Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
An organization is using Prisma Cloud to identify and prioritize security risks. They've identified several critical vulnerabilities on a publicly exposed virtual machine that also has high-privilege access to a sensitive database. Which Prisma Cloud feature would be most effective for visualizing the potential impact of compromising this VM and understanding the chain of interconnected risks?
- AResource Explorer
- BAsset Inventory
- CAttack Path Analysis
- DCompliance Policies
Show answer & explanationAnswer & explanation
Correct answer: C. Attack Path Analysis
Attack Path Analysis is specifically designed to visualize and quantify the risk of interconnected vulnerabilities and misconfigurations. It helps understand how an attacker could move from an initial compromise (e.g., publicly exposed VM) to a high-value target (sensitive database) by chaining together various weaknesses.
Why the other options are wrong
- A. Resource Explorer provides detailed information on individual resources, not the chained risk of multiple resources.
- B. Asset Inventory lists resources but doesn't visualize potential attack chains or their impact.
- D. Compliance Policies enforce rules but don't provide a visual representation of attack paths.
Prisma Cloud Attack Path Analysis
A Prisma Cloud feature that identifies and visualizes potential attack vectors by chaining together misconfigurations, vulnerabilities, and overly permissive access between cloud resources.
- Visualizes interconnected risks.
- Quantifies the impact of a compromise.
- Helps prioritize remediation efforts.
Memory trick: Attack Path Analysis maps the enemy's journey.