Which step should a SecOps engineer implement in order to create a network exposure policy that identifies instances accessible from any untrusted internet sources?
Reveal answer details Close answer details
Correct answerD
Palo Alto Networks · PAN-CSP
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which step should a SecOps engineer implement in order to create a network exposure policy that identifies instances accessible from any untrusted internet sources? Reveal answer details Close answer detailsCorrect answerD
Single choice
An administrator of Prisma Cloud wants to enable role-based access control for Docker engine. Which configuration step is needed first to accomplish this task? Reveal answer details Close answer detailsCorrect answerB Explanation https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/access_control/rbac
Single choice
A customer wants to prevent public exposure of their S3 buckets in AWS. Which Prisma Cloud feature should they use? Reveal answer details Close answer detailsCorrect answerC Explanation Explanation: Configuration policies can detect and remediate publicly accessible AWS S3 buckets.
Multiple choice
In which two ways can Prisma Cloud images be retrieved in Prisma Cloud Compute Self-Hosted Edition? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, C Explanation In Prisma Cloud Compute Self-Hosted Edition, images can be retrieved by first authenticating with the Prisma Cloud registry and then pulling the images from the Prisma Cloud registry. This process ensures secure access to Prisma Cloud images, as authentication is required to access the registry. By using authentication, Prisma Cloud ensures that only authorized users can retrieve and deploy Prisma Cloud images, maintaining the security and integrity of the deployment.
Single choice
An organization wants to be notified immediately to any `High Severity` alerts for the account group Which option shows the steps the organization can use to achieve this goal? Reveal answer details Close answer detailsCorrect answerA Explanation To achieve immediate notification for "High Severity" alerts for a specific account group via Slack, the steps outlined in option A provide a comprehensive and effective approach. Firstly, configuring the Slack Integration establishes the necessary communication channel between Prisma Cloud and the Slack workspace. Creating an alert rule with the specified account group and severity filters ensures that only relevant alerts trigger notifications. Selecting Slack as the notification channel and setting the frequency to "As it Happens" ensures real-time alerting for critical issues. This method leverages Prisma Cloud's alerting capabilities and Slack's real-time messaging platform to promptly notify the security team, enabling swift action to mitigate risks. This approach is in line with Prisma Cloud's flexible and configurable alerting system, designed to integrate with various external platforms for efficient incident response.
Multiple choice
Which two of the following are required to be entered on the IdP side when setting up SSO in Prisma Cloud? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, D
Single choice
Creation of a new custom compliance standard that is based on other individual custom compliance standards needs to be automated. Assuming the necessary data from other standards has been collected, which API order should be used for this new compliance standard? Reveal answer details Close answer detailsCorrect answerB Explanation https://api.prismacloud.io/compliance https://api.prismacloud.io/compliance/complianceld/requirement https://api.prismacloud.io/compliance/requirementld/section https://pan.dev/prisma-cloud/api/cspm/get-all-standards/
Single choice
A security team needs real-time notifications when Prisma Cloud detects high-severity alerts. How can they achieve this? Reveal answer details Close answer detailsCorrect answerA Explanation Explanation: Alert rules in Prisma Cloud allow Slack notifications for real-time threat alerts.
Single choice
Which intensity setting for anomaly alerts is used for the measurement of 100 events over 30 days? Reveal answer details Close answer detailsCorrect answerB Explanation In the context of setting anomaly alert intensities in Prisma Cloud, an intensity setting of "Medium" could be used for the measurement of 100 events over 30 days. This setting indicates a moderate level of anomaly detection sensitivity, which is suitable for environments where there is a need to balance between detecting potential security issues and minimizing false positives.
Multiple choice
Which three platforms support the twistcli tool? (Choose three.) Reveal answer details Close answer detailsCorrect answersC, D, E Explanation Prisma Cloud ships a command-line configuration and control tool known as twistcli. It is supported on Linux, macOS, and Windows. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/tools/twistcli
Single choice
A customer has multiple violations in the environment including: 1. User namespace is enabled Which section of Console should the administrator use to review these findings? Reveal answer details Close answer detailsCorrect answerA
Single choice
An organization wants to restrict outbound internet access from containers. Which feature can help achieve this? Reveal answer details Close answer detailsCorrect answerA Explanation Explanation: Network segmentation policies help restrict outbound access and prevent data exfiltration.
Multiple choice
A customer wants to harden its environment from misconfiguration. Prisma Cloud Compute Compliance enforcement for hosts covers which three options? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, B, D Explanation Prisma Cloud Compute Compliance enforcement for hosts covers several aspects to ensure a secure and compliant host environment, particularly within containerized environments. These include: Docker daemon configuration files: Ensuring that Docker daemon configuration files are set up according to best security practices is crucial. These files contain various settings that control the behavior of the Docker daemon, and misconfigurations can lead to security vulnerabilities. Docker daemon configuration: Beyond just the configuration files, the overall configuration of the Docker daemon itself is critical. This encompasses runtime settings and command-line options that determine how Docker containers are executed and managed on the host.
