Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Easy
A security analyst is reviewing Prisma Cloud's CIEM dashboard for a multi-cloud environment. They notice several 'Shadow Admin' alerts for AWS IAM roles. Which core CIEM capability is primarily identifying these potential over-privileged identities?
- AIdentity and access management (IAM) visibility
- BAnomaly detection
- CRemediation workflows
- DIdentity-based microsegmentation
Show answer & explanationAnswer & explanation
Correct answer: A. Identity and access management (IAM) visibility
IAM visibility is the foundational capability that discovers and maps all identities and their permissions, allowing for the identification of over-privileged roles like 'Shadow Admins'. Without this visibility, other CIEM functions cannot operate effectively.
Why the other options are wrong
- B. Anomaly detection identifies unusual behavior, but visibility is needed first to define normal.
- C. Remediation workflows are actions taken after an issue is identified, not the identification mechanism itself.
- D. Identity-based microsegmentation focuses on network access based on identity, not primarily on identifying over-privileged roles.
IAM Visibility (CIEM)
The capability within CIEM to discover, map, and analyze all identities (human and machine) and their effective permissions across multi-cloud environments.
- Foundation for all other CIEM capabilities.
- Identifies who has access to what, and how.
- Uncovers 'Shadow Admins' and permission sprawl.
Memory trick: CIEM sees all, secures all.