Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Easy

A security auditor is reviewing a Prisma Cloud CIEM implementation and observes that several AWS IAM roles have permissions that have not been exercised in the past 90 days. The auditor recommends a strategy to reduce this unused access without disrupting legitimate operations. Which Prisma Cloud CIEM capability is best suited to address this recommendation?

  1. APolicy Creation
  2. BIdentity-based Microsegmentation
  3. CUsage-based Rightsizing
  4. DAnomaly Detection
Show answer & explanation

Correct answer: C. Usage-based Rightsizing

Usage-based rightsizing in CIEM solutions like Prisma Cloud analyzes actual identity usage to recommend and implement permissions that align with observed activity, thereby removing unused or excessive permissions without impacting necessary operations.

Why the other options are wrong

  • A. Policy Creation is a broad term; while policies are involved, the specific capability for rightsizing based on usage is more precise.
  • B. Identity-based Microsegmentation focuses on restricting network access based on identity, not on optimizing IAM role permissions.
  • D. Anomaly Detection focuses on identifying unusual or suspicious activities, not on proactively reducing unexercised permissions.

Usage-based Rightsizing (CIEM)

A CIEM capability that analyzes actual identity usage patterns to recommend and enforce permissions that align with observed activity, reducing excessive or unused access.

  • Reduces unused or excessive permissions
  • Based on actual identity activity/usage
  • Helps enforce least privilege without disruption

Memory trick: Rightsize your permissions, right-wing a bird to fly with only what it needs.

More Cloud Infrastructure Entitlement Management (CIEM) questions