'.
Prisma Cloud Resource Explorer
Flip cardA Prisma Cloud feature enabling security teams to perform powerful, ad-hoc queries on their cloud asset inventory using RQL (Resource Query Language).
- Uses RQL for flexible querying.
- Allows filtering by resource type, region, tags, network details, and more.
- Provides a comprehensive view of all inventoried cloud resources.
Memory trick: To explore resources, use RQL and query with precision.
RQL Region Attribute
Flip cardThe 'region' attribute in Resource Query Language (RQL) allows users to filter and query cloud resources based on their geographical deployment region, enabling enforcement of data residency and compliance with regional regulations.
- Filters resources by geographic location.
- Crucial for data residency compliance (e.g., GDPR).
- Applicable across all supported cloud providers.
Memory trick: For location, look to the 'region'.
Prisma Cloud Network Explorer
Flip cardA visual tool within Prisma Cloud that maps network topology, security controls, and traffic flows across cloud environments.
- Shows inter-resource connectivity.
- Visualizes security group and NACL rules.
- Helps identify potential lateral movement and egress points.
Memory trick: To explore the network, you need a good 'Network Explorer'.
Prisma Cloud Alert Suppression
Flip cardA mechanism to reduce alert noise by preventing alerts from being generated or by automatically dismissing them based on defined criteria.
- Can be configured based on policies, accounts, tags, or resource types.
- Helps focus on critical alerts.
- More granular than disabling policies.
Memory trick: Suppress rules to quiet the noise, not silence the whole show.
Prisma Cloud Attack Path Remediation
Flip cardIdentifying and implementing the most effective action to disrupt a potential attack path identified by Prisma Cloud's analysis.
- Focuses on breaking the chain of compromise.
- Often involves removing initial exposure or critical vulnerabilities.
- Prioritizes actions with the highest impact on reducing risk.
Memory trick: To break a chain, remove the 'first' weak link.
Prisma Cloud CSP Audit Log Integration
Flip cardPrisma Cloud integrates with Cloud Service Provider (CSP) audit logs (e.g., CloudTrail, Activity Log) to ingest activity data, providing detailed information about who made changes to cloud resources, when, and what API calls were involved, which is essential for forensic analysis and compliance.
- Ingests native cloud audit logs.
- Captures 'who', 'what', 'when' of changes.
- Crucial for compliance and forensic investigations.
Memory trick: To know 'who' changed 'what', check the 'CSP logs'.
Cloud Account Onboarding
Flip cardThe foundational process of connecting a cloud environment to Prisma Cloud, granting it necessary permissions to discover and collect data about cloud resources.
- First step for any CSPM activity.
- Involves granting read-only access.
- Enables resource discovery and data collection.
Memory trick: Onboarding is step one to open the cloud's door.
Prisma Cloud Automated Remediation
Flip cardPrisma Cloud's capability to automatically correct security misconfigurations or policy violations, often through integrations with cloud-native automation services.
- Can trigger serverless functions (Lambda, Cloud Functions).
- Enables self-healing cloud environments.
- Requires careful planning to avoid unintended service disruptions.
Memory trick: Automate your fixes, trigger a function, and reduce those privileges carefully.
Prisma Cloud Data Residency Enforcement (RQL)
Flip cardUsing Prisma Cloud's Resource Query Language (RQL) to create custom policies that continuously monitor and enforce data residency requirements across multi-cloud environments.
- Leverages RQL for granular region-based queries.
- Applicable across AWS, Azure, GCP.
- Ensures continuous monitoring for data residency compliance.
Memory trick: RQL is your multi-cloud border patrol for data.
RQL for GCP External IPs
Flip cardIn Prisma Cloud's Resource Query Language (RQL), the `network.externalIp` attribute is used to identify GCP Compute Engine instances that have external (public) IP addresses assigned, allowing for filtering based on public exposure.
- Identifies public IP presence on GCP instances.
- Part of the `network` object for instances.
- Crucial for assessing internet exposure.
Memory trick: For GCP public, think 'externalIp' in the 'network'.
