Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
A security operations center (SOC) analyst is using Prisma Cloud to investigate a series of alerts related to suspicious API calls originating from a compromised IAM user in AWS. The analyst needs to reconstruct the sequence of events, including when the user was created, when suspicious activity started, and what resources were accessed. Which Prisma Cloud feature allows for a consolidated timeline view of these security events and configuration changes?
- AAudit Logs
- BCloud Security Governance
- CAlert Management
- DAsset Inventory
Show answer & explanationAnswer & explanation
Correct answer: A. Audit Logs
Prisma Cloud integrates and normalizes audit logs (e.g., AWS CloudTrail, Azure Activity Logs) from various cloud providers. These logs provide a chronological record of all API calls, user activities, and configuration changes, which is crucial for reconstructing a timeline of events during an investigation.
Why the other options are wrong
- B. Cloud Security Governance is a broader domain encompassing policies and compliance, not a specific feature for event timeline reconstruction.
- C. Alert Management shows triggered alerts but doesn't provide the detailed underlying audit trail of all activities.
- D. Asset Inventory provides a list of resources and their current configurations, not a historical timeline of events.
Prisma Cloud Audit Log Integration
Prisma Cloud's capability to ingest, normalize, and analyze cloud provider audit logs (e.g., CloudTrail, Activity Logs) to provide a historical record of events and configuration changes.
- Crucial for incident response and forensic analysis.
- Provides a chronological timeline of user and API activity.
- Helps identify root causes and scope of security incidents.
Memory trick: To reconstruct the past, follow the audit logs, event by event.