Courseiva
Identity And Access SecurityhardMultiple SelectObjective-mapped

Cloud-Security-Engineer Identity And Access Security Practice Question

When auditing GCP IAM configurations using Prisma Cloud, which THREE findings indicate potential privilege escalation or high security risks? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Identities with 'roles/iam.securityAdmin' enabling broad permission grants

Dangerous GCP roles include service account key administration, project ownership, and binding arbitrary service accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identities with 'roles/iam.securityAdmin' enabling broad permission grants

    Why this is correct

    Security admins can modify IAM policies across scopes, leading to privilege escalation.

  • Enabling VPC Flow Logs on custom subnets

    Why it's wrong here

    VPC Flow Logs enhance network visibility and security monitoring.

  • Service accounts possessing 'roles/iam.serviceAccountKeyAdmin'

    Why this is correct

    Key administrators can generate keys for any service account, enabling persistence and privilege escalation.

  • Users holding 'roles/owner' at the project or organization level

    Why this is correct

    Project or organization owners have full administrative privileges.

  • Buckets configured with uniform bucket-level access enabled

    Why it's wrong here

    Uniform bucket-level access is a security best practice, not a risk finding.

About these practice questions

One of 216 original Cloud-Security-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.