Prisma Cloud Automated Remediation Prerequisites
Flip cardConditions that must be met for Prisma Cloud to successfully perform automated corrective actions on cloud resources.
- Requires specific IAM permissions (Remediation access).
- Policy must be configured for automated remediation.
- Supported for specific resource types and cloud providers.
Memory trick: To fix automatically, you need the 'right Remediation Access'.
Prisma Cloud Custom Policies
Flip cardUser-defined compliance rules in Prisma Cloud, crafted using RQL, to enforce specific security standards and organizational requirements.
- Leverage RQL for powerful and flexible rule creation.
- Can target specific resource types, tags, and configuration attributes.
- Enable enforcement of unique organizational policies beyond built-in standards.
Memory trick: Craft your own rules with RQL, tag your resources, and encrypt your data.
RQL for SSE-KMS CMK
Flip cardResource Query Language (RQL) queries in Prisma Cloud can be used to identify S3 buckets based on their encryption configuration, specifically differentiating between Server-Side Encryption with AWS KMS (SSE-KMS) using customer-managed keys (CMKs) versus AWS-managed keys (AMKs).
- SSE-KMS uses 'aws:kms' as encryption type.
- CMKs have a specific ARN format and do not contain ':alias/aws/'.
- AMKs often contain ':alias/aws/' in their key ID or are implicitly AWS managed.
Memory trick: To find the 'NOT', combine the 'OR' conditions.
Prisma Cloud Audit Log Integration
Flip cardPrisma Cloud's capability to ingest, normalize, and analyze cloud provider audit logs (e.g., CloudTrail, Activity Logs) to provide a historical record of events and configuration changes.
- Crucial for incident response and forensic analysis.
- Provides a chronological timeline of user and API activity.
- Helps identify root causes and scope of security incidents.
Memory trick: To reconstruct the past, follow the audit logs, event by event.
Prisma Cloud Custom Compliance Standards
Flip cardAllows users to define new compliance frameworks and map existing Prisma Cloud policies to their specific requirements.
- Extends Prisma Cloud's compliance reporting.
- Maps to internal or external regulations (e.g., GDPR, HIPAA).
- Provides a consolidated view of compliance posture against custom standards.
Memory trick: Compliance standards are built from 'standards' you 'create'.
Prisma Cloud Resource Query Language (RQL)
Flip cardA powerful query language used in Prisma Cloud to search, filter, and identify cloud resources based on their configurations, attributes, and relationships.
- Enables precise resource identification.
- Supports complex queries for tags, metadata, and configurations.
- Used to build custom policies and investigate alerts.
Memory trick: RQL is your cloud search engine.
Prisma Cloud Asset Inventory
Flip cardA feature that continuously discovers, catalogs, and monitors all cloud resources across integrated cloud environments.
- Automates resource discovery.
- Provides a unified view of all cloud assets.
- Feeds data to policies and other security features.
Memory trick: Assets are the foundation, inventory is the map.
Prisma Cloud AWS Onboarding
Flip cardThe process of integrating an AWS account with Prisma Cloud for security monitoring, typically leveraging IAM roles for secure, granular access.
- IAM roles are preferred over IAM users for cross-account access.
- External ID enhances security by preventing the confused deputy problem.
- Least privilege principle should always be applied to assigned policies.
Memory trick: Securely connect your cloud, role up your permissions, and ID your external trust.
Prisma Cloud Onboarding Scope
Flip cardThe ability to define specific cloud resources (e.g., by resource group, region, or tags) that Prisma Cloud will monitor during the initial account onboarding process.
- Allows for granular control over ingested assets.
- Reduces noise and focuses monitoring on critical resources.
- Configured during the initial cloud account setup.
Memory trick: Scope your onboarding keenly, target your groups, and monitor precisely.
Prisma Cloud Account Access Type
Flip cardThe method and level of permissions granted to Prisma Cloud to access and ingest configuration data from a cloud environment during onboarding.
- Crucial for comprehensive data collection.
- Typically uses read-only IAM roles/service principals.
- Determines visibility across regions and services.
Memory trick: Access type is the key to Prisma Cloud's view.
