Courseiva
Prisma Cloud Architecture And ComponentshardMultiple SelectObjective-mapped

Cloud-Security-Engineer Prisma Cloud Architecture And Components Practice Question

Which THREE best practices should be followed when administering Prisma Cloud API Access Keys?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assigning the principle of least privilege by scoping keys to specific roles and account groups

API Access Key administration best practices include setting expiration dates, applying least-privilege roles, and rotating keys regularly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assigning the principle of least privilege by scoping keys to specific roles and account groups

    Why this is correct

    Keys should only have permissions required for their specific automated integration purpose.

  • Hardcoding master API keys directly into public GitHub repositories for CI/CD automation

    Why it's wrong here

    Hardcoding keys in public repositories is a severe security risk.

  • Storing keys securely in enterprise secret managers rather than plain-text configuration files

    Why this is correct

    Secret managers protect API keys from exposure.

  • Setting appropriate key expiration dates and implementing regular rotation policies

    Why this is correct

    Keys should expire and rotate periodically to minimize credential compromise risks.

  • Sharing a single master System Admin API key among all development teams

    Why it's wrong here

    Sharing master keys violates auditability and least-privilege principles.

About these practice questions

This Cloud-Security-Engineer question is part of Courseiva's 216-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.