Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard

A cloud security architect is designing an automated remediation strategy for their AWS environment using Prisma Cloud. They have a critical policy that detects publicly accessible S3 buckets. Upon detecting such a bucket, they want Prisma Cloud to automatically modify the bucket policy to restrict public access. What is the MOST critical prerequisite for enabling this automated remediation in Prisma Cloud?

  1. AEnable CloudTrail logging for S3 bucket events.
  2. BOnboard the AWS account with 'Remediation' access type.
  3. CEnsure the S3 bucket is tagged with 'remediate:true'.
  4. DConfigure an external webhook for remediation actions.
Show answer & explanation

Correct answer: B. Onboard the AWS account with 'Remediation' access type.

For Prisma Cloud to automatically remediate issues like modifying an S3 bucket policy, it requires the necessary permissions within the target AWS account. This is achieved by onboarding the account with a 'Remediation' access type, which grants Prisma Cloud the write/modify permissions needed to perform corrective actions.

Why the other options are wrong

  • A. CloudTrail logging is essential for visibility and auditing, but it doesn't grant Prisma Cloud the permission to _perform_ remediation actions.
  • C. Tagging is useful for policy targeting but not a direct prerequisite for the _permission_ to remediate.
  • D. External webhooks are for integrating with external systems for remediation, but Prisma Cloud's native automated remediation doesn't strictly require it for direct actions.

Prisma Cloud Automated Remediation Prerequisites

Conditions that must be met for Prisma Cloud to successfully perform automated corrective actions on cloud resources.

  • Requires specific IAM permissions (Remediation access).
  • Policy must be configured for automated remediation.
  • Supported for specific resource types and cloud providers.

Memory trick: To fix automatically, you need the 'right Remediation Access'.

More Cloud Security Posture Management (CSPM) questions