Prisma Cloud Compliance Policies
Flip cardRules within Prisma Cloud that continuously monitor cloud resources against predefined security standards, regulatory frameworks, and custom organizational requirements.
- Enforce industry standards (PCI DSS, HIPAA).
- Provide continuous monitoring.
- Generate reports on compliance posture.
Memory trick: Compliance policies are your continuous cloud auditor.
Prisma Cloud Custom Policy (RQL)
Flip cardUser-defined policies created using Resource Query Language (RQL) to detect specific configurations or misconfigurations across cloud environments.
- Provides maximum flexibility for detection.
- Supports multi-cloud attribute-based filtering.
- Can be integrated into compliance standards and automated remediation.
Memory trick: When it's 'custom' logic, you need a 'Custom Policy with RQL'.
RQL NOT IN Operator
Flip cardA Resource Query Language (RQL) operator used to filter resources where a specific attribute's value is not present within a given list of values.
- Efficient for checking against multiple exclusions.
- Often used for compliance and data residency checks.
- Provides a concise way to express 'not equal to any of these'.
Memory trick: If it's NOT IN the allowed list, it's out!
Prisma Cloud Onboarding Access
Flip cardThe method of granting Prisma Cloud the necessary permissions to discover and monitor resources within a cloud environment.
- Utilizes IAM roles in AWS/GCP, or Service Principals in Azure.
- Prisma Cloud provides managed templates for minimal permissions.
- Read-only access is typically sufficient for CSPM.
Memory trick: Managed templates are the 'key' to 'least privilege'.
Multi-Cloud Custom Policy (CMEK)
Flip cardA Prisma Cloud custom policy, defined using RQL, to enforce specific encryption standards like Customer-Managed Encryption Keys (CMEK) across diverse storage services in multiple cloud environments.
- Addresses granular, multi-cloud requirements.
- Differentiates between encryption key types (CMEK vs. default).
- Leverages RQL for precise querying across S3, Blob, Cloud Storage.
Memory trick: RQL is the Rosetta Stone for multi-cloud encryption standards.
Prisma Cloud Custom Policies (RQL)
Flip cardPrisma Cloud's mechanism to define highly specific security and compliance rules using Resource Query Language (RQL).
- Uses RQL for granular control.
- Addresses unique organizational compliance needs.
- Can combine multiple conditions and resource types.
Memory trick: Custom RQL policies are like tailored suits for your cloud security.
Prisma Cloud Azure Onboarding Access
Flip cardFor Azure subscription onboarding, Prisma Cloud requires read-only access to resource configurations and permissions to ingest activity logs to perform continuous security monitoring, identify misconfigurations, and generate alerts.
- Principle of Least Privilege is key.
- Requires read access to resources.
- Needs permissions to access activity logs (e.g., Log Analytics Contributor).
Memory trick: To monitor and alert, read and log are enough.
Prisma Cloud AWS Organization Onboarding
Flip cardThe process of integrating an entire AWS Organization with Prisma Cloud for centralized CSPM, typically via an IAM role in the master account.
- Centralized discovery and monitoring.
- Utilizes an IAM role in the master account.
- Scalable for multi-account AWS environments.
Memory trick: One master key unlocks all AWS doors for Prisma Cloud.
S3 Public Exposure Vectors
Flip cardMechanisms through which an Amazon S3 bucket can become publicly accessible, often involving bucket policies, ACLs, or Block Public Access settings.
- S3 Bucket Policies define access rules at the bucket level.
- S3 Access Control Lists (ACLs) grant object-level and bucket-level permissions.
- AWS S3 Block Public Access settings provide a crucial layer to prevent public exposure.
Memory trick: Don't just check the bucket policy, remember the ACLs and block public access too!
Prisma Cloud Console Outbound Ports
Flip cardThe network ports that must be open outbound from the Prisma Cloud console (SaaS or self-hosted) to communicate with cloud provider APIs, external services, and Defenders.
- TCP 443 is crucial for cloud API communication (HTTPS).
- Other ports may be needed for specific integrations (e.g., SIEM, webhooks).
