Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security architect is evaluating Prisma Cloud deployment options for a large enterprise with a strict data residency requirement for all security logs and metadata. The enterprise operates exclusively within a single AWS region and prefers not to send any data outside its control. Which Prisma Cloud deployment model is best suited for this scenario?

  1. APrisma Cloud Enterprise Edition (SaaS)
  2. BPrisma Cloud Enterprise Edition (Federated)
  3. CPrisma Cloud Compute Edition (Self-Hosted)
  4. DPrisma Cloud Compute Edition (SaaS)
Show answer & explanation

Correct answer: C. Prisma Cloud Compute Edition (Self-Hosted)

For strict data residency requirements where all security logs and metadata must remain within the customer's control and infrastructure, the self-hosted Prisma Cloud Compute Edition is the most appropriate choice. This allows the customer to deploy and manage all components within their own environment.

Why the other options are wrong

  • A. SaaS editions inherently involve data processed and stored by Palo Alto Networks, which violates strict data residency requirements.
  • B. Federated deployments still rely on a central SaaS console for management, which does not meet the 'no data outside its control' requirement.
  • D. Prisma Cloud Compute SaaS still involves data being managed by Palo Alto Networks in a SaaS model, which violates strict data residency.

Prisma Cloud Self-Hosted Deployment

A deployment model where all Prisma Cloud components, including the console, Defenders, and databases, are installed and managed within the customer's infrastructure.

  • Provides maximum control over data residency and security.
  • Requires customer to manage infrastructure and updates.
  • Typically used for Prisma Cloud Compute Edition.

Memory trick: Self-hosted means your house, your rules, especially for data.

More Prisma Cloud Platform questions