Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformHard
A development team is using the Prisma Cloud API to automate the deployment of new compliance policies and integrate policy checks into their CI/CD pipeline. They need to authenticate their automation scripts without using a human-managed username and password, and the authentication token should have a limited lifespan and specific permissions. Which API authentication method should they implement?
- AEmbedding an administrator's session cookie directly into the scripts.
- BUtilizing OAuth 2.0 Client Credentials flow to obtain an access token.
- CGenerating a static API token from a user account with administrative privileges.
- DBasic Authentication with a service account's username and password.
Show answer & explanationAnswer & explanation
Correct answer: B. Utilizing OAuth 2.0 Client Credentials flow to obtain an access token.
The OAuth 2.0 Client Credentials flow is ideal for machine-to-machine authentication, providing a secure way for automation scripts to obtain short-lived access tokens with specific scopes (permissions) without requiring human interaction or storing static credentials.
Why the other options are wrong
- A. Embedding session cookies is highly insecure, prone to expiration issues, and not designed for API automation.
- C. Static API tokens, even if generated, often have long lifespans and broad permissions, posing a security risk if compromised.
- D. Basic authentication with static credentials is less secure and lacks granular control over token lifespan and scope.
Prisma Cloud API OAuth 2.0 Client Credentials
An authentication flow within Prisma Cloud's API that allows applications (like automation scripts) to obtain an access token using a client ID and client secret, without user interaction.
- Designed for machine-to-machine communication.
- Tokens are short-lived, enhancing security.
- Supports scope-based authorization for least privilege.
Memory trick: Automated access needs a secure, temporary key, like OAuth's client credentials.