Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Hard

A cloud security engineer is configuring Prisma Cloud CIEM to monitor for 'shadow IT' identities—those created outside standard provisioning processes or with excessive permissions that bypass established security baselines. Which combination of CIEM capabilities would be most effective in continuously identifying and highlighting such rogue identities?

  1. AIdentity and access management (IAM) visibility, combined with policy creation and anomaly detection.
  2. BData Security Posture Management (DSPM) for sensitive data access and network microsegmentation.
  3. CVulnerability management (VM) scans for outdated software and cloud network analyzer.
  4. DCloud Security Posture Management (CSPM) for resource misconfigurations and incident response playbooks.
Show answer & explanation

Correct answer: A. Identity and access management (IAM) visibility, combined with policy creation and anomaly detection.

To detect 'shadow IT' identities, you need comprehensive IAM visibility to discover all identities, policy creation to define what 'standard' looks like, and anomaly detection to flag those that deviate from the norm or exhibit suspicious behavior. This combination allows for continuous monitoring and identification of rogue identities.

Why the other options are wrong

  • B. DSPM and microsegmentation target data and network, not the discovery and monitoring of rogue identities.
  • C. VM scans and network analysis focus on software vulnerabilities and network traffic, not identity provisioning or rogue identities.
  • D. CSPM focuses on resource misconfigurations, and incident response is reactive; detecting 'shadow IT' requires proactive identity-focused capabilities.

Shadow IT Identity Detection

The process of identifying and flagging identities (users, roles, service accounts) that have been created or configured outside of approved processes, often with excessive or unmonitored permissions.

  • Reduces unauthorized access risk
  • Requires comprehensive identity visibility
  • Leverages policy and anomaly detection

Memory trick: Ghost identities lurk; see them, define normal, flag anomalies.

More Cloud Infrastructure Entitlement Management (CIEM) questions