nerdexam
Palo_Alto_Networks

PSE-PRISMACLOUD · Question #104

Which type of alert captures unusual user activity and excessive login failures?

The correct answer is A. Anomaly. Anomaly alerts are designed to detect deviations from established baselines, making them the right fit for unusual user behavior and excessive login failures - both patterns that diverge from normal activity. B. Audit Event alerts track specific logged actions (file access…

Prisma Cloud Alert Management

Question

Which type of alert captures unusual user activity and excessive login failures?

Options

  • AAnomaly
  • BAudit Event
  • CConfiguration
  • DNetwork

How the community answered

(56 responses)
  • A
    89% (50)
  • B
    2% (1)
  • C
    5% (3)
  • D
    4% (2)

Explanation

Anomaly alerts are designed to detect deviations from established baselines, making them the right fit for unusual user behavior and excessive login failures - both patterns that diverge from normal activity.

  • B. Audit Event alerts track specific logged actions (file access, policy changes) for compliance purposes - they record what happened, not whether it's abnormal.
  • C. Configuration alerts fire when system settings change unexpectedly, not when user behavior is suspicious.
  • D. Network alerts monitor traffic patterns, bandwidth, or connectivity issues - not authentication or user behavior.

Memory tip: Think "A for Abnormal" - Anomaly = something that doesn't match the expected pattern, whether it's a user logging in 50 times or accessing resources at 3am.

Topics

#anomaly alerts#user behavior#login failures#alert types

Community Discussion

No community discussion yet for this question.

Full PSE-PRISMACLOUD Practice