Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy

A security auditor is reviewing the access control implementation for Prisma Cloud within a large organization. The auditor needs to confirm that users are granted the minimum necessary privileges to perform their roles, following the principle of least privilege. Specifically, a user responsible for reviewing vulnerability scan results and compliance reports, but not making any configuration changes, needs appropriate access. Which built-in Prisma Cloud role best suits this user's requirements?

  1. ADeveloper
  2. BAuditor
  3. CAdministrator
  4. DOperator
Show answer & explanation

Correct answer: B. Auditor

The Auditor role in Prisma Cloud is specifically designed for users who need read-only access to security events, vulnerability reports, and compliance dashboards without the ability to modify configurations or deploy resources.

Why the other options are wrong

  • A. Developer roles usually focus on integrating security into development workflows, not just reviewing reports.
  • C. Administrator has full control and can make configuration changes, violating least privilege.
  • D. Operator typically has permissions to manage deployments and potentially some configurations, which is more than read-only.

Prisma Cloud Auditor Role

The Auditor role in Prisma Cloud provides read-only access to security dashboards, vulnerability reports, compliance reports, and audit logs. It is ideal for users who need to review security posture without the ability to make changes.

  • Read-only access
  • Focuses on reports and dashboards
  • Adheres to the principle of least privilege for review functions

Memory trick: Each role in Prisma Cloud has a specific job: Admin, Auditor, Operator, Developer.

More Cloud Workload Protection Platform (CWPP) questions