CloudSec-Pro IAM And Access Governance IN Cloud Practice Question
Which TWO actions are necessary to ensure that Prisma Cloud can effectively govern IAM in a new AWS account?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role in the AWS account for Prisma Cloud
Onboarding requires creating a cross-account role and granting it the necessary read-only permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a local IAM user with full access
Why it's wrong here
Cross-account roles are preferred over local IAM users.
- ✗
Enable VPC Flow Logs for the account
Why it's wrong here
Flow logs are for network monitoring, not IAM governance.
- ✓
Create an IAM role in the AWS account for Prisma Cloud
Why this is correct
This role allows Prisma Cloud to access the account metadata.
- ✗
Disable Multi-Factor Authentication for the account root
Why it's wrong here
MFA should never be disabled.
- ✓
Attach the required read-only policy to the role
Why this is correct
The role must have permissions to read IAM configuration.
About these practice questions
Courseiva writes every CloudSec-Pro question from scratch — 203 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This CloudSec-Pro practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CloudSec-Pro exam.