Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security auditor is performing a review of Prisma Cloud's access control configurations. They specifically need to verify that all users who have been assigned the 'Auditor' role can only view data and cannot make any changes or configurations within the Prisma Cloud console. Which type of access control best describes this 'read-only' permission level?

  1. AMandatory Access Control (MAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CDiscretionary Access Control (DAC)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: D. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) is the access control model where permissions are associated with specific roles (e.g., 'Auditor'), and users are assigned to those roles. This allows for defining 'read-only' permissions for a role, which is then inherited by all users assigned to it.

Why the other options are wrong

  • A. MAC is a highly restrictive model, typically used in high-security environments, where access is determined by security labels, which is not applicable here.
  • B. ABAC grants access based on attributes of the user, resource, and environment, which is more dynamic and complex than simply assigning 'read-only' to a role.
  • C. DAC allows resource owners to determine who can access their resources, which is not how centralized role-based permissions are managed in Prisma Cloud.

Role-Based Access Control (RBAC)

An access control methodology where permissions are associated with roles, and users are assigned to roles, thereby inheriting the permissions defined for that role.

  • Simplifies user management by grouping permissions.
  • Enables segregation of duties and least privilege.
  • Widely used in enterprise security platforms like Prisma Cloud.

Memory trick: Roles give access, like job titles give duties.

More Prisma Cloud Platform questions