Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard

A cloud security architect is designing an automated remediation strategy for their AWS environment using Prisma Cloud. They want to automatically disable public access to S3 buckets that are found to be publicly exposed. Before implementing this, what crucial prerequisite must be configured in Prisma Cloud to allow automated remediation actions to be performed?

  1. AThe policy must be set to 'Audit' severity.
  2. BA 'Remediation App' must be deployed and configured in the cloud environment.
  3. CThe cloud account must be onboarded with 'Monitor' access type.
  4. DAn alert rule must be created with 'Email' notification.
Show answer & explanation

Correct answer: B. A 'Remediation App' must be deployed and configured in the cloud environment.

For Prisma Cloud to perform automated remediation actions, a 'Remediation App' (e.g., a Lambda function for AWS or Azure Function for Azure) must be deployed in the cloud environment and configured within Prisma Cloud. This app acts as the execution engine for the remediation scripts.

Why the other options are wrong

  • A. Policy severity affects prioritization and alerting, not the capability to perform remediation.
  • C. Monitor access type is for observation; 'Manage' access (or equivalent permissions) is required for remediation, along with the Remediation App.
  • D. Email notification is for alerting, not for enabling remediation actions.

Prisma Cloud Automated Remediation Prerequisites

To enable automated remediation in Prisma Cloud, a 'Remediation App' (such as a serverless function like AWS Lambda or Azure Function) must be deployed in the target cloud environment and properly configured within Prisma Cloud to execute remediation scripts.

  • Requires a Remediation App in the cloud environment.
  • Remediation App acts as the executor for changes.
  • Cloud account needs 'Manage' or equivalent write permissions.

Memory trick: For the bot to fix, an 'app' must exist.

More Cloud Security Posture Management (CSPM) questions