Cloud-Security-Engineer Identity And Access Security Practice Question
When setting up integration between Prisma Cloud and AWS, which Terraform resource type is commonly used to create the secure cross-account IAM role?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws_iam_role
AWS IAM roles and role policies are provisioned using aws_iam_role and aws_iam_policy Terraform resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws_instance
Why it's wrong here
This resource provisions EC2 virtual machine instances.
- ✗
aws_s3_bucket
Why it's wrong here
This resource provisions Amazon S3 object storage buckets.
- ✓
aws_iam_role
Why this is correct
This resource creates the IAM role assumed by Prisma Cloud for cross-account API polling.
- ✗
aws_security_group
Why it's wrong here
This resource provisions virtual firewall rules for network traffic.
About these practice questions
This Cloud-Security-Engineer question is part of Courseiva's 216-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.