Multiple choice
A security team has a requirement to ensure the environment is scanned for vulnerabilities. What are three options for configuring vulnerability policies? (Choose three.) Reveal answer details Close answer detailsCorrect answersB, C, D Explanation References:
Drag & drop
DRAG DROP What is the order of steps to create a custom network policy? (Drag the steps into the correct order of occurrence, from the first step to the last.) ![]() Reveal answer details Close answer details![]() Explanation References:
Single choice
Which port should a security team use to pull data from Console's API? Reveal answer details Close answer detailsCorrect answerD
Drag & drop
DRAG DROP An administrator needs to write a script that automatically deactivates access keys that have not been used for 30 days. In which order should the API calls be used to accomplish this task? (Drag the steps into the correct order from the first step to the last.) ![]() Reveal answer details Close answer details![]()
Single choice
How many CLI remediation commands can be added in a custom policy sequence? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which policy type in Prisma Cloud can protect against malware? Reveal answer details Close answer detailsCorrect answerA Explanation The Data policy type in Prisma Cloud is designed to protect against malware by scanning data and files for malicious content. This policy type helps in identifying and mitigating malware threats in the cloud environment.
Multiple choice
A customer is reviewing Container audits, and an audit has identified a cryptominer attack. Which three options could have generated this audit? (Choose three.) Reveal answer details Close answer detailsCorrect answersB, C, E
Single choice
In Azure, what permissions need to be added to Management Groups to allow Prisma Cloud to calculate net effective permissions? Reveal answer details Close answer detailsCorrect answerB Explanation In Azure, to enable Prisma Cloud to calculate net effective permissions across Management Groups, the necessary permission is "Microsoft.Management/managementGroups/descendants/read." This permission grants Prisma Cloud the ability to read the management group hierarchy and the related details, allowing for a comprehensive analysis of the effective permissions applied across different levels of the management group structure. By having this level of access, Prisma Cloud can accurately assess and report on the permissions assigned to various resources and identities within the Azure environment, facilitating better security and compliance management.
Single choice
A user from an organization is unable to log in to Prisma Cloud Console after having logged in the previous day. Which area on the Console will provide input on this issue? Reveal answer details Close answer detailsCorrect answerB Explanation In the event a user is unable to log in to the Prisma Cloud Console, Audit Logs serve as a critical area for investigating the issue. Audit Logs provide a detailed record of activities, including login attempts, within the Prisma Cloud environment. By examining the Audit Logs, administrators can identify failed login attempts, understand the reasons behind login failures (e.g., incorrect credentials, account lockouts, or access policy changes), and take appropriate actions to resolve the login issues, ensuring users can access the console as expected.
Single choice
What is the primary purpose of Cloud Native Application Firewall (CNAF) in Prisma Cloud? Reveal answer details Close answer detailsCorrect answerB Explanation Explanation: CNAF helps protect containerized web applications from attacks such as SQL Injection (SQLi) and Cross-Site Scripting (XSS).
Multiple choice
Which two variables must be modified to achieve automatic remediation for identity and access management (IAM) alerts in the Amazon Web Services (AWS) Cloud? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Multiple choice
Which two options may be used to upgrade the Defenders with a Console v20.04 and Kubernetes deployment? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B
Single choice
Which feature belongs to Application Security? Reveal answer details Close answer detailsCorrect answerB Explanation The correct answer is B because the blueprint identifies secrets scanning as an Application Security capability. CDR is a Cloud Runtime Security concept, while unified compliance management and identity security are listed under Cloud Posture Security, so A, C, and D are incorrect.
Single choice
How does assigning an account group to an administrative user on Prisma Cloud help restrict access to resources? Reveal answer details Close answer detailsCorrect answerC Explanation In Prisma Cloud, assigning an administrative user to an account group is a way to implement the principle of least privilege by restricting the user's access to a specific subset of resources and data. Account groups are logical collections of cloud accounts, and by associating an administrative user with a particular account group, their access is limited to only those resources and data associated with the cloud accounts within that group. This mechanism ensures that users have access only to the information and resources necessary for their role or tasks, enhancing security by minimizing the potential for unauthorized access or actions within the cloud environment.
Single choice
Which of the following is not a supported external integration for receiving Prisma Cloud Code Security notifications? Reveal answer details Close answer detailsCorrect answerC
Single choice
An administrator wants to install the Defenders to a Kubernetes cluster. This cluster is running the console on the default service endpoint and will be exporting to YAML. Console Address: $CONSOLE_ADDRESS Which command generates the YAML file for Defender install? Reveal answer details Close answer detailsCorrect answerD Explanation The correct command to generate the YAML file for Defender install in a Kubernetes cluster, considering the console and websocket addresses, as well as the admin user, would typically involve specifying the addresses and user details. The option D seems most aligned with standard practices for such commands, where you export the Defender configuration for Kubernetes, specifying the console and websocket addresses along with the user details.
