Support · Self-Service

Frequently Asked Questions

Quick answers to the questions we hear most. Don't see yours? Ask the CLARA Assistant below or ping #help-netsec-clara on Slack.

Ask CLARA Assistant →

Common Questions

These answers reflect the shipped CLARA suite as of today. For the very latest — including new regions, cloud coverage, or roadmap timing — check with the Loop page or the CLARA Assistant.

What is CLARA?

CLARA (Cloud and AI Risk Assessment) is a complimentary, expert-led assessment suite from Palo Alto Networks. It bundles three assessments that quantify risk across a customer's cloud network, firewalls, and AI applications, and turns raw evidence into data-driven security decisions.

The three shipped assessments are the Cloud Network Risk Assessment, Cloud Firewall Benchmarking, and AI Risk Assessment.

Is CLARA free for customers?

Yes. All three assessments are complimentary — no cost to the customer. Customers get dedicated access to senior Palo Alto Networks security engineers throughout the engagement.

The only exception is Cloud Firewall Benchmarking when customer-hosted (rather than PANW-hosted), which incurs approximately $50 one-time in cloud infrastructure spend for the six test instances.

How long does each assessment take?
  • Cloud Network Risk Assessment — under 24 hours for Discovery Mode; 5–7 days of passive collection for Mirror Mode.
  • Cloud Firewall Benchmarking — under 24 hours from deploy to report.
  • AI Risk Assessment — 2–3 hours end-to-end (the scan itself takes ~25 minutes at default settings).
Which clouds are supported?
  • Cloud Network Risk Assessment — AWS, Azure, and GCP.
  • Cloud Firewall Benchmarking — AWS and Azure only. GCP is not supported today. For GCP customers, position the Cloud Network Risk Assessment instead.
  • AI Risk Assessment — cloud-agnostic; runs against any AI application reachable via a cURL command from the host machine.
Which regions is CLARA available in?
  • Cloud Network — Discovery Mode: US, CA, UK, DE, NL, IN, SG, AU.
  • Cloud Network — Mirror Mode: United States only.
  • Firewall Benchmarking: Worldwide — no regional restrictions.
  • AI Risk Assessment: US, NL, SG, JP.
Does CLARA require write access to a customer's cloud account?

No. Prerequisites are minimal and privilege-conscious:

  • Cloud Network: read-only access to the cloud account plus an existing cloud storage bucket.
  • Firewall Benchmarking: quota for six test instances in a non-production environment. The assessment runs in an isolated sandbox with zero risk to production traffic.
  • AI Risk Assessment: browser access to the AI application and access to an SCM tenant to upload results.
What standards and frameworks are findings mapped to?

Findings are audit-ready by default:

  • CIS Benchmarks and NIST — Cloud Network and Firewall assessments.
  • OWASP ML Top 10, NIST AI RMF, and MITRE ATLAS — AI Risk Assessment.
  • Miercom test methodology and Cyperf strike pack — used by Firewall Benchmarking.
What's the difference between Discovery Mode and Mirror Mode?

Both are delivery modes of the Cloud Network Risk Assessment. They differ in depth and access level:

  • Discovery Mode (low touch): read-only onboarding to Strata Cloud Manager. Analyzes VPC flow logs — L3/L4 metadata only. Under 24-hour TTV. Available in eight countries.
  • Mirror Mode / Cloud SLR (high touch): deploys a tap-mode firewall via native cloud traffic mirroring for full L7 packet inspection. Runs silently for 5–7 days with zero performance impact. US only today.

Discovery Mode is the right starting point for customers uncomfortable with in-line inspection or those outside the US.

What deliverables do customers get?
  • Cloud Network: Cloud SLR report — protected vs unprotected assets, application inventory (App-ID / User-ID), threats found in traffic, and a Zero Trust segmentation blueprint.
  • Firewall Benchmarking: Security Validation Report (SVR) — side-by-side blocking rates, threat categorization, test topology, and an appendix listing every injected threat with per-DUT block status.
  • AI Risk: AI Red Team Brief — critical application vulnerabilities, guardrail testing results, and remediation aligned to OWASP / NIST / MITRE ATLAS.
What's coming next in CLARA?

AI Benchmarking is on the roadmap — a fourth CLARA assessment that will prove Prisma AIRS efficacy against native cloud AI safety guardrails. It uses the same non-intrusive CyPerf (Keysight) sandbox that powers Firewall Benchmarking today.

See the roadmap preview on the AI Risk page for more.

Where do I get the AI Risk Assessment scan package?

Clone or download it from the official Palo Alto Networks repository: github.com/PaloAltoNetworks/clara-ai-risk-assessment.

The Resources section on the AI Risk page also links directly to the deployment guide, sample report, and demo video.

Where do I get help if I have more questions?
  • Ask CLARA Assistant below — real-time answers grounded in the same material you're reading now.
  • Slack: #help-netsec-clara — real-time help from the CLARA team on positioning, deployments, and demo troubleshooting.
  • The Loop: CLARA Risk portal — full internal resource hub, sales toolkit, technical FAQs, request forms.

Ask CLARA Assistant

A Claude-powered chat trained on the CLARA material in this training site. It's best at questions about the three assessments — anything outside that scope, it'll redirect you to the right place.

CLARA Assistant

Enter to send · Shift+Enter for a new line · Reload clears the conversation