SECOPS-PRO · Question #64
An organization is migrating its security operations to a cloud-native environment, leveraging Palo Alto Networks Prisma Cloud for security posture management and cloud workload protection. Incident r
The correct answer is C. The specific cloud service (e.g., S3 bucket, Lambda function, Kubernetes pod) involved and its. In a cloud-native environment, the specific cloud service and its IAM (Identity and Access Management) permissions are paramount for incident prioritization. A misconfigured S3 bucket with public access, a compromised Lambda function with excessive permissions, or a vulnerable Ku
Question
An organization is migrating its security operations to a cloud-native environment, leveraging Palo Alto Networks Prisma Cloud for security posture management and cloud workload protection. Incident response requires adapting existing on-premise prioritization schemes. Which of the following factors becomes SIGNIFICANTLY more impactful for incident prioritization in a cloud- native context compared to traditional on-premise environments?
Options
- AThe physical location of the server hosting the affected application. This is less relevant in cloud
- BThe organizational unit responsible for the application. While important, this is a consistent factor.
- CThe specific cloud service (e.g., S3 bucket, Lambda function, Kubernetes pod) involved and its
- DThe brand of the underlying hardware vendor. Cloud abstracts hardware, making this irrelevant.
- EThe patching cycle of the operating system. While important, patching is often automated or
How the community answered
(54 responses)- A11% (6)
- B2% (1)
- C80% (43)
- D6% (3)
- E2% (1)
Explanation
In a cloud-native environment, the specific cloud service and its IAM (Identity and Access Management) permissions are paramount for incident prioritization. A misconfigured S3 bucket with public access, a compromised Lambda function with excessive permissions, or a vulnerable Kubernetes pod could lead to rapid data exposure, privilege escalation, or resource abuse, often with broader and faster impact than traditional on-premise incidents. The blast radius and potential for lateral movement are heavily influenced by cloud service configurations and IAM. This makes understanding and prioritizing based on these factors critical.
Topics
Community Discussion
No community discussion yet for this question.