Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium

A security engineer is configuring Prisma Cloud CIEM to enforce least privilege for an AWS S3 bucket. They want to ensure that an application's IAM role can only perform 's3:GetObject' actions on objects within a specific prefix, 'app-data/', and nothing else. Which CIEM feature directly helps in defining and automatically enforcing this granular level of access?

  1. ACloud asset inventory
  2. BAnomaly detection
  3. CIdentity-based microsegmentation
  4. DPolicy creation and enforcement
Show answer & explanation

Correct answer: D. Policy creation and enforcement

Policy creation and enforcement is the CIEM feature responsible for defining and implementing specific rules, such as resource-level permissions (e.g., 's3:GetObject' on a specific prefix), to ensure least privilege.

Why the other options are wrong

  • A. Cloud asset inventory discovers resources but doesn't define or enforce access policies on them.
  • B. Anomaly detection flags unusual behavior but doesn't define or enforce static access permissions.
  • C. Identity-based microsegmentation controls network access, not object-level S3 permissions.

Least Privilege Enforcement

The security principle and CIEM capability of granting identities only the minimum permissions necessary to perform their intended functions, and no more.

  • Reduces attack surface and blast radius.
  • Often implemented through fine-grained policies.
  • Requires continuous monitoring and adjustment.

Memory trick: Least Privilege: Only what you need, nothing more.

More Cloud Infrastructure Entitlement Management (CIEM) questions