Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A security engineer is configuring a new AWS account for onboarding into Prisma Cloud. To minimize the permissions granted to Prisma Cloud while ensuring full CSPM functionality, which of the following is the most granular and recommended access type for a read-only role?

  1. AAWS Managed Policy 'SecurityAudit'
  2. BPrisma Cloud Managed Template for Read-Only Access
  3. CAWS Managed Policy 'ReadOnlyAccess'
  4. DCustom IAM Policy with only specific `s3:GetObject` and `ec2:DescribeInstances` permissions
Show answer & explanation

Correct answer: B. Prisma Cloud Managed Template for Read-Only Access

Prisma Cloud provides its own managed templates for read-only access (and other access types) which are specifically tailored to include only the necessary permissions for Prisma Cloud to perform its functions without over-privileging the role. These templates are updated by Palo Alto Networks to reflect new services and required permissions.

Why the other options are wrong

  • A. AWS Managed Policy 'SecurityAudit' is also very broad and includes permissions beyond what Prisma Cloud requires for CSPM, such as permissions for CloudTrail and Config.
  • C. AWS Managed Policy 'ReadOnlyAccess' is broader than necessary and may grant permissions Prisma Cloud doesn't need.
  • D. Creating a custom IAM policy from scratch for all required services is complex, error-prone, and difficult to maintain as Prisma Cloud evolves.

Prisma Cloud Onboarding Access

The method of granting Prisma Cloud the necessary permissions to discover and monitor resources within a cloud environment.

  • Utilizes IAM roles in AWS/GCP, or Service Principals in Azure.
  • Prisma Cloud provides managed templates for minimal permissions.
  • Read-only access is typically sufficient for CSPM.

Memory trick: Managed templates are the 'key' to 'least privilege'.

More Cloud Security Posture Management (CSPM) questions