PSE-PRISMACLOUD · Question #75
Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)
The correct answer is A. Excessive login failures B. Unusual user activity D. Account hijacking attempts. Prisma Cloud comes with three predefined anomaly policies out of the box: Excessive login failures (A), Unusual user activity (B), and Account hijacking attempts (D). These target identity-based threats - brute force attempts, behavioral anomalies from users, and credential…
Question
Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)
Options
- AExcessive login failures
- BUnusual user activity
- CDenial-of-service activity
- DAccount hijacking attempts
- ESuspicious file activity
How the community answered
(37 responses)- A89% (33)
- C3% (1)
- E8% (3)
Explanation
Prisma Cloud comes with three predefined anomaly policies out of the box: Excessive login failures (A), Unusual user activity (B), and Account hijacking attempts (D). These target identity-based threats - brute force attempts, behavioral anomalies from users, and credential compromise - which are the most critical cloud account security risks Prisma Cloud monitors by default.
Why C and E are wrong: "Denial-of-service activity" (C) and "Suspicious file activity" (E) are not among Prisma Cloud's predefined anomaly policies. DoS detection typically falls under network security tooling, and file activity monitoring is more aligned with endpoint/CSPM controls rather than Prisma's built-in anomaly policy set.
Memory tip: Think "Login, Users, Hijacking" - all three correct answers revolve around identity and authentication, not traffic or files. If a choice is about what a user account is doing (too many logins, odd behavior, being taken over), it's likely in the predefined set.
Topics
Community Discussion
No community discussion yet for this question.