Courseiva

Cloud-Security-Engineer · domain

Identity And Access Security

Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Identity And Access Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

58 questions20 easy20 medium18 hard

Focused practice

Practice Identity And Access Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Identity And Access Security

Identity And Access Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Identity And Access Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Identity And Access Security questions (58)

Click any question to see the full explanation, or start a practice session above.

1

What is an External ID in the context of AWS IAM cross-account role assumption, and why does Prisma Cloud require it?

Easy
2

You are configuring Prisma Cloud IAM Security to remediate an over-privileged service account in Google Cloud Platform (GCP). The Prisma Cloud recommendation engine suggests generating a custom least-privilege role. How does Prisma Cloud calculate the precise permissions needed for this suggestion?

Hard
3

When configuring Prisma Cloud Alert Rules for IAM security findings, which TWO parameters can an administrator use to filter alerts effectively? (Choose two.)

Medium
4

A cloud security engineer needs to implement the principle of least privilege for an AWS IAM role used by Prisma Cloud to discover cloud resources. Which policy type should the engineer attach to the role?

Easy
5

Which TWO actions are considered core best practices for securing cloud IAM identities and credentials? (Choose two.)

Easy
6

An organization is deploying Prisma Cloud and needs to enforce least privilege access for cloud native identities. Which Prisma Cloud feature should you use to analyze actual permissions used versus permissions granted in AWS IAM?

Easy
7

Which TWO features are provided by Prisma Cloud when monitoring cloud identities and access? (Choose two.)

Easy
8

While investigating an IAM misconfiguration via Prisma Cloud RQL, an engineer wants to find all AWS IAM users who have both console access and active access keys older than 90 days. Which RQL query structure correctly accomplishes this?

Hard
9

An auditor examining AWS IAM security findings from Prisma Cloud notices several issues with password policies. Which THREE settings are evaluated as best practices for AWS account password policies? (Choose three.)

Hard
10

When reviewing IAM security findings in Prisma Cloud, which TWO metrics or indicators are typically used to assess the risk level of an IAM role? (Choose two.)

Medium
11

When configuring Prisma Cloud to scan for IAM policies, how frequently does Prisma Cloud typically ingest cloud configuration metadata by default?

Easy
12

Which TWO steps are typically required to onboard a new AWS account into Prisma Cloud for IAM posture management and discovery? (Choose two.)

Medium
13

What is the primary purpose of applying the principle of least privilege to cloud IAM policies?

Easy
14

An engineer is investigating a Prisma Cloud finding where an IAM user has active access keys but no associated password for console access. What does this configuration typically indicate?

Medium
15

When auditing GCP IAM configurations using Prisma Cloud, which THREE findings indicate potential privilege escalation or high security risks? (Choose three.)

Hard
16

An Azure subscription integrated with Prisma Cloud has a custom RBAC role assigned to multiple identities. The custom role was recently modified to include 'Microsoft.Authorization/*/write'. How does Prisma Cloud evaluate and report this change?

Hard
17

What is the primary function of an AWS IAM service-linked role?

Easy
18

An auditor asks an engineer to demonstrate how Prisma Cloud verifies that IAM policies adhere to compliance standards like CIS Benchmarks. Which Prisma Cloud component links policies to CIS requirements?

Medium
19

Which Prisma Cloud dashboard view provides a consolidated summary of identity risks, including inactive users, overly permissive roles, and missing MFA?

Easy
20

An enterprise is hardening its AWS IAM environment. Which THREE policy conditions or elements can help restrict role assumption security risks when configured correctly? (Choose three.)

Hard
21

You are hardening an Azure environment monitored by Prisma Cloud. An alert fires indicating that an Azure Service Principal possesses the 'Owner' role at the subscription level, but it is only used for read-only monitoring tasks. What is the recommended remediation step using least privilege principles?

Medium
22

An engineer needs to ensure that Prisma Cloud can monitor GCP IAM policies across multiple projects in an entire folder hierarchy. At which level in GCP should the Prisma Cloud service account be granted permissions?

Medium
23

An engineer wants to ensure that all human users in AWS access the AWS Management Console using single sign-on (SSO) with an identity provider rather than native IAM user passwords. Which Prisma Cloud policy check evaluates this best practice?

Medium
24

An auditor asks you to identify all external identities (such as cross-account AWS roles or external Azure tenants) that have access to your cloud environment. Which Prisma Cloud console section should you access to investigate this?

Easy
25

A security engineer discovers that an AWS IAM role has a trusted relationship allowing any account within the same organization to assume it without external ID verification. What is the primary security risk of this configuration?

Medium
26

An engineer is reviewing GCP IAM policies in Prisma Cloud. A finding flags a service account with the 'roles/iam.serviceAccountKeyAdmin' role. What specific risk does this role introduce?

Medium
27

Which TWO cloud provider identity constructs are regularly monitored by Prisma Cloud Identity and Access Security? (Choose two.)

Easy
28

When integrating AWS accounts with Prisma Cloud for IAM Security and Cloud Entitlement Management, which IAM deployment method is typically recommended to grant Prisma Cloud secure, least-privilege read and remediation access?

Easy
29

While reviewing Prisma Cloud Identity and Access Security findings, an engineer notices an IAM user with persistent access keys that have not been used in 180 days. Which Prisma Cloud feature identifies this risk?

Medium
30

Which Azure feature corresponds to AWS IAM roles and is used by Prisma Cloud to perform agentless scanning and posture management?

