CloudSec-Pro Practice Question: Prisma Cloud Configuration And Posture Management
When onboarding a new AWS account to Prisma Cloud, what is the primary role of the Cross-Account IAM Role?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To grant Prisma Cloud read-only access to environment metadata
The Cross-Account IAM role allows Prisma Cloud to securely access the customer's AWS account data via API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To bypass MFA requirements
Why it's wrong here
This is not the purpose of the role.
- ✓
To grant Prisma Cloud read-only access to environment metadata
Why this is correct
The role must have read-only permissions to collect telemetry for CSPM.
- ✗
To enable write-access for automated remediation
Why it's wrong here
While possible, the primary role is for reading, not writing.
- ✗
To install agents on EC2 instances
Why it's wrong here
CSPM does not require EC2 agents.
About these practice questions
Courseiva writes every CloudSec-Pro question from scratch — 203 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This CloudSec-Pro practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CloudSec-Pro exam.