Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A security engineer is configuring Prisma Cloud CIEM to enforce least privilege for an AWS S3 bucket. They want to ensure that an application's IAM role can only perform 's3:GetObject' actions on objects within a specific prefix, 'app-data/', and nothing else. Which CIEM feature directly helps in defining and automatically enforcing this granular level of access?
- ACloud asset inventory
- BAnomaly detection
- CIdentity-based microsegmentation
- DPolicy creation and enforcement
Show answer & explanationAnswer & explanation
Correct answer: D. Policy creation and enforcement
Policy creation and enforcement is the CIEM feature responsible for defining and implementing specific rules, such as resource-level permissions (e.g., 's3:GetObject' on a specific prefix), to ensure least privilege.
Why the other options are wrong
- A. Cloud asset inventory discovers resources but doesn't define or enforce access policies on them.
- B. Anomaly detection flags unusual behavior but doesn't define or enforce static access permissions.
- C. Identity-based microsegmentation controls network access, not object-level S3 permissions.
Least Privilege Enforcement
The security principle and CIEM capability of granting identities only the minimum permissions necessary to perform their intended functions, and no more.
- Reduces attack surface and blast radius.
- Often implemented through fine-grained policies.
- Requires continuous monitoring and adjustment.
Memory trick: Least Privilege: Only what you need, nothing more.