Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A security engineer is configuring Prisma Cloud's access control for a team of developers who need to view container vulnerability reports and compliance status but should NOT be able to modify any security policies or deploy Defenders. Which built-in role in Prisma Cloud would provide the LEAST privileged access while meeting these requirements?
- AOperator
- BAuditor
- CDevSecOps
- DAdministrator
Show answer & explanationAnswer & explanation
Correct answer: B. Auditor
The Auditor role in Prisma Cloud is designed for users who need read-only access to security posture, vulnerability reports, and compliance status, aligning perfectly with the requirement to view reports without modifying policies or deploying Defenders.
Why the other options are wrong
- A. Operator typically has permissions to manage deployments and some operational aspects, potentially including Defender deployment.
- C. DevSecOps roles usually have permissions to integrate security into CI/CD and potentially deploy, which is more than read-only.
- D. Administrator has full control and can modify policies and deploy Defenders.
Prisma Cloud Auditor Role
A built-in role in Prisma Cloud that grants read-only access to security posture, vulnerability, and compliance reports.
- Provides visibility without modification privileges.
- Ideal for compliance officers, auditors, or non-security developers.
- Ensures least privilege for reporting and monitoring.
Memory trick: Roles define what you can 'do' in Prisma Cloud: Admin commands, Operator acts, Auditor observes, DevSecOps builds secure.