Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

An organization is migrating sensitive workloads to the cloud and using Prisma Cloud for security. They need to ensure that only specific security administrators can view and modify compliance policies related to PCI DSS, while other administrators can only view general security posture and manage alerts. What is the most granular and secure way to implement this access control within Prisma Cloud?

  1. AImplementing multifactor authentication for all administrators to secure access, regardless of role.
  2. BCreating custom roles with specific permissions for viewing and managing PCI DSS policies and assigning them to relevant users.
  3. CProviding read-only access to all administrators and requiring a separate approval process for policy changes.
  4. DAssigning all administrators to a single 'Security Admin' role and relying on manual oversight.
Show answer & explanation

Correct answer: B. Creating custom roles with specific permissions for viewing and managing PCI DSS policies and assigning them to relevant users.

Prisma Cloud's Role-Based Access Control (RBAC) allows for the creation of custom roles with highly granular permissions, enabling administrators to define exactly what actions users can perform on specific types of resources or policies, thus meeting the requirement for differentiated access.

Why the other options are wrong

  • A. MFA enhances authentication security but does not provide granular authorization control over what actions users can perform once authenticated.
  • C. Read-only access for all does not allow for policy modification by authorized personnel and is not granular enough.
  • D. A single broad role violates the principle of least privilege and does not differentiate access to PCI DSS policies.

Prisma Cloud Custom RBAC Roles

User-defined roles within Prisma Cloud's Role-Based Access Control (RBAC) system that allow granular specification of permissions for different user groups over various platform features and cloud resources.

  • Enforces the principle of least privilege.
  • Allows separation of duties for different security functions.
  • Permissions can be defined for specific features, resource types, or policy categories.

Memory trick: To control access finely, carve custom roles for each security key.

More Prisma Cloud Platform questions