PCCSE · Question #101
An administrator needs to detect and alert on any activities performed by a root account. Which policy type should be used?
The correct answer is D. audit event. Audit Event policies in Prisma Cloud monitor cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log, GCP Audit Logs) to detect specific user actions and API calls in real time. Detecting 'who did what' - such as actions taken by a root or privileged account - is precisely…
Question
An administrator needs to detect and alert on any activities performed by a root account. Which policy type should be used?
Options
- Aconfig-run
- Bconfig-build
- Cnetwork
- Daudit event
How the community answered
(42 responses)- A2% (1)
- B5% (2)
- C2% (1)
- D90% (38)
Explanation
Audit Event policies in Prisma Cloud monitor cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log, GCP Audit Logs) to detect specific user actions and API calls in real time. Detecting 'who did what' - such as actions taken by a root or privileged account - is precisely the use case for Audit Event policies. Config-run and config-build policies evaluate resource configuration state, and Network policies analyze traffic; neither captures identity-based activity logs.
Topics
Community Discussion
No community discussion yet for this question.