Prisma Access Traffic Replication is built on Google Cloud Packet Mirroring, deliberately architected to avoid inserting a physical or virtual appliance into the inline security processing path so that forensic capture has zero performance impact on regular traffic inspection. When an administrator enables Traffic Replication for mobile users, remote networks, or both, Prisma Access provisions dedicated cloud storage buckets in each enabled compute location and continuously writes encrypted PCAP files containing a replica of decrypted traffic traversing that location. Administrators retrieve these files from their own designated GCP service account, which is granted read-only access to the bucket, and decrypt them locally using a private key that only the customer holds — a design that preserves confidentiality even from Palo Alto Networks. This directly rules out option A: there is no requirement, and no supported workflow, to stream mirrored traffic to a customer-managed internal appliance in real time; the architecture is store-and-retrieve, not a live tap. Panorama and Strata Cloud Manager (options C and D) are management and policy planes, not traffic-capture destinations — they configure Traffic Replication settings but never receive or store the mirrored packets themselves. The dedicated cloud storage bucket model is what allows organizations to reconstruct full session flows for breach investigation and post-mortem analysis in SASE architectures where traditional span/tap infrastructure no longer exists.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit