Prisma Certified Cloud Security Engineer (PCCSE) — Question 61
Anomaly policy uses which two logs to identify unusual network and user activity? (Choose two.)
Answer options
- A. Network flow
- B. Audit
- C. Traffic
- D. Users
Correct answer: A, B
Explanation
The correct answers are A and B because the anomaly policy specifically relies on Network flow and Audit logs to monitor and identify unusual patterns in network and user activities. Options C (Traffic) and D (Users) are not correct as they do not represent logs that the anomaly policy uses for its detection processes.