Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium
A security engineer is observing an unusually high volume of API calls originating from a specific IP address to the Prisma Cloud API, attempting to enumerate cloud resources. These calls are all failing due to authorization errors. Which type of event would be logged in Prisma Cloud to indicate these unauthorized attempts?
- APolicy Violation Log
- BAudit Log
- CCloud Activity Log
- DSystem Health Log
Show answer & explanationAnswer & explanation
Correct answer: B. Audit Log
Unauthorized API attempts against the Prisma Cloud API, even if failing, constitute administrative or user activity within the context of the Prisma Cloud platform. These actions are recorded in the Audit Logs, providing details on who (or what client) attempted the action, when, from where, and the outcome.
Why the other options are wrong
- A. Policy Violation Logs record cloud resource configurations that don't meet policies, not attempts to access the Prisma Cloud API.
- C. Cloud Activity Logs (often referred to as CloudTrail/CloudWatch Logs, etc.) track activity within the customer's cloud environment, not direct interactions with the Prisma Cloud platform's own API.
- D. System Health Logs monitor the operational status of Prisma Cloud components, not API access attempts.
Prisma Cloud Audit Log API Activity
The Prisma Cloud Audit Log records all API calls made to the Prisma Cloud platform, including successful and failed authentication and authorization attempts.
- Captures caller identity, source IP, timestamp, API endpoint, and response code.
- Essential for monitoring for unauthorized access attempts or suspicious activity against Prisma Cloud itself.
- Distinct from cloud provider-specific activity logs.
Memory trick: Audit logs record every knock on the Prisma Cloud door, authorized or not.