Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium

A cloud security engineer needs to identify all identities within their AWS accounts that have permissions to create or modify IAM policies, regardless of whether those permissions are directly assigned or inherited through groups/roles. Which Prisma Cloud CIEM feature provides the most comprehensive view for this specific requirement?

  1. AAnomaly Detection
  2. BIAM Visibility Dashboard
  3. CIdentity Exposure Analysis
  4. DPolicy Creation Workflow
Show answer & explanation

Correct answer: C. Identity Exposure Analysis

Identity Exposure Analysis in Prisma Cloud CIEM specifically focuses on identifying and analyzing the effective permissions of all identities, including those inherited or indirect, to pinpoint potential privilege escalation paths or over-privileged accounts. This goes beyond a general visibility dashboard by actively analyzing risk.

Why the other options are wrong

  • A. Anomaly Detection identifies unusual behavior, not the static analysis of who *can* perform an action.
  • B. IAM Visibility Dashboard provides an overview but may not deeply analyze inherited or effective permissions for specific high-risk actions.
  • D. Policy Creation Workflow is for defining new policies, not for analyzing existing identity permissions.

Identity Exposure Analysis

A CIEM capability that comprehensively analyzes the effective permissions of all identities (human and machine), considering direct, inherited, and conditional access, to identify potential risks like excessive privileges or privilege escalation paths.

  • Analyzes effective permissions (direct + inherited)
  • Identifies potential privilege escalation
  • Highlights over-privileged identities

Memory trick: Exposure Analysis shines a spotlight on every hidden path to power.

More Cloud Infrastructure Entitlement Management (CIEM) questions