Single choice
The Compute Console has recently been upgraded, and the administrator plans to delay upgrading the Defenders and the Twistcli tool until some of the team's resources have been rescaled. The Console is What will happen as a result of the Console upgrade? Reveal answer details Close answer detailsCorrect answerC Explanation When the Compute Console in Prisma Cloud is upgraded to a newer major release, while the Defenders and the Twistcli tool remain on the older version, the system is designed to ensure backward compatibility to a certain extent. As a result, both Defenders and Twistcli will continue to operate despite the version discrepancy. The Defenders will remain connected, continuing their monitoring and protection duties, and the Twistcli tool will keep functioning, allowing for continued scanning and other CLI-based operations.
Single choice
The exclamation mark on the resource explorer page would represent? Reveal answer details Close answer detailsCorrect answerC Explanation https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/investigate-incidents-on-prisma-cloud/investigate-config-incidents-on-prisma-cloud
Single choice
The administrator wants to review the Console audit logs from within the Console. Which page in the Console should the administrator use to review this data, if it can be reviewed at all? Reveal answer details Close answer detailsCorrect answerD Explanation References:
Single choice
Given the following RQL: event from cloud.audit_logs where operation IN (`CreateCryptoKey', `DestroyCryptoKeyVersion', compute.disks.createSnapshot') Which audit event snippet is identified? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which ban for DoS protection will enforce a rate limit for users who are unable to post five (5) ". Reveal answer details Close answer detailsCorrect answerC
Multiple choice
Which two statements explain differences between build and run config policies? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, D Explanation The Run policies monitor resources and check for potential issues once these cloud resources are deployed Build policies enable you to check for security misconfigurations in the IaC templates and ensure that these issues do not make their way into production. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/create-a-policy
Multiple choice
A Prisma Cloud administrator is onboarding a single GCP project to Prisma Cloud. Which two steps can be performed by the Terraform script? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, C Explanation When a Prisma Cloud administrator is onboarding a single GCP project to Prisma Cloud, the Terraform script can perform several steps to facilitate this integration. The steps include
Single choice
The Unusual protocol activity (Internal) network anomaly is generating too many alerts. An administrator has been asked to tune it to the option that will generate the least number of events without disabling it entirely. Which strategy should the administrator use to achieve this goal? Reveal answer details Close answer detailsCorrect answerB Explanation To reduce the number of alerts generated by the "Unusual protocol activity (Internal)" network anomaly without entirely disabling the policy, setting the Alert Disposition to Conservative (option B) is the most effective strategy. This configuration adjusts the sensitivity of the anomaly detection, reducing the likelihood of false positives and minimizing alert fatigue without compromising the ability to detect genuine security threats. By adopting a more conservative approach to anomaly detection, the administrator can ensure that only the most significant and potentially harmful activities trigger alerts, thus maintaining a balance between security vigilance and operational efficiency.
Single choice
Given a default deployment of Console, a customer needs to identify the alerted compliance checks that are set by default. Where should the customer navigate in Console? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
Which of the below actions would indicate - "The timestamp on the compliance dashboard"? Reveal answer details Close answer detailsCorrect answerD Explanation The timestamp on the compliance dashboard in a cloud security context typically reflects the point in time when data from various sources is collected, processed, and then consolidated to present the compliance status or results. This aggregation process involves compiling data from multiple scans, logs, and other compliance-related information to provide a comprehensive overview of the current compliance posture.
Single choice
Given the following audit event activity snippet: { Which RQL will be triggered by the audit event? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
What are the two ways to scope a CI policy for image scanning? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, D Explanation References:
Multiple choice
Which two attributes of policies can be fetched using API? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C Explanation Using the Prisma Cloud API, users can fetch various attributes of policies, including the policy label (Option A) and policy mode (Option C). The policy label helps in categorizing and organizing policies, while the
Single choice
If you are required to run in an air-gapped environment, which product should you install? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
A customer has Defenders connected to Prisma Cloud Enterprise. The Defenders are deployed as a DaemonSet in OpenShift. How should the administrator get a report of vulnerabilities on hosts? Reveal answer details Close answer detailsCorrect answerD Explanation To view the vulnerabilities identified on a host, navigating to the "Monitor > Vulnerabilities > Hosts" section within the Prisma Cloud Console is the correct approach. This section is specifically designed to provide a comprehensive overview of all detected vulnerabilities within the host environment, offering detailed insights into each vulnerability's nature, severity, and potential impact. This pathway allows users to efficiently assess the security posture of their hosts, prioritize vulnerabilities based on their severity, and take appropriate remediation actions. The "Hosts" section under "Vulnerabilities" is tailored to display vulnerabilities related to host configurations, installed software, and other host-level security concerns, making it the ideal location within the Prisma Cloud Console for this purpose. |