Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard

A financial institution uses Prisma Cloud to enforce strict compliance with PCI DSS. They need to ensure that all data stores containing cardholder data are encrypted at rest. Due to specific audit requirements, they must generate an audit trail of all policy violations related to unencrypted data stores, including who made the change that caused the violation. Which Prisma Cloud integration is crucial for capturing the 'who' and 'when' of configuration changes that lead to policy violations?

  1. ASIEM Integration
  2. BTicketing System Integration
  3. CCloud Service Provider (CSP) Audit Log Integration
  4. DIdentity Provider (IdP) Integration
Show answer & explanation

Correct answer: C. Cloud Service Provider (CSP) Audit Log Integration

Prisma Cloud's integration with Cloud Service Provider (CSP) audit logs (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is crucial for capturing detailed event data, including the user identity, timestamp, and API call that resulted in a configuration change leading to a policy violation. This provides the necessary audit trail for 'who' and 'when'.

Why the other options are wrong

  • A. SIEM integration forwards alerts but doesn't inherently provide the detailed change history (who/when) from the CSP logs directly.
  • B. Ticketing system integration is for workflow management and issue tracking, not for capturing the underlying audit trail data.
  • D. IdP integration is for user authentication to Prisma Cloud, not for auditing changes in the cloud environment itself.

Prisma Cloud CSP Audit Log Integration

Prisma Cloud integrates with Cloud Service Provider (CSP) audit logs (e.g., CloudTrail, Activity Log) to ingest activity data, providing detailed information about who made changes to cloud resources, when, and what API calls were involved, which is essential for forensic analysis and compliance.

  • Ingests native cloud audit logs.
  • Captures 'who', 'what', 'when' of changes.
  • Crucial for compliance and forensic investigations.

Memory trick: To know 'who' changed 'what', check the 'CSP logs'.

More Cloud Security Posture Management (CSPM) questions