Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

A security engineer is configuring access control for Prisma Cloud users. A new team of developers needs to be able to view all security findings (vulnerabilities, compliance issues) for their applications but must not be able to modify any policies or deploy Defenders. Which Prisma Cloud built-in role is most appropriate for this team?

  1. AOperator
  2. BDeveloper
  3. CAdministrator
  4. DAuditor
Show answer & explanation

Correct answer: D. Auditor

The Auditor role in Prisma Cloud is specifically designed for users who need read-only access to security findings, reports, and dashboards without the ability to make any changes to security configurations or deployments. This perfectly matches the developers' requirement to view findings but not modify policies or deploy Defenders.

Why the other options are wrong

  • A. Operator has permissions to manage deployments and some policies, which exceeds the 'view only' requirement.
  • B. Developer is not a standard built-in role in Prisma Cloud; custom roles would be needed for specific development tasks.
  • C. Administrator has full read/write access, which is too permissive.

Prisma Cloud Auditor Role

A built-in Prisma Cloud role providing read-only access to security findings, reports, and dashboards.

  • Cannot modify policies, deploy Defenders, or change configurations.
  • Ideal for compliance officers, security analysts, or developers needing visibility.
  • Ensures segregation of duties for security management.

Memory trick: Roles: Who can do what in the cloud castle.

More Cloud Workload Protection Platform (CWPP) questions