Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard
A security engineer is tasked with performing a comprehensive security audit of a newly deployed microservices application in AWS. The audit requires identifying potential attack paths that could lead to unauthorized data exfiltration from an S3 bucket containing sensitive customer data. Specifically, the engineer needs to find if any publicly exposed EC2 instances have network access to this S3 bucket, even if indirectly through other resources. Which Prisma Cloud feature is BEST suited for this complex analysis?
- AAttack Path Analysis in Network Explorer.
- BAlert management for existing data exfiltration alerts.
- CResource Explorer with RQL queries for EC2 and S3.
- DCompliance policies dashboard for S3 public access and EC2 exposure.
Show answer & explanationAnswer & explanation
Correct answer: A. Attack Path Analysis in Network Explorer.
Attack Path Analysis, integrated within Prisma Cloud's Network Explorer, is specifically designed to identify and visualize multi-hop, indirect attack vectors between an attacker's entry point (like a publicly exposed EC2 instance) and a target resource (like a sensitive S3 bucket). This goes beyond simple resource queries or compliance checks to model actual exploitation routes.
Why the other options are wrong
- B. Alert management deals with existing alerts, not proactive identification of potential attack paths.
- C. Resource Explorer can query individual resources but cannot automatically chain together complex, multi-hop network paths for attack scenarios.
- D. Compliance policies check for individual misconfigurations but do not visualize the combined, exploitable path between resources.
Prisma Cloud Attack Path Analysis
A feature in Prisma Cloud that identifies and visualizes potential multi-hop attack vectors between an attacker's entry point and sensitive target resources across the cloud environment.
- Goes beyond individual misconfigurations to model exploitation routes.
- Considers network connectivity, identity, and configuration risks.
- Helps prioritize remediation efforts based on actual attack likelihood.
Memory trick: To find the attack path, map the steps from entry to target.