Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A security analyst uses Prisma Cloud to monitor for deviations from their organization's security baseline. They notice a significant number of alerts for a specific policy related to 'unencrypted S3 buckets' in a development environment. This policy is critical for production but causes too much noise in dev. The analyst wants to suppress these alerts for the development environment only, without disabling the policy entirely or affecting other environments. Which alert management capability should they use?

  1. AGlobal alert suppression
  2. BResource exemption
  3. CPolicy disabling
  4. DAlert rule suppression
Show answer & explanation

Correct answer: D. Alert rule suppression

Alert rule suppression allows you to define specific conditions (e.g., for a particular policy and a specific account/tag like a development environment) under which alerts will not be generated or will be automatically dismissed. This is more granular than disabling the policy and more flexible than resource exemption for a broad set of resources.

Why the other options are wrong

  • A. Global alert suppression would affect all alerts across all environments, which is too broad.
  • B. Resource exemption is for individual resources, which would be tedious for a 'significant number' of S3 buckets in a whole environment.
  • C. Policy disabling would turn off the policy for all environments, which is not desired.

Prisma Cloud Alert Suppression

A mechanism to reduce alert noise by preventing alerts from being generated or by automatically dismissing them based on defined criteria.

  • Can be configured based on policies, accounts, tags, or resource types.
  • Helps focus on critical alerts.
  • More granular than disabling policies.

Memory trick: Suppress rules to quiet the noise, not silence the whole show.

More Cloud Security Posture Management (CSPM) questions