Cloud-Security-Engineer Identity And Access Security Practice Question
An enterprise is using Prisma Cloud to detect risky identities in AWS and Azure. Which TWO indicators are commonly flagged by Prisma Cloud as high-risk identity findings? (Choose two)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM users with active access keys that have not been used for over 90 days.
Prisma Cloud flags accounts with unused credentials that remain enabled and accounts with administrative privileges lacking MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enabling AWS CloudTrail integration in all active operational regions.
Why it's wrong here
Enabling CloudTrail is a security best practice, not a risk finding.
- ✓
IAM users with active access keys that have not been used for over 90 days.
Why this is correct
Dormant credentials with long-term validity represent an unnecessary risk surface.
- ✗
Using standard lowercase naming conventions for custom IAM roles.
Why it's wrong here
Naming conventions do not constitute a security risk.
- ✗
Tagging cloud resources with owner email addresses for billing attribution.
Why it's wrong here
Resource tagging for governance and billing is a best practice and poses no security risk.
- ✓
Human users with administrative privileges who do not have Multi-Factor Authentication (MFA) enabled.
Why this is correct
Admin accounts without MFA are highly vulnerable to credential stuffing and phishing attacks.
About these practice questions
One of 216 original Cloud-Security-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.