- Outbound connectivity is essential for metadata collection and policy enforcement.
Memory trick: To talk to cloud APIs, always use the secure 443 highway.
Prisma Cloud Data Export for Archival
Flip cardPrisma Cloud provides mechanisms to export raw security data, such as alerts, audit logs, and compliance findings, to external cloud storage for long-term archival and advanced analytics.
- Exports to S3, Azure Blob Storage, or Google Cloud Storage.
- Enables compliance with extended retention periods.
- Facilitates advanced security analytics in external platforms.
Memory trick: To fill your data lake, you need a direct pipeline, not just a bucket.
Prisma Cloud SAML 2.0 Integration
Flip cardThe process of configuring Prisma Cloud as a Service Provider (SP) to integrate with an external Identity Provider (IdP) using SAML 2.0 for Single Sign-On (SSO) and user provisioning based on IdP group attributes.
- Enables centralized authentication with corporate credentials.
- Supports automatic role mapping based on IdP group memberships.
- Industry standard for federated identity management.
Memory trick: To connect identities, SAML is the secure bridge for SSO and roles.
Prisma Cloud Policy Group Schedules
Flip cardPolicy groups in Prisma Cloud can be assigned schedules that dictate when the policies within that group are evaluated against cloud resources, determining when alerts might be generated.
- Policies must be in an active policy group to run.
- Schedules define the frequency of policy evaluation.
- No schedule means no policy evaluation, no alerts.
Memory trick: Even a perfect policy needs a 'start' button to run.
Prisma Cloud Defender
Flip cardA lightweight, deployable component of Prisma Cloud that enforces security policies, scans for vulnerabilities, and monitors runtime behavior within hosts, containers, and serverless functions, capable of operating in various environments including on-premises.
- Deployed directly in the protected environment (host, container, serverless).
- Enables runtime protection and local scanning.
- Can operate with limited or no connectivity to the central console for air-gapped or data sovereignty needs.
Memory trick: To protect locally and keep data home, deploy the Defender as your guardian drone.
Prisma Cloud API OAuth 2.0 Client Credentials
Flip cardA secure authentication flow for applications to access the Prisma Cloud API without user interaction, using a client ID and client secret.
- Enables machine-to-machine communication.
- Provides granular role-based access control (RBAC) for the application.
- Recommended for automation and integration scenarios.
Memory trick: For apps, OAuth client credentials are the secure key to the API kingdom.
Prisma Cloud SIEM Integration
Flip cardThe process of connecting Prisma Cloud to a Security Information and Event Management (SIEM) system to centralize security event data and audit logs for monitoring and analysis.
- Enables automated export of audit logs and alerts.
- Supports various SIEM platforms (e.g., Splunk, QRadar, Sumo Logic).
- Often uses log forwarders (e.g., Syslog, HTTP Event Collector) for data transfer.
Memory trick: Log exports need a smooth, automated highway to the SIEM city.
Prisma Cloud Custom RBAC Roles
Flip cardAllows administrators to define granular permissions for users and groups within Prisma Cloud, controlling access to specific features and data based on job function.
- Enforces least privilege principle.
- Permissions categorized by feature (e.g., Policy, Alert, Asset).
- Can combine read, write, manage, execute permissions.
Memory trick: Give roles just enough power, like a key that only opens specific doors.
Prisma Cloud API for Policy Management
Flip cardThe Prisma Cloud API provides a programmatic interface to manage and retrieve information about policies, compliance standards, and other configurations within the platform.
- Enables automation of policy-related tasks.
- Supports integration with CI/CD pipelines and custom reporting tools.
- Requires API authentication (e.g., OAuth 2.0 Client Credentials).
Memory trick: For automated policy data, the API is your best ally.
Prisma Cloud Webhooks
Flip cardA mechanism in Prisma Cloud to automatically send HTTP POST requests with alert or event data to a specified URL, enabling real-time integration with external systems.
- Event-driven, real-time notifications.
- Configurable payload structure for detailed information.
- Ideal for integrating with SIEMs, SOAR platforms, custom tools.
