Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Easy
A security auditor is reviewing the access control implementation for Prisma Cloud within a large organization. The auditor needs to confirm that users are granted the minimum necessary privileges to perform their roles, following the principle of least privilege. Specifically, a user responsible for reviewing vulnerability scan results and compliance reports, but not making any configuration changes, needs appropriate access. Which built-in Prisma Cloud role best suits this user's requirements?
- ADeveloper
- BAuditor
- CAdministrator
- DOperator
Show answer & explanationAnswer & explanation
Correct answer: B. Auditor
The Auditor role in Prisma Cloud is specifically designed for users who need read-only access to security events, vulnerability reports, and compliance dashboards without the ability to modify configurations or deploy resources.
Why the other options are wrong
- A. Developer roles usually focus on integrating security into development workflows, not just reviewing reports.
- C. Administrator has full control and can make configuration changes, violating least privilege.
- D. Operator typically has permissions to manage deployments and potentially some configurations, which is more than read-only.
Prisma Cloud Auditor Role
The Auditor role in Prisma Cloud provides read-only access to security dashboards, vulnerability reports, compliance reports, and audit logs. It is ideal for users who need to review security posture without the ability to make changes.
- Read-only access
- Focuses on reports and dashboards
- Adheres to the principle of least privilege for review functions
Memory trick: Each role in Prisma Cloud has a specific job: Admin, Auditor, Operator, Developer.