Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A large e-commerce company uses Prisma Cloud CIEM to manage identity permissions across its multi-cloud environment. They've identified a significant number of inactive IAM users and roles that pose a potential security risk if compromised. The security team wants to implement a process to automatically identify and disable or remove these inactive identities after a defined period (e.g., 60 days of no activity). Which CIEM capability is essential for establishing this automated lifecycle management for identities?
- AIdentity Discovery
- BInactive Identity Remediation
- CIdentity Graph Analysis
- DContext-aware Access Control
Show answer & explanationAnswer & explanation
Correct answer: B. Inactive Identity Remediation
Inactive Identity Remediation is a specific CIEM capability designed to identify identities that have not been active for a predefined period and to automatically or semi-automatically take actions such as disabling or removing them, thereby reducing the attack surface.
Why the other options are wrong
- A. Identity Discovery identifies all identities but doesn't specifically manage their lifecycle based on inactivity.
- C. Identity Graph Analysis maps relationships and potential privilege escalation paths, not inactivity-based lifecycle management.
- D. Context-aware Access Control dynamically adjusts permissions based on context, not on identity inactivity.
Inactive Identity Remediation
A CIEM capability that automates the identification and remediation (e.g., disabling, removing) of identities that have shown no activity for a predefined period, reducing the attack surface and enforcing security hygiene.
- Identifies dormant identities
- Automates deactivation/removal
- Reduces security risk from stale accounts
Memory trick: Inactive Identity Remediation sweeps away the ghost accounts that no longer serve a purpose.