CloudSec-Pro · domain
IAM And Access Governance IN Cloud
Practise Certified Cloud Security Professional (CloudSec-Pro) IAM And Access Governance IN Cloud practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice IAM And Access Governance IN Cloud questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about IAM And Access Governance IN Cloud
Watch out for
Common IAM And Access Governance IN Cloud exam traps
Question index
All IAM And Access Governance IN Cloud questions (33)
Click any question to see the full explanation, or start a practice session above.
Where in the Prisma Cloud console can you view the overall IAM security posture of your cloud accounts?
Easy2You have integrated Prisma Cloud with Azure AD. If a user is deleted from Azure AD, what happens to their Prisma Cloud console access?
Hard3When conducting an IAM audit, which THREE data sources does Prisma Cloud leverage?
Hard4A security administrator needs to ensure that Prisma Cloud only uses specific Identity Providers for SSO. Where should they configure this integration?
Easy5Which THREE actions can be taken when an IAM alert is generated in Prisma Cloud?
Medium6Which THREE features are part of the Prisma Cloud 'Access Governance' capabilities?
Hard7What is the purpose of 'Access Groups' in Prisma Cloud?
Easy8Which Prisma Cloud feature allows you to map cloud identities to real-world entities for compliance auditing?
Easy9If a user needs to see all alerts related to IAM, what is the most efficient way to view them?
Medium10You need to detect over-privileged IAM users in GCP. Which Prisma Cloud policy type should be utilized?
Hard11Which TWO statements describe the benefits of using Prisma Cloud for IAM governance?
Easy12If you want to view all IAM users who have performed sensitive actions, which filter should you use in Prisma Cloud?
Medium13Which THREE types of IAM risks can Prisma Cloud automatically detect?
Hard14An administrator needs to automatically remediate an IAM policy that allows '*' access to S3 buckets. How is this achieved in Prisma Cloud?
Medium15Which TWO actions are necessary to ensure that Prisma Cloud can effectively govern IAM in a new AWS account?
Medium16You are troubleshooting why an IAM policy isn't triggering an alert. What is the first thing you should check?
Medium17When managing access governance, which TWO methods can be used to restrict console access in Prisma Cloud?
Medium18Which of the following is the standard method to onboard an AWS account into Prisma Cloud for IAM monitoring?
Easy19What does the 'IAM' dashboard in Prisma Cloud typically show?
Easy20When assessing the impact of a compromised IAM user, which THREE Prisma Cloud metrics are most valuable?
Hard21What is the impact of assigning a 'Limited' role in Prisma Cloud compared to an 'Admin' role?
Medium22In Prisma Cloud, what is the significance of the 'Compute' role in the context of IAM?
Hard23What is the primary role of the 'System Admin' in Prisma Cloud?
Easy24When auditing IAM, you notice a user with 'AdministratorAccess' in AWS who only uses S3. Which Prisma Cloud feature identifies this discrepancy?
Medium25When setting up cross-account roles for Prisma Cloud to monitor an AWS account, what is the 'External ID' used for?
Medium26Which TWO items are required to create a new user in the Prisma Cloud console?
Easy27How can you verify if an IAM policy is currently being enforced in Prisma Cloud?
Hard28You need to ensure that no IAM user has permanent access keys older than 90 days. How do you construct this policy in Prisma Cloud?
Hard29How do you ensure that IAM policy changes in your cloud provider are tracked by Prisma Cloud?
Hard30Which of the following is a recommended best practice for IAM in cloud environments?
Easy31You are configuring Prisma Cloud to perform least-privilege analysis. Which feature should be enabled to identify unused IAM permissions in AWS accounts?
Medium32An administrator needs to restrict a user to read-only access for a specific resource group in Azure while using Prisma Cloud. What is the best approach?
Hard33Which TWO settings can be managed within the Prisma Cloud 'Access Control' menu?
MediumOther domains
All CloudSec-Pro exam domains
Frequently asked questions
- What does the IAM And Access Governance IN Cloud domain cover on the CloudSec-Pro exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 33 IAM And Access Governance IN Cloud questions in the CloudSec-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only IAM And Access Governance IN Cloud questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.