Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformHard

A global financial institution is deploying Prisma Cloud Enterprise. Due to stringent regulatory requirements (e.g., GDPR, CCPA, local financial regulations), they must ensure that all security data, including asset inventory, configuration changes, and alert details, for their European operations remain exclusively within the EU, while data for their North American operations remains within North America. They also require a centralized view of all global security posture from a single console. How should their Prisma Cloud architecture be designed to meet these conflicting requirements?

  1. AUtilize multiple Prisma Cloud Regional SaaS Tenants (one for each region) and federate data to a global dashboard.
  2. BImplement a hybrid deployment with a global SaaS tenant for CSPM and regional Compute Consoles for CWPP.
  3. CDeploy Prisma Cloud Compute Edition with an on-premises Console in each region and integrate them into a custom global dashboard.
  4. DDeploy a single Prisma Cloud SaaS tenant in a central region and use data filtering to segment views.
Show answer & explanation

Correct answer: A. Utilize multiple Prisma Cloud Regional SaaS Tenants (one for each region) and federate data to a global dashboard.

The core conflict is data residency ('remain exclusively within the EU/NA') vs. 'centralized view'. Regional SaaS Tenants directly address data residency by keeping data within specific geographic boundaries. To achieve a centralized view despite physically separate tenants, Prisma Cloud's federation capabilities (often via API or a global dashboard feature) are used to aggregate information from these regional tenants into a single pane of glass without moving the underlying data.

Why the other options are wrong

  • B. A hybrid deployment combines SaaS for CSPM and Compute for CWPP, but a 'global SaaS tenant' for CSPM would again violate regional data residency for the CSPM data itself. Regional Compute Consoles would address CWPP data residency but not the broader CSPM data residency for the entire organization.
  • C. Deploying Compute Edition Consoles primarily addresses workload protection and does not inherently provide CSPM capabilities across multiple cloud accounts with regional data residency for all security data, nor does it offer a native centralized global dashboard for CSPM data as easily as federated SaaS tenants.
  • D. A single SaaS tenant, even with data filtering, would still store all data in one central region, violating the strict data residency requirements for separate regions.

Prisma Cloud Federated Architecture

A deployment model combining multiple regional Prisma Cloud SaaS tenants to satisfy data residency requirements while providing a consolidated, centralized view of global security posture.

  • Achieves data residency through regional tenants.
  • Offers a 'single pane of glass' via federation or global dashboard.
  • Requires careful planning for data aggregation and user access.

Memory trick: Separate homes for data, but one window to see them all.

More Prisma Cloud Platform questions