Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A global organization is leveraging Prisma Cloud CIEM to manage identity permissions across its vast multi-cloud infrastructure. They aim to standardize and automate the deployment of least privilege policies across new accounts and services. Which CIEM approach is best suited for achieving this goal effectively and consistently?
- APolicy-as-Code (PaC)
- BJust-in-Time (JIT) Access
- CManual Policy Configuration
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Policy-as-Code (PaC)
Policy-as-Code (PaC) allows defining and managing security policies in a version-controlled, machine-readable format, enabling automation, consistency, and scalability in deploying least privilege across large cloud environments.
Why the other options are wrong
- B. JIT access grants temporary elevated permissions, which is a specific control, not an overarching approach for standardizing all policy deployment.
- C. Manual configuration is prone to errors and lacks scalability for a 'global organization' with 'vast multi-cloud infrastructure'.
- D. RBAC is a mechanism for applying permissions, but PaC is the method for *automating and standardizing* the definition and deployment of those roles/policies.
Policy-as-Code (PaC)
The practice of defining and managing security policies in a structured, machine-readable code format, allowing for automation, version control, and consistent deployment across cloud environments.
- Enables automation of policy deployment and enforcement.
- Provides version control and auditability for policies.
- Ensures consistency and reduces human error in policy management.
Memory trick: Policy-as-Code is like a blueprint for your security rules, ensuring every building (cloud account) is built to the same safe standard.