Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard

A security auditor is reviewing Prisma Cloud's alert management system and notices a significant number of 'Low' severity alerts for 'AWS EBS Volume Not Encrypted'. While these are true positives, they are generating excessive noise and obscuring higher-priority alerts. The auditor wants to reduce the volume of these specific alerts without disabling the policy entirely or ignoring critical EBS volumes. What is the MOST effective strategy within Prisma Cloud to achieve this?

  1. AAdjust the global alert threshold for all 'Low' severity alerts.
  2. BDisable the 'AWS EBS Volume Not Encrypted' policy for all accounts.
  3. CCreate an alert rule with a suppression mechanism based on resource tags, excluding non-critical volumes.
  4. DChange the policy severity to 'Informational' and filter alerts by severity.
Show answer & explanation

Correct answer: C. Create an alert rule with a suppression mechanism based on resource tags, excluding non-critical volumes.

Creating an alert rule with a suppression mechanism based on resource tags is the most effective approach. This allows specific non-critical EBS volumes (e.g., tagged 'Environment:Dev' or 'DataClassification:None') to be excluded from generating alerts, while still enforcing the policy for critical volumes and maintaining visibility on other 'Low' severity alerts from different policies.

Why the other options are wrong

  • A. Adjusting the global threshold for all 'Low' alerts would impact all policies with 'Low' severity, potentially hiding other important alerts.
  • B. Disabling the policy entirely removes all monitoring for EBS encryption, including critical volumes, which is not desired.
  • D. Changing severity to 'Informational' still generates alerts; filtering by severity would hide all 'Informational' alerts, potentially including other important ones.

Prisma Cloud Alert Suppression

A mechanism in Prisma Cloud's alert rules to prevent specific, non-critical policy violations from generating alerts, often based on filters like resource tags or accounts.

  • Reduces alert fatigue by focusing on relevant issues.
  • Configured within alert rules, not directly on policies.
  • Can use various filters (tags, accounts, resource attributes) for granular control.

Memory trick: Suppress the noise with smart rules, tag your non-critical, and keep the important alerts clear.

More Cloud Security Posture Management (CSPM) questions