Memory trick: For instant alerts, let webhooks be your digital messenger.
Prisma Cloud Default Policy Groups
Flip cardConfigurable policy groups in Prisma Cloud that are automatically assigned to newly onboarded cloud accounts, ensuring a baseline security posture and immediate policy enforcement.
- Automates policy application for new accounts.
- Ensures consistent security baseline.
- Reduces manual overhead during onboarding.
Memory trick: To secure new clouds instantly, use the 'default' setup.
Prisma Cloud Data Retention
Flip cardPrisma Cloud allows administrators to configure how long different types of security data (e.g., audit logs, scan results, alerts) are stored, typically to meet compliance or operational requirements.
- Configurable per data type.
- Important for compliance (e.g., GDPR, HIPAA).
- Impacts storage costs and performance.
Memory trick: Remember what data stays long and what can be forgotten quickly.
Prisma Cloud Syslog Export
Flip cardA Prisma Cloud feature that allows real-time forwarding of security alerts, audit logs, and other event data to an external syslog server, typically a SIEM.
- Supports standard syslog protocols (UDP, TCP, TLS).
- Enables centralized logging and security event correlation.
- Configurable for various event types (alerts, audit logs).
Memory trick: To SIEM, send it with Syslog, simple and sound.
Prisma Cloud Policy Violation Trends
Flip cardA reporting feature in Prisma Cloud that provides a historical view of policy violations, showing changes in compliance posture, violation counts, and remediation progress over a specified time period.
- Tracks policy violations over time for specific policies or groups.
- Essential for demonstrating compliance improvement or identifying degradation.
- Helps in understanding the effectiveness of remediation efforts.
Memory trick: To see how policy violations change, follow the trends report's historical range.
Prisma Cloud Regional SaaS Tenant
Flip cardA deployment option for Prisma Cloud SaaS where the customer's data and management plane are hosted within a specific geographic region to meet data residency and compliance requirements.
- Data processing and storage confined to selected region.
- Leverages Palo Alto Networks' managed infrastructure.
- Simplifies compliance with local regulations like GDPR.
Memory trick: Choosing your cloud home: SaaS is easy, but where does your data sleep?
Prisma Cloud Webhook Integration
Flip cardA mechanism in Prisma Cloud that sends automated HTTP POST requests to a specified URL in response to certain events, such as alert generation, enabling real-time integration with external systems.
- Provides real-time, event-driven notifications.
- Commonly used for SIEM, SOAR, or custom integrations.
- Payloads are typically JSON-formatted.
Memory trick: To get alerts to your SIEM instantly, think of a 'hook' that pulls them over.
Prisma Cloud Activity Log
Flip cardA centralized record within Prisma Cloud that tracks all administrative actions, configuration changes, user logins, and system events, serving as a critical audit trail.
- Records 'who, what, when, where' for actions.
- Essential for compliance, forensics, and operational auditing.
- Includes changes to policies, rules, integrations, and user management.
Memory trick: To audit past actions, check the activity scroll, not the alert bells.
Prisma Cloud Federated Architecture
Flip cardAn architectural model where multiple independent Prisma Cloud tenants (child tenants) operate autonomously within specific regions or business units, often with an optional central (parent) tenant for global oversight.
- Enables regional autonomy for management and data.
- Supports regulatory compliance and data residency.
- Allows for global visibility if a parent tenant is configured.
Memory trick: Like a 'federation' of states, each is independent but can be united.
Prisma Cloud Policies API
Flip cardA set of API endpoints within Prisma Cloud that allows programmatic interaction with policy definitions, including creation, modification, deletion, and retrieval of policy data.
- Enables automation of policy management tasks.
- Supports integration with CI/CD and compliance pipelines.
- Allows retrieval of policy details, including RQL and remediation actions.
Memory trick: To get 'policies', use the 'Policies' API.
Prisma Cloud Self-Hosted Deployment
Flip cardAn on-premises or customer-managed deployment of Prisma Cloud that provides full control over the platform's infrastructure and data locality.
- Customer manages all components (Console, Defenders, database).
- Offers maximum control over data residency.
