Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security operations center (SOC) analyst needs to investigate a critical security alert generated by Prisma Cloud. They need to understand who made the configuration change that led to the policy violation, when it occurred, and from what source IP address. Which Prisma Cloud feature provides this detailed historical information?

  1. AAudit Logs
  2. BAlerts Dashboard
  3. CCompliance Report
  4. DAsset Inventory
Show answer & explanation

Correct answer: A. Audit Logs

Prisma Cloud's Audit Logs record all administrative and user actions within the platform, including who performed an action, when, and from where, which is crucial for incident investigation and forensic analysis.

Why the other options are wrong

  • B. The Alerts Dashboard displays active and historical alerts but doesn't provide the granular 'who, when, from where' details of platform configuration changes.
  • C. A Compliance Report summarizes compliance posture against policies, not individual user actions or configuration changes.
  • D. Asset Inventory provides details about cloud resources, not actions performed by users within Prisma Cloud.

Prisma Cloud Audit Logs

Detailed records of all administrative and user actions performed within the Prisma Cloud platform, including logins, configuration changes, and policy modifications.

  • Provides 'who, what, when, where' for platform activities.
  • Essential for security investigations and forensic analysis.
  • Supports compliance and regulatory requirements for accountability.

Memory trick: To 'audit' who did what, check the 'audit' logs.

More Prisma Cloud Platform questions