Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A security auditor is reviewing a Prisma Cloud CIEM implementation and observes that several AWS IAM roles have permissions to modify critical infrastructure, but these permissions are rarely, if ever, used. The auditor recommends enforcing least privilege. Which Prisma Cloud CIEM feature should the security team leverage to automatically right-size these over-privileged roles based on actual usage?
- ACloud Security Posture Management (CSPM) baselines
- BUsage-based Rightsizing
- CResource Query Language (RQL)
- DPolicy-as-Code templates
Show answer & explanationAnswer & explanation
Correct answer: B. Usage-based Rightsizing
Usage-based Rightsizing in Prisma Cloud CIEM analyzes actual identity activity over time and recommends or automatically applies policies that grant only the permissions truly required by an identity, thereby enforcing least privilege based on observed usage.
Why the other options are wrong
- A. CSPM baselines define desired security states but don't automatically right-size permissions based on usage.
- C. RQL is a query language for finding resources, not for automated permission adjustments.
- D. Policy-as-Code templates define policies but don't automatically adjust them based on usage.
Usage-based Rightsizing
A CIEM capability that automatically analyzes identity activity to determine actual permission usage and then recommends or enforces policies that grant only the necessary permissions.
- Automates least privilege enforcement
- Reduces attack surface
- Continuously adapts to changing usage patterns
Memory trick: Rightsizing means giving just enough, based on what's used.