Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Easy

A cloud security architect is integrating a new Azure subscription into Prisma Cloud. The subscription contains numerous resource groups, and the architect needs to ensure that all resources within a specific resource group, 'Production-WebApps', are continuously monitored for compliance, while other resource groups are initially excluded. During the onboarding process, how can this granular scoping be achieved MOST effectively?

  1. AOnboard the subscription with read-only access and then upgrade permissions for 'Production-WebApps' later.
  2. BApply a custom policy specifically to 'Production-WebApps' after onboarding the whole subscription.
  3. COnboard the entire subscription and then manually exclude resources from other groups using RQL.
  4. DOnly onboard the 'Production-WebApps' resource group by configuring a specific scope during the account setup in Prisma Cloud.
Show answer & explanation

Correct answer: D. Only onboard the 'Production-WebApps' resource group by configuring a specific scope during the account setup in Prisma Cloud.

During the cloud account onboarding process in Prisma Cloud, it is possible to define a specific scope, such as a particular resource group or set of tags, for monitoring. This allows for granular control over which resources are ingested and managed from the outset.

Why the other options are wrong

  • A. Access level (read-only vs. read-write) is distinct from the scope of resources to be monitored.
  • B. Applying a custom policy afterwards would check compliance but doesn't control which resources are initially onboarded and inventoried by Prisma Cloud.
  • C. Manually excluding resources post-onboarding is less efficient than defining the scope upfront.

Prisma Cloud Onboarding Scope

The ability to define specific cloud resources (e.g., by resource group, region, or tags) that Prisma Cloud will monitor during the initial account onboarding process.

  • Allows for granular control over ingested assets.
  • Reduces noise and focuses monitoring on critical resources.
  • Configured during the initial cloud account setup.

Memory trick: Scope your onboarding keenly, target your groups, and monitor precisely.

More Cloud Security Posture Management (CSPM) questions