Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium

A financial institution uses Prisma Cloud CIEM to manage identity permissions across AWS, Azure, and GCP. They are concerned about service accounts with excessive permissions that are rarely used, posing a potential attack vector. Which CIEM feature would best help them identify and then reduce the permissions of these specific service accounts to only what they actually need?

  1. AUsage-based Rightsizing
  2. BThreat Detection Alerts
  3. CCloud Security Posture Management (CSPM)
  4. DIdentity Governance Dashboard
Show answer & explanation

Correct answer: A. Usage-based Rightsizing

Usage-based Rightsizing analyzes actual identity activity to recommend and implement permissions that align with observed usage, effectively reducing over-privileged accounts to a least-privilege state.

Why the other options are wrong

  • B. Threat detection alerts identify active threats, not proactively reduce unused excessive permissions.
  • C. CSPM focuses on cloud resource misconfigurations, not specifically identity permission usage analysis.
  • D. The dashboard provides an overview, but not the specific mechanism for rightsizing permissions based on usage.

Usage-based Rightsizing

A CIEM capability that analyzes the actual usage patterns of an identity's permissions and recommends reducing excessive or unused privileges to achieve a least-privilege state.

  • Reduces attack surface by removing unnecessary permissions.
  • Based on observed activity, not just defined policies.
  • Applies to both human and non-human identities.

Memory trick: Rightsizing permissions is like tailoring a suit: fit it to what's actually needed, not just a generic size.

More Cloud Infrastructure Entitlement Management (CIEM) questions