Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityEasy
A cloud administrator is configuring access to a shared object storage bucket containing sensitive customer data. They need to ensure that different teams within the organization have varying levels of access (e.g., read-only for analytics, read-write for application developers, no access for general users). Which cloud security component is primarily responsible for defining and enforcing these fine-grained permissions?
- ANetwork Access Control List (NACL)
- BIdentity and Access Management (IAM)
- CCloud Logging and Monitoring
- DVirtual Private Cloud (VPC)
Show answer & explanationAnswer & explanation
Correct answer: B. Identity and Access Management (IAM)
Identity and Access Management (IAM) is the primary service in cloud environments responsible for managing users, groups, roles, and their associated permissions, allowing administrators to define and enforce fine-grained access control to resources like object storage buckets.
Why the other options are wrong
- A. NACLs control network traffic at the subnet level, not user access to specific resources.
- C. Cloud Logging and Monitoring track activities and resource health, but do not enforce access policies.
- D. VPCs provide network isolation but don't manage user/resource permissions.
Identity and Access Management (IAM)
A framework of policies and technologies that controls who can access what resources under which circumstances in a cloud environment.
- Manages users, groups, and roles
- Defines granular permissions to cloud resources
- Crucial for enforcing the principle of least privilege
Memory trick: IAM: I Am Allowed What I Need.