nerdexam
Palo_Alto_Networks

PSE-PRISMACLOUD · Question #111

Which Prisma Public Cloud policy alerts administrators to unusual user activity?

The correct answer is A. Anomaly. Anomaly policies in Prisma Public Cloud are specifically designed to detect unusual or suspicious user behavior by leveraging machine learning and behavioral analytics to identify deviations from normal patterns - making them the correct tool for alerting on unusual user…

Prisma Cloud Alert Management

Question

Which Prisma Public Cloud policy alerts administrators to unusual user activity?

Options

  • AAnomaly
  • BAudit Event
  • CNetwork
  • DConfiguration

How the community answered

(51 responses)
  • A
    90% (46)
  • B
    2% (1)
  • C
    2% (1)
  • D
    6% (3)

Explanation

Anomaly policies in Prisma Public Cloud are specifically designed to detect unusual or suspicious user behavior by leveraging machine learning and behavioral analytics to identify deviations from normal patterns - making them the correct tool for alerting on unusual user activity.

  • Audit Event (B) policies monitor API calls and log-based events for compliance purposes, not behavioral anomalies.
  • Network (C) policies detect suspicious traffic patterns and network threats, not user behavioral anomalies.
  • Configuration (D) policies check cloud resources against security best practices and compliance standards (e.g., "is S3 bucket public?"), not user activity patterns.

Memory tip: Think "Anomaly = Activity that's Abnormal" - all three A's link the policy type to its purpose of flagging unusual user behavior.

Topics

#anomaly policy#unusual user activity#alert types#Prisma Cloud

Community Discussion

No community discussion yet for this question.

Full PSE-PRISMACLOUD Practice