Prisma Certified Cloud Security Engineer (PCCSE) — Question 61

Anomaly policy uses which two logs to identify unusual network and user activity? (Choose two.)

Answer options

Correct answer: A, B

Explanation

The correct answers are A and B because the anomaly policy specifically relies on Network flow and Audit logs to monitor and identify unusual patterns in network and user activities. Options C (Traffic) and D (Users) are not correct as they do not represent logs that the anomaly policy uses for its detection processes.