Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Easy
A cloud security engineer needs to analyze the potential impact of a compromised EC2 instance on their AWS environment. Specifically, they want to understand which other resources (e.g., S3 buckets, RDS instances, other EC2s) could be accessed or affected if a particular EC2 instance were breached. Which Prisma Cloud feature is best suited for this task?
- AResource Explorer
- BAsset Inventory
- CAttack Path Analysis
- DNetwork Explorer
Show answer & explanationAnswer & explanation
Correct answer: C. Attack Path Analysis
Attack Path Analysis in Prisma Cloud is specifically designed to identify and visualize potential attack vectors and the blast radius from a compromised resource, showing how a breach could impact other connected resources.
Why the other options are wrong
- A. Resource Explorer provides detailed information about individual resources but doesn't map attack paths.
- B. Asset Inventory lists all resources but does not analyze their interdependencies for attack scenarios.
- D. Network Explorer visualizes network connectivity but not necessarily the logical access paths or vulnerabilities that lead to compromise.
Attack Path Analysis
Attack Path Analysis in Prisma Cloud identifies and visualizes potential sequences of actions an attacker could take to compromise critical assets, starting from an initial point of entry.
- Maps relationships between cloud resources and configurations.
- Highlights vulnerabilities and misconfigurations that can be exploited.
- Helps prioritize remediation efforts by showing the 'blast radius' of a compromise.
Memory trick: Think 'Attack Path' for 'Impact Analysis' of a breach.