Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard
A security engineer has identified a critical misconfiguration in a Google Cloud Platform (GCP) project where a BigQuery dataset is publicly accessible. They need to use Prisma Cloud's automated remediation to revoke public access to this dataset. Which of the following is a prerequisite for Prisma Cloud to successfully remediate this issue?
- AThe Prisma Cloud service principal for GCP must have the 'BigQuery Admin' role.
- BThe Prisma Cloud service principal for GCP must have the 'BigQuery Data Editor' role.
- CThe BigQuery dataset must have a 'Default Table Expiration' set to at least 30 days.
- DThe BigQuery dataset must be tagged with 'remediable:true'.
Show answer & explanationAnswer & explanation
Correct answer: A. The Prisma Cloud service principal for GCP must have the 'BigQuery Admin' role.
Automated remediation in Prisma Cloud requires specific permissions for the service principal or role used for onboarding. To modify BigQuery dataset permissions, the service principal needs a role with sufficient privileges, such as 'BigQuery Admin', which allows management of datasets and their access controls. 'BigQuery Data Editor' typically only allows data manipulation, not permission changes.
Why the other options are wrong
- B. The 'BigQuery Data Editor' role primarily allows editing data within tables, not managing dataset permissions, which is required for revoking public access.
- C. The 'Default Table Expiration' setting is unrelated to the permissions required for Prisma Cloud to remediate public access on a BigQuery dataset.
- D. Prisma Cloud does not require resources to be tagged with 'remediable:true' for automated remediation; this is not a standard prerequisite.
Automated Remediation Prerequisites (GCP BigQuery)
For Prisma Cloud to perform automated remediation on GCP BigQuery datasets, the associated service principal must possess the necessary IAM roles to modify dataset access controls.
- Requires specific GCP IAM roles.
- Role must allow modification of BigQuery dataset permissions.
- Example role: 'BigQuery Admin' or a custom role with equivalent permissions.
Memory trick: Remediation needs the right keys to fix the locks.