Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Hard
A cloud security architect is designing a secure multi-cloud environment. They want to ensure that access to sensitive data buckets is only granted if the requesting identity originates from an approved network segment AND is accessing during business hours. Which CIEM capability best supports this requirement?
- APrivilege Escalation Path Analysis
- BIdentity Lifecycle Management
- CContext-aware Access Control
- DIdentity-based Microsegmentation
Show answer & explanationAnswer & explanation
Correct answer: C. Context-aware Access Control
Context-aware Access Control evaluates multiple contextual factors (like network origin, time of day, device posture) in addition to identity and resource attributes to make dynamic access decisions.
Why the other options are wrong
- A. Privilege escalation path analysis identifies potential risks, but doesn't enforce access based on context.
- B. Identity lifecycle management focuses on provisioning and deprovisioning identities, not dynamic access decisions.
- D. Identity-based microsegmentation segregates network traffic based on identity, but doesn't typically incorporate time-of-day or network origin for access to data buckets at this level of granularity.
Context-aware Access Control
An access control mechanism that evaluates environmental factors beyond just identity and resource attributes, such as location, time, device posture, and network segment, to make dynamic authorization decisions.
- Enhances security by adding layers of contextual validation.
- Reduces risk of compromised credentials being misused.
- Goes beyond traditional RBAC/ABAC by incorporating 'when' and 'where'.
Memory trick: Context-aware access is like a smart gate: it checks your ID, but also *where* you are and *when* you're trying to enter.