Courseiva
Identity And Access SecuritymediumMultiple SelectObjective-mapped

Cloud-Security-Engineer Identity And Access Security Practice Question

An enterprise is using Prisma Cloud to detect risky identities in AWS and Azure. Which TWO indicators are commonly flagged by Prisma Cloud as high-risk identity findings? (Choose two)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IAM users with active access keys that have not been used for over 90 days.

Prisma Cloud flags accounts with unused credentials that remain enabled and accounts with administrative privileges lacking MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enabling AWS CloudTrail integration in all active operational regions.

    Why it's wrong here

    Enabling CloudTrail is a security best practice, not a risk finding.

  • IAM users with active access keys that have not been used for over 90 days.

    Why this is correct

    Dormant credentials with long-term validity represent an unnecessary risk surface.

  • Using standard lowercase naming conventions for custom IAM roles.

    Why it's wrong here

    Naming conventions do not constitute a security risk.

  • Tagging cloud resources with owner email addresses for billing attribution.

    Why it's wrong here

    Resource tagging for governance and billing is a best practice and poses no security risk.

  • Human users with administrative privileges who do not have Multi-Factor Authentication (MFA) enabled.

    Why this is correct

    Admin accounts without MFA are highly vulnerable to credential stuffing and phishing attacks.

About these practice questions

One of 216 original Cloud-Security-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.