Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Easy

A cloud security engineer is tasked with identifying and managing all human and non-human identities across their multi-cloud environment using Prisma Cloud. Which core CIEM capability is primarily responsible for discovering and cataloging these diverse identities?

  1. AAutomated Remediation Workflows
  2. BPolicy Creation and Enforcement
  3. CIdentity Discovery and Classification
  4. DPrivilege Escalation Path Analysis
Show answer & explanation

Correct answer: C. Identity Discovery and Classification

Identity Discovery and Classification is the foundational CIEM capability that provides visibility into all identities (human, service, role) across cloud environments, which is essential for effective identity management.

Why the other options are wrong

  • A. Automated remediation addresses issues, but doesn't discover the identities themselves.
  • B. Policy creation and enforcement defines rules for identities, but doesn't discover them.
  • D. Privilege escalation analysis identifies risks after identities are discovered.

Identity Discovery

The process of automatically identifying and cataloging all human and non-human identities present across various cloud environments.

  • Establishes a comprehensive inventory of all cloud identities.
  • Includes users, service accounts, roles, and managed identities.
  • Foundational for other CIEM capabilities like least privilege.

Memory trick: Discovering cloud identities is like finding all the actors backstage before the show.

More Cloud Infrastructure Entitlement Management (CIEM) questions