Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Easy

A security operations team uses Prisma Cloud CIEM to monitor suspicious activity. They receive an alert indicating that an infrequently used service account, typically operating only during business hours, attempted to create an EC2 instance in a different region at 3 AM. Which CIEM capability is most likely responsible for generating this alert?

  1. AAnomaly detection
  2. BLeast privilege enforcement
  3. CIdentity and access management (IAM) visibility
  4. DIdentity-based microsegmentation
Show answer & explanation

Correct answer: A. Anomaly detection

The scenario describes unusual behavior (infrequently used account, off-hours, unusual region, unusual action), which is a classic indicator of an anomaly. Anomaly detection capabilities in CIEM are designed to identify and alert on such deviations from normal patterns.

Why the other options are wrong

  • B. Least privilege enforcement prevents excessive permissions, it doesn't detect unusual *usage* of existing permissions.
  • C. IAM visibility identifies permissions but doesn't inherently detect unusual *activity* based on those permissions.
  • D. Identity-based microsegmentation focuses on network access, not the behavioral patterns of service accounts.

Anomaly Detection (CIEM)

The CIEM capability that monitors identity activity, establishes baselines of normal behavior, and flags deviations as potential threats or misconfigurations.

  • Uses machine learning to identify unusual patterns.
  • Detects compromised credentials or insider threats.
  • Alerts on deviations in time, location, resource, or action.

Memory trick: Anomaly: Something's off, it's not normal!

More Cloud Infrastructure Entitlement Management (CIEM) questions