Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformEasy

A cloud security engineer is setting up a new Prisma Cloud Enterprise tenant and needs to ensure that all administrative actions performed within the console are meticulously recorded for compliance audits. Specifically, they need to track who made what changes, when, and from where. Which feature within Prisma Cloud provides this capability?

  1. AAudit Logs
  2. BPolicy Violation Logs
  3. CAlert History
  4. DResource Inventory
Show answer & explanation

Correct answer: A. Audit Logs

Prisma Cloud's Audit Logs feature is specifically designed to record all administrative actions, configuration changes, and user activities within the Prisma Cloud console, providing the necessary details for compliance and forensics.

Why the other options are wrong

  • B. Policy Violation Logs record instances where cloud resources violate defined policies, not administrative actions.
  • C. Alert History tracks the lifecycle of security alerts, not changes made by administrators.
  • D. Resource Inventory lists discovered cloud resources but does not track administrative changes.

Prisma Cloud Audit Logs

A comprehensive record of all administrative and user actions performed within the Prisma Cloud console, critical for compliance and security forensics.

  • Tracks user logins, configuration changes, policy updates, and more.
  • Includes details like user, timestamp, action, and source IP.
  • Essential for meeting regulatory compliance requirements.

Memory trick: Audit logs are like a security diary for administrators.

More Prisma Cloud Platform questions