Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium

A financial institution uses Prisma Cloud CIEM to manage identities across AWS, Azure, and GCP. A new compliance requirement dictates that all service accounts with read access to production databases must be reviewed for activity every 30 days and have unused permissions revoked. Which CIEM process would be most effective for automating this continuous review and remediation?

  1. ACSPM policy scans for misconfigurations
  2. BCloud discovery and inventory reports
  3. CAutomated remediation workflows triggered by CIEM policies
  4. DNetwork segmentation rules for database access
Show answer & explanation

Correct answer: C. Automated remediation workflows triggered by CIEM policies

Automated remediation workflows in CIEM, triggered by policies detecting over-privileged or unused permissions, are designed to continuously review and revoke permissions. This directly addresses the compliance requirement for regular review and remediation of service account access.

Why the other options are wrong

  • A. CSPM scans detect misconfigurations but don't automatically review and revoke permissions based on usage.
  • B. Discovery and inventory reports provide a snapshot but don't automate continuous review and remediation of permissions.
  • D. Network segmentation controls network access, not identity permissions to databases.

Automated Remediation (CIEM)

The capability within a CIEM solution to automatically take corrective actions, such as revoking permissions or modifying policies, based on detected policy violations or security risks.

  • Reduces manual security overhead
  • Ensures continuous compliance
  • Accelerates incident response

Memory trick: Remediation means fixing problems, especially automatically.

More Cloud Infrastructure Entitlement Management (CIEM) questions