Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Hard
A global organization is leveraging Prisma Cloud CIEM to manage identity permissions across its diverse cloud footprint, including AWS, Azure, and GCP. To maintain consistency, ensure auditability, and enable version control for their security policies, they require that all identity-related policies are defined, stored, and managed as code within a Git repository. Which CIEM approach is this organization adopting?
- AIdentity Discovery
- BAutomated Remediation
- CPolicy-as-Code (PaC)
- DAnomaly Detection
Show answer & explanationAnswer & explanation
Correct answer: C. Policy-as-Code (PaC)
Policy-as-Code (PaC) is the practice of defining and managing security policies, including identity-related ones, in a machine-readable format within a version control system like Git. This enables consistency, automation, testing, and auditability, aligning perfectly with the organization's requirements.
Why the other options are wrong
- A. Identity Discovery is about identifying identities, not managing policies as code.
- B. Automated Remediation is about taking action on policy violations, not defining policies as code.
- D. Anomaly Detection focuses on identifying unusual behavior, not the method of policy definition and storage.
Policy-as-Code (PaC) in CIEM
The practice of defining, storing, and managing cloud identity and access management (IAM) policies as machine-readable code within a version control system (e.g., Git), enabling automation, consistency, auditability, and collaborative policy development.
- Policies defined as code (e.g., JSON, YAML)
- Stored in version control (Git)
- Enables automation, consistency, auditability
Memory trick: Policy-as-Code is like writing the rulebook for your cloud in a programming language, keeping it in a digital library.