Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A financial institution uses Prisma Cloud CIEM to manage identity permissions across AWS, Azure, and GCP. They are concerned about service accounts with excessive permissions that are rarely used, posing a potential attack vector. Which CIEM feature would best help them identify and then reduce the permissions of these specific service accounts to only what they actually need?
- AUsage-based Rightsizing
- BThreat Detection Alerts
- CCloud Security Posture Management (CSPM)
- DIdentity Governance Dashboard
Show answer & explanationAnswer & explanation
Correct answer: A. Usage-based Rightsizing
Usage-based Rightsizing analyzes actual identity activity to recommend and implement permissions that align with observed usage, effectively reducing over-privileged accounts to a least-privilege state.
Why the other options are wrong
- B. Threat detection alerts identify active threats, not proactively reduce unused excessive permissions.
- C. CSPM focuses on cloud resource misconfigurations, not specifically identity permission usage analysis.
- D. The dashboard provides an overview, but not the specific mechanism for rightsizing permissions based on usage.
Usage-based Rightsizing
A CIEM capability that analyzes the actual usage patterns of an identity's permissions and recommends reducing excessive or unused privileges to achieve a least-privilege state.
- Reduces attack surface by removing unnecessary permissions.
- Based on observed activity, not just defined policies.
- Applies to both human and non-human identities.
Memory trick: Rightsizing permissions is like tailoring a suit: fit it to what's actually needed, not just a generic size.