Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security architect is designing the network connectivity for a Prisma Cloud Enterprise self-hosted deployment within a private data center. To ensure the console can retrieve metadata from connected AWS accounts, which outbound network port must be opened from the console to the AWS API endpoints?

  1. AUDP 53.
  2. BTCP 80.
  3. CTCP 22.
  4. DTCP 443.
Show answer & explanation

Correct answer: D. TCP 443.

AWS API endpoints, like most cloud service APIs, are accessed securely over HTTPS, which uses TCP port 443. This port must be open outbound from the Prisma Cloud console to retrieve metadata from AWS accounts.

Why the other options are wrong

  • A. UDP 53 is for DNS, which is necessary for name resolution but not the direct API communication port.
  • B. TCP 80 is for HTTP, which is unencrypted and not used for secure API communication with AWS.
  • C. TCP 22 is for SSH, not for API communication with AWS.

Prisma Cloud Console Outbound Ports

The network ports that must be open outbound from the Prisma Cloud console (SaaS or self-hosted) to communicate with cloud provider APIs, external services, and Defenders.

  • TCP 443 is crucial for cloud API communication (HTTPS).
  • Other ports may be needed for specific integrations (e.g., SIEM, webhooks).
  • Outbound connectivity is essential for metadata collection and policy enforcement.

Memory trick: To talk to cloud APIs, always use the secure 443 highway.

More Prisma Cloud Platform questions