Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Hard
A security engineer is investigating a potential privilege escalation pathway in an Azure subscription. They suspect that an Azure AD user might be able to gain administrative access to a critical resource by leveraging a series of highly permissive role assignments and group memberships. Which Prisma Cloud CIEM feature is specifically designed to analyze such complex, multi-hop permission chains and highlight potential privilege escalation risks?
- AIdentity Graph Analysis
- BData Security Posture Management (DSPM)
- CVulnerability Management (VM) scans
- DCloud Security Posture Management (CSPM) compliance checks
Show answer & explanationAnswer & explanation
Correct answer: A. Identity Graph Analysis
Identity Graph Analysis in Prisma Cloud CIEM visualizes and analyzes the relationships between identities, permissions, and resources across multi-cloud environments. It is specifically designed to uncover complex, multi-hop access paths and potential privilege escalation routes that are difficult to identify with traditional methods.
Why the other options are wrong
- B. DSPM focuses on data discovery and classification, not identity access paths.
- C. VM scans detect software vulnerabilities, not identity-based privilege escalation paths.
- D. CSPM focuses on misconfigurations, not complex identity access paths and privilege escalation.
Identity Graph Analysis
A CIEM capability that uses graph database technology to visualize and analyze the intricate relationships between identities, permissions, and resources, revealing hidden access paths and privilege escalation risks.
- Uncovers multi-hop access paths
- Identifies privilege escalation vectors
- Provides visual representation of identity relationships
Memory trick: Graph analysis maps the 'who can jump to what' in a complex web.