nerdexam
Palo_Alto_Networks

PCCSE · Question #101

An administrator needs to detect and alert on any activities performed by a root account. Which policy type should be used?

The correct answer is D. audit event. Audit Event policies in Prisma Cloud monitor cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log, GCP Audit Logs) to detect specific user actions and API calls in real time. Detecting 'who did what' - such as actions taken by a root or privileged account - is precisely…

Prisma Cloud Platform

Question

An administrator needs to detect and alert on any activities performed by a root account. Which policy type should be used?

Options

  • Aconfig-run
  • Bconfig-build
  • Cnetwork
  • Daudit event

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    2% (1)
  • D
    90% (38)

Explanation

Audit Event policies in Prisma Cloud monitor cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log, GCP Audit Logs) to detect specific user actions and API calls in real time. Detecting 'who did what' - such as actions taken by a root or privileged account - is precisely the use case for Audit Event policies. Config-run and config-build policies evaluate resource configuration state, and Network policies analyze traffic; neither captures identity-based activity logs.

Topics

#Audit Policies#Root Account Monitoring#Activity Detection#Cloud Security Monitoring

Community Discussion

No community discussion yet for this question.

Full PCCSE Practice