Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Easy
A security operations center (SOC) analyst is investigating a high-severity alert generated by Prisma Cloud indicating 'Unrestricted Egress to Internet' from an EC2 instance. To understand the full impact and potential attack vectors, the analyst needs to visualize the network connections, security groups, and NACLs associated with the compromised instance and its communication paths. Which Prisma Cloud feature is purpose-built for this type of network visualization and analysis?
- AAsset Inventory
- BCompliance Policies
- CNetwork Explorer
- DResource Explorer
Show answer & explanationAnswer & explanation
Correct answer: C. Network Explorer
The Network Explorer in Prisma Cloud provides a graphical representation of network topology, showing ingress/egress paths, security group rules, NACLs, and internet connectivity, which is precisely what's needed to analyze network connections related to the alert.
Why the other options are wrong
- A. Asset Inventory lists resources but doesn't provide a visual representation of network connectivity.
- B. Compliance Policies define rules but don't offer dynamic network visualization.
- D. Resource Explorer focuses on individual asset configurations, not network topology and flow.
Prisma Cloud Network Explorer
Prisma Cloud's Network Explorer visualizes the network topology of cloud environments, showing connections between resources, inbound/outbound traffic, security group rules, and Network Access Control Lists (NACLs) to aid in network security analysis.
- Graphical representation of network topology.
- Shows ingress/egress paths and security rules.
- Aids in understanding network attack vectors.
Memory trick: To explore network paths, use the Network Explorer.