ExamGecko
Question list
Search
Search

List of questions

Search

Question 103 - PCCSE discussion

Report
Export

A customer wants to monitor the company's AWS accounts via Prisma Cloud, but only needs the resource configuration to be monitored for now.

Which two pieces of information do you need to onboard this account? (Choose two.)

A.
Cloudtrail
Answers
A.
Cloudtrail
B.
Subscription ID
Answers
B.
Subscription ID
C.
Active Directory ID
Answers
C.
Active Directory ID
D.
External ID
Answers
D.
External ID
E.
Role ARN
Answers
E.
Role ARN
Suggested answer: A, E

Explanation:

To onboard an AWS account into Prisma Cloud for the purpose of monitoring resource configurations, the necessary information includes the Role ARN (Amazon Resource Name) and CloudTrail setup. The Role ARN (Option E) is crucial because Prisma Cloud requires permission to access and monitor resources within the AWS account, which is facilitated through an IAM role that Prisma Cloud can assume. This IAM role must have the necessary permissions to access AWS services and resources that Prisma Cloud needs to monitor. CloudTrail (Option A) is essential for auditing and monitoring API calls within the AWS environment, including those related to resource configurations. It provides visibility into user and resource activity by recording API calls made on the account. CloudTrail logs are used by Prisma Cloud to detect changes in resource configurations and ensure compliance with security policies. Subscription ID (Option B) and Active Directory ID (Option C) are more relevant to Azure cloud environments, not AWS. External ID (Option D) is used in a cross-account role trust relationship to prevent the 'confused deputy' problem, but it's not specifically required just to onboard the account for resource configuration monitoring.

asked 23/09/2024
Theodoros Flabouras
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first