Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Easy

A security analyst is reviewing Prisma Cloud's CIEM dashboard for a multi-cloud environment. They notice several 'Shadow Admin' alerts for AWS IAM roles. Which core CIEM capability is primarily identifying these potential over-privileged identities?

  1. AIdentity and access management (IAM) visibility
  2. BAnomaly detection
  3. CRemediation workflows
  4. DIdentity-based microsegmentation
Show answer & explanation

Correct answer: A. Identity and access management (IAM) visibility

IAM visibility is the foundational capability that discovers and maps all identities and their permissions, allowing for the identification of over-privileged roles like 'Shadow Admins'. Without this visibility, other CIEM functions cannot operate effectively.

Why the other options are wrong

  • B. Anomaly detection identifies unusual behavior, but visibility is needed first to define normal.
  • C. Remediation workflows are actions taken after an issue is identified, not the identification mechanism itself.
  • D. Identity-based microsegmentation focuses on network access based on identity, not primarily on identifying over-privileged roles.

IAM Visibility (CIEM)

The capability within CIEM to discover, map, and analyze all identities (human and machine) and their effective permissions across multi-cloud environments.

  • Foundation for all other CIEM capabilities.
  • Identifies who has access to what, and how.
  • Uncovers 'Shadow Admins' and permission sprawl.

Memory trick: CIEM sees all, secures all.

More Cloud Infrastructure Entitlement Management (CIEM) questions