Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A financial institution uses Prisma Cloud CIEM to manage identities across AWS, Azure, and GCP. They have a strict compliance requirement to ensure that 'break glass' roles, used only for emergencies, are audited immediately after activation and that their permissions are revoked or reduced if no longer needed. Which Prisma Cloud CIEM capability specifically supports this post-activation auditing and remediation for emergency access?
- AContinuous Identity Posture Validation
- BRole-Based Access Control (RBAC) Enforcement
- CIdentity Discovery
- DAutomated Remediation
Show answer & explanationAnswer & explanation
Correct answer: D. Automated Remediation
Automated Remediation in Prisma Cloud CIEM can be configured to detect the activation of 'break glass' roles and trigger workflows for immediate auditing, notification, and subsequent permission revocation or reduction once the emergency is resolved, ensuring compliance and security.
Why the other options are wrong
- A. Continuous Identity Posture Validation ensures ongoing compliance but Automated Remediation is the specific capability that *acts* on the 'break glass' event.
- B. RBAC Enforcement ensures roles are assigned correctly, but Automated Remediation handles the post-event actions for 'break glass' roles.
- C. Identity Discovery identifies existing identities, not the post-activation management of emergency roles.
'Break Glass' Role Auditing (CIEM)
The process of monitoring and managing emergency access roles ('break glass') in a CIEM solution, specifically focusing on immediate auditing upon activation and automated or semi-automated remediation (e.g., permission revocation) once the emergency is over.
- For emergency, high-privilege access
- Requires immediate auditing upon activation
- Needs automated/prompt remediation post-use
Memory trick: After breaking the glass, the automated cleanup crew immediately comes to secure the scene.