Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
A large enterprise uses Prisma Cloud to manage security posture across thousands of cloud resources. The security team needs to identify all EC2 instances in a specific AWS region (us-east-1) that have port 22 (SSH) open to the internet (0.0.0.0/0) AND are tagged with 'Environment:Production'. Which Prisma Cloud feature should they use for this ad-hoc, targeted query?
- AResource Explorer
- BCompliance Policies
- CNetwork Explorer
- DAlert Management
Show answer & explanationAnswer & explanation
Correct answer: A. Resource Explorer
Resource Explorer allows security teams to perform ad-hoc, granular queries across their cloud assets using RQL (Resource Query Language) to filter by resource type, region, tags, network configurations, and more. This is ideal for specific, targeted searches not necessarily tied to a continuous compliance check.
Why the other options are wrong
- B. Compliance Policies are for continuous monitoring against predefined rules, not ad-hoc queries.
- C. Network Explorer focuses on visualizing network connectivity and attack paths, not directly on querying resource attributes like tags and open ports in a tabular format.
- D. Alert Management is for reviewing and responding to generated alerts, not for initiating new searches.
Prisma Cloud Resource Explorer
A Prisma Cloud feature enabling security teams to perform powerful, ad-hoc queries on their cloud asset inventory using RQL (Resource Query Language).
- Uses RQL for flexible querying.
- Allows filtering by resource type, region, tags, network details, and more.
- Provides a comprehensive view of all inventoried cloud resources.
Memory trick: To explore resources, use RQL and query with precision.