- Requires significant operational overhead from the customer.
Memory trick: To keep data 'home', you need to 'host' it yourself.
Prisma Cloud Data Export for Long-Term Retention
Flip cardThe process of regularly exporting security and compliance data from Prisma Cloud to external customer-managed storage for retention periods exceeding Prisma Cloud's default SaaS policy.
- Enables compliance with stringent long-term data retention regulations.
- Typically uses cloud storage buckets (S3, Azure Blob) as export targets.
- Automated exports ensure continuous data capture for archival.
Memory trick: For data longer than 1 year, export it to your own archive.
OAuth 2.0 Client Credentials Flow
Flip cardAn OAuth 2.0 grant type where a client application authenticates itself directly to the authorization server using its client ID and client secret to obtain an access token.
- Used for machine-to-machine authentication.
- No end-user interaction required.
- Ideal for daemon services or backend applications.
Memory trick: For machines talking to machines, give them credentials, not a user's key.
Role-Based Access Control (RBAC)
Flip cardAn access control methodology where permissions are associated with roles, and users are assigned to roles, thereby inheriting the permissions defined for that role.
- Simplifies user management by grouping permissions.
- Enables segregation of duties and least privilege.
- Widely used in enterprise security platforms like Prisma Cloud.
Memory trick: Roles give access, like job titles give duties.
Prisma Cloud Defender Outbound Communication
Flip cardPrisma Cloud Defenders establish an outbound, encrypted connection to the Prisma Cloud console over TCP port 443 to send security telemetry and receive configuration updates.
- Communication is always initiated by the Defender (outbound).
- Uses standard HTTPS (TCP 443) for secure transport.
- Simplifies firewall rules in customer environments by avoiding inbound connections.
Memory trick: Defenders 'call out' to the Console securely on 443.
Prisma Cloud Audit Logs
Flip cardA comprehensive record of all administrative and system activities within the Prisma Cloud platform, used for accountability, compliance, and forensic analysis.
- Tracks user logins, policy changes, alert dismissals.
- Includes timestamps, user IDs, and action details.
- Essential for security investigations and compliance audits.
Memory trick: To find out 'who did what,' look for the logs of their actions.
Prisma Cloud Audit Log API Activity
Flip cardThe Prisma Cloud Audit Log records all API calls made to the Prisma Cloud platform, including successful and failed authentication and authorization attempts.
- Captures caller identity, source IP, timestamp, API endpoint, and response code.
- Essential for monitoring for unauthorized access attempts or suspicious activity against Prisma Cloud itself.
- Distinct from cloud provider-specific activity logs.
Memory trick: Audit logs record every knock on the Prisma Cloud door, authorized or not.
Prisma Cloud Onboarding Permissions
Flip cardThe specific set of IAM permissions (e.g., AWS IAM roles, Azure service principals) that must be granted to Prisma Cloud to allow it to securely collect configuration, activity, and vulnerability data from integrated cloud environments.
- Adheres to least privilege principle.
- Cloud-provider specific (AWS, Azure, GCP, OCI, Alibaba Cloud).
- Detailed in official Prisma Cloud documentation.
Memory trick: To check the cloud's gatekeeper, read the instruction manual for the gate.
Prisma Cloud Policy Groups & Schedules
Flip cardA feature in Prisma Cloud that allows administrators to logically group compliance policies and assign them unique scan schedules, enabling fine-grained control over policy evaluation frequency.
- Organizes policies for easier management.
- Enables custom scan intervals for specific policy sets.
- Helps optimize resource utilization by varying scan frequency for different policy types.
Memory trick: For specific policy timing, group them up and set their own clock.
Prisma Cloud Custom Roles & Resource Groups
Flip cardCustom Roles define specific permissions in Prisma Cloud, which can then be applied to users or groups, often in conjunction with Resource Groups to limit access to a subset of cloud assets.
- Custom Roles enable least privilege access.
- Resource Groups logically segment cloud accounts.
- Together they provide granular, context-aware access control.
Memory trick: Custom roles define 'what' you can do, Resource Groups define 'where'.