Easy
31

Which Prisma Cloud feature allows security teams to create custom alerts based on specific cloud configuration criteria, such as an IAM role missing a description or having untrusted trust relationships?

Easy
32

An enterprise uses Prisma Cloud Identity and Access Security to detect overly permissive policies. A policy grants 'iam:*' on 'arn:aws:iam::*:role/Developer-*'. What finding severity does Prisma Cloud typically assign to this policy pattern?

Hard
33

Which tool or feature in Prisma Cloud Code Security can scan Terraform files for IAM misconfigurations before they are deployed to the cloud?

Easy
34

An enterprise wishes to enforce that all GCP service accounts created within their organization do not possess primitive roles (Owner, Editor, Viewer). Where can an engineer set this up in GCP to prevent these roles from being assigned?

Medium
35

An enterprise wants to ensure that Prisma Cloud alert notifications regarding high-risk IAM policy changes are sent immediately to their security operations channel in Slack. Which Prisma Cloud feature should be configured?

Medium
36

Prisma Cloud detects an AWS IAM policy that allows the 'iam:PassRole' action combined with 'ec2:RunInstances' without resource constraints. Why is this combination flagged as a critical risk?

Hard
37

Prisma Cloud flags an AWS IAM role because its trust policy contains a condition with 'aws:SourceIp' allowing access from any IP address when combined with another weak condition. Why can 'aws:SourceIp' in trust policies sometimes be misleading or risky?

Hard
38

An enterprise utilizes AWS Organizations and wants to ensure that no member account can remove or modify the Prisma Cloud IAM role created for cross-account access. Which mechanism should be deployed in the management account?

Hard
39

While reviewing Prisma Cloud Identity-First Security findings, you notice an AWS IAM role flagged for having a toxic combination of permissions. The role can read sensitive S3 buckets and also modify trust policies. What is the primary risk identified by Prisma Cloud?

Medium
40

Which TWO methods are standard ways to query IAM configuration data within Prisma Cloud? (Choose two.)

Easy
41

Which TWO of the following capabilities are provided by Prisma Cloud Cloud Entitlement Management (CEM) when securing cloud identities? (Choose two)

Medium
42

While reviewing IAM permissions in GCP, Prisma Cloud detects a user who has been granted 'roles/owner' at the organization level. Why is this considered an extreme risk according to Cloud Security best practices?

Hard
43

Which of the following is considered a best practice for managing cloud root account credentials?

Easy
44

An organization's security policy states that no IAM policy should grant permissions to '*' resource combined with administrative actions. Prisma Cloud detects a violation where an inline policy grants 's3:*' on resource '*'. How should the security engineer remediate this finding?

Hard
45

Your security team wants to write a custom RQL (Resource Query Language) query in Prisma Cloud to detect any AWS IAM users who have not used their access keys in the last 90 days but remain active. Which RQL syntax construct should you use?

Hard
46

When securing cloud identities and managing risky IAM roles across multi-cloud environments using Prisma Cloud, which THREE practices should be implemented to mitigate identity-based attack vectors? (Choose three)

Hard
47

An administrator needs to review alerts generated by Prisma Cloud regarding anomalous IAM behavior, such as an identity accessing services from an unusual geographic location. Which Prisma Cloud feature provides this capability?

Medium
48

An organization uses AWS IAM Identity Center (formerly AWS SSO). Prisma Cloud scans the environment and reports an identity risk related to permission sets. What does an overly permissive permission set typically represent in this context?

Hard
49

When setting up integration between Prisma Cloud and AWS, which Terraform resource type is commonly used to create the secure cross-account IAM role?

Easy
50

When managing cross-account access for Prisma Cloud in AWS, which TWO IAM policy components are essential for the role trust policy? (Choose two.)

Medium
51

An enterprise is using Prisma Cloud to detect risky identities in AWS and Azure. Which TWO indicators are commonly flagged by Prisma Cloud as high-risk identity findings? (Choose two)

Medium
52

What is the primary benefit of disabling unused IAM access keys identified by Prisma Cloud?

Easy
53

An enterprise is reviewing AWS IAM policies flagged by Prisma Cloud for allowing 'iam:PutUserPolicy' or 'iam:AttachUserPolicy'. Why are these specific permissions frequently flagged as critical privilege escalation vectors? (Choose three.)

Hard
54

An organization uses Prisma Cloud to monitor AWS IAM trust policies. A finding triggers indicating that an external AWS account ID unknown to the enterprise is trusted by an internal role. What remediation action should the engineer take in Prisma Cloud or the cloud console?

Hard
55

An organization wants to restrict Prisma Cloud Compute access so that developers can only view vulnerabilities for repositories they own. Where in the Prisma Cloud Compute console should an administrator configure this access control?

Hard
56

Which TWO methods can an engineer use to remediate an overly permissive IAM policy flagged by Prisma Cloud? (Choose two.)

Medium
57

An engineer is configuring a custom RQL query in Prisma Cloud to find AWS IAM policies that allow wildcard actions on sensitive services. Which RQL object should the query start with?

Medium
58

Which TWO cloud services or platforms can be integrated with Prisma Cloud Identity and Access Security for posture management? (Choose two.)

Easy

Frequently asked questions

What does the Identity And Access Security domain cover on the Cloud-Security-Engineer exam?
Identity And Access Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 58 Identity And Access Security questions in the Cloud-Security-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Identity And Access Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cloudsec-engineer PANW-CLOUDSEC-ENGINEER identity and access security Practice Questions