

Prisma Cloud and AWS WAF are both security solutions competing in the cloud security space. Prisma Cloud has the upper hand due to its extensive integration capabilities and comprehensive security features.
Features: Prisma Cloud offers dynamic workload identity creation and assignment, cloud security posture management, and cloud workload protection. AWS WAF provides web traffic filtering, IP address blocking, and customizable security rules.
Room for Improvement: Prisma Cloud needs better documentation, licensing clarity, and a more intuitive interface. AWS WAF could improve rule management, bot protection, and automation.
Ease of Deployment and Customer Service: Prisma Cloud offers flexibility and extensive support, though setup can be complex. AWS WAF benefits from AWS's robust infrastructure but has mixed customer service feedback.
Pricing and ROI: Prisma Cloud's pricing is based on workloads and offers strong ROI in risk reduction, but can be costly. AWS WAF's pay-as-you-go model may suit smaller applications, with lower pricing but less extensive ROI in cloud security.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
It eliminates the need for additional hardware, making it a financially and technically sound investment.
There was a cost reduction. That was the benefit that we had visualized while evaluating Prisma Cloud as one of the possible solutions.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
They can respond with technical documentation or pass on the case to the next level because it requires the development of a new feature or changing a feature due to a bug.
Anywhere we raise a tech case, they revert back within an hour.
I would give them 10 out of 10.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
Scalability within the credit limit is good. It is 100%.
I would rate it a ten out of ten for scalability.
I would rate it a nine out of ten for scalability.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
We faced issues with AWS WAF when writing the custom rules.
I would rate it a ten out of ten for stability.
We had issues whenever we were downloading the vulnerability report. It did not include all the information.
Once the issues were identified, Palo Alto applied the correct solutions to ensure high availability and scalability.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
The level of granularity is not great, and as you cross a certain threshold, the cost goes up by twenty or thirty percent every time.
We could have deployed the runtime monitoring with Prisma Cloud by Palo Alto Networks, but within our organization at our company, it was very difficult to find who would be the owner for the alerts.
Even though documentation was available, it took a while for a new person to understand what integration meant, what will be achieved after the integration, or how the integration needed to be done on the Azure or AWS side.
Having auto Defender upgrades so that we do not have to upgrade Defender manually would be helpful.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
The cost was not on the higher side.
However, its price can be better so that small banks or small organizations can afford it and adopt it to secure their environment and data.
The pricing for Prisma Cloud is high.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
The specific outcomes showing how AWS WAF has helped our organization include improving our security posture by reducing the attack surface and reducing malicious attacks.
Its ability to centralize and address security vulnerabilities across these diverse environments makes it a crucial and decisive element within the Prisma Cloud ecosystem.
For CWP, the runtime protection is the most valuable feature. Every tool does vulnerability monitoring through tools such as Qualys, but the additional feature we get here is runtime protection in CWP.
It is as easy as registering a new subscription to AWS, and you start seeing all that data.
| Product | Mindshare (%) |
|---|---|
| Prisma Cloud by Palo Alto Networks | 1.9% |
| AWS WAF | 3.9% |
| Other | 94.2% |

| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 28 |
| Company Size | Count |
|---|---|
| Small Business | 37 |
| Midsize Enterprise | 21 |
| Large Enterprise | 58 |
AWS WAF provides configurable rules, integration with AWS services, and scalable protection against web threats like SQL injections and DDoS attacks. Its automation and reliable performance are highly valued by users.
AWS WAF is a web application firewall offering significant security features like geo-restriction, custom rules, and IP filtering. Designed for seamless orchestration within AWS environments, it facilitates easy configuration and threat automation. Users benefit from its security policies, enhancing application performance by protecting against threats such as cross-site scripting. Despite its strengths, there is a call for enhanced user interfaces, better documentation, flexible pricing, and improved support. Expanding features like real-time analysis, bot protection, and AI integration can further elevate its utility.
What are the key features of AWS WAF?AWS WAF is extensively used in industries hosting applications on AWS, protecting sensitive data, and monitoring for unauthorized access. Custom and managed rules help cater to infrastructure needs, serving a vital role in maintaining application security across various sectors.
Prisma Cloud by Palo Alto Networks provides comprehensive cloud-native security solutions. It covers dynamic workload identity, automated forensics, and multi-cloud protection, ensuring robust security across diverse cloud platforms.
Prisma Cloud delivers advanced capabilities for managing cloud security across AWS, Azure, and GCP platforms. It offers dynamic workload identity creation, real-time monitoring, and seamless integration into CI/CD pipelines. With automation, centralized dashboards, and enhanced visibility, users effectively manage security misconfigurations and vulnerabilities. While optimizing cloud environments through runtime protection and compliance, Prisma Cloud faces challenges with its navigation, pricing, and limited automation capabilities. Users seek improvements in API security, role-based access controls, and documentation quality, emphasizing the need for enhanced customization and reporting features.
What are the important features of Prisma Cloud?
What benefits or ROI should users consider in reviews?
Industries like finance and telecom rely on Prisma Cloud for managing cloud security posture and container security. Teams utilize its capabilities across hybrid and multi-cloud settings to ensure compliance and robust threat protection. Features like misconfiguration detection and runtime monitoring are critical in promoting security objectives in these sectors.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.