Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Training Test PA-PSE

Total questions: 60

Worksheet time: 28mins

Name
Class
Date
1.

Which two cloud-native service providers are supported by Prisma Cloud? (Choose two).

a)

Oracle Cloud

b)

DigitalOcean

c)

IBM Cloud

d)

Azure

2.

Which onboarding scope or method is used to automatically onboard new AWS accounts into Prisma Cloud?

a)

AWS Account

b)

AWS Organization

c)

CronJobs

d)

Account Groups

3.

Which application security category displays secrets found in source code?

a)

SBOM

b)

Projects

c)

CI/CD Risks

d)

Technologies

4.

What is a business outcome benefit of Prisma Cloud?

a)

Autoconfiguring network policies

b)

Improving security operations productivity

c)

Increasing remediation time

d)

Eliminating customer chum

5.

In the Prisma Cloud dashboard, how can alerts related to Amazon RDS be quickly identified?

a)

Generate a CIS compliance report and search for Amazon RDS policy violations

b)

View the alert data on the "Asset Inventory" dashboard, then filter on Amazon RDS

c)

Create a custom RQL configuration report that includes Amazon RDS

d)

In the "Alerts" tab, filter on Amazon RDS as a service

6.

How are violations to public cloud infrastructure autoromedigted by Prismna Cloud Enterprise?

a)

By making changes after the violation has been identified in monitoring

b)

By stopping any configurations without prior authorization and locking all changes to public cloud infrastructure

c)

By using machine learning (ML) to identify unusual infrastructure modifications

d)

By inspecting the API call made to public cloud and blocking the change if a determination is made that there has been a policy violation

7.

Which two data sources are ingested by Prisma Cloud? (Choose two)

a)

Compute resource configuration metadata

b)

Database instance table list

c)

Strata Logging Service

d)

Network flow logs

8.

What are the five areas that help make a Prisma Cloud solutions architect a trusted advisor by developing a deep understanding of customer security needs?

a)

Understanding the customer's business, organization, cloud journey, cniticality / nature of cloud applications, and security use cases

b)

Understanding the customer's organization, budget requirements, leadership, cloud journey, and criticality / nature of cloud applications

c)

Understanding the customer's business, organization, budget requirements, leadership, and industry trends

d)

Understanding the custom's organization, criticality / nature of cloud applications, industry trends, and security use cases

9.

The Trusted Images security control feature allows declaration of how to respond to which scenario?

a)

There are trusted images started in the environment

b)

There are unsigned images in the environment

c)

There are untrusted images started in the environment

d)

There are images with malware or cryptominers in the environment

10.

Which resource is included in the Prisma Cloud Enterprise licensing count?

a)

NAT gateways

b)

Shared rules

c)

Security groups

d)

CloudFront distributions

11.

Which template is supported by Cloud Code Security scan service?

a)

Github

b)

HTML

c)

Terraform

d)

NAT

12.

Which Prisma Cloud module can identify misconfigured infrastructure-as-code that leads to insecure runtime cloud services?

a)

IaC scanning in the application security module

b)

CI pipeline scanning in the runtime module

c)

Vulnerability scanning in the runtime or Cloud Security Module

d)

Compliance scanning in the Cloud Security Module

13.

Which action allows Prisma Cloud to be enabled to proactively help developers secure code and provide proactive developer feedback regarding code issues?

a)

Setting up agentless scanning to view the results

b)

Enabling automatic learning

c)

Viewing console logs within Prisma Cloud

d)

Setting up an IDE plugin and running the first scan

14.

Which feature is exclusive to Prisma Cloud Compute Edition?

a)

Centralized policy management

b)

Integration with third-party tools

c)

Self-hosted management console

d)

Automated compliance reporting

15.

In a vulnerability management policy, what is the correlation between the block and alert thresholds?

a)

The block threshold must always be equal to or greater than the alert threshold

b)

Both thresholds can be set to informational, low, medium, high, and critical

c)

The alert threshold always has precedence over, and can be greater than, the block threshold

d)

The block threshold always has precedence over, and can be less than, the alert threshold

16.

A year has passed since an AWS Organization has been onboarded into Prisma Cloud New Prisma Cloud features have been released that require additional permissions from the cloud accounts

Which actions will ensure the necessary permissions are available across the IAM roles?

a)

Generate a new Prisma Cloud onboarding template and delete the existing stacks from the AWS Organization

b)

Trigger a Jenkins automation that will automatically upgrade all Defenders regardless of N-2 support policy

c)

Generate a new Prisma Cloud onboarding template and apply it to existing stacks in the AWS Organization

d)

Redeploy all Defenders and check for version type

17.

Which tool is used to onboard an AWS account into Prisma Cloud using the provided template?

a)

Terraform

b)

Ansible

c)

AWS CloudFormation

d)

AWS CodeCommit

18.

What are two benefits to organizations that deploy Prisma Cloud? (Choose two)

a)

On-premises infrastructure costs decrease exponentially year-over-year

b)

Security outcomes are improved by consolidating security management

c)

Adopted security practices improve efficiency for cloud security enforcement

d)

Data is automatically prepared and enriched, then uniquely stitched into security intelligence

19.

Which action is appropriate when configuring Prisma Cloud to scan a registry?

a)

Allow automatic optimization of registry scans with version pattern matching

b)

Determine the predefined version pattern-matching algorithm

c)

Explicitly specify the Defender to perform the task

d)

Block Defender image manifest generation

20.

What are two benefits of Cloud Security Posture Management (CSPM) over other solutions? (Choose two)

a)

Addressing risks proactively

b)

Native integration of network, endpoint, and cloud data to stop attacks

c)

Elimination of blind spots

d)

Guaranteed proof of concept (POC) extensions beyond 30 days

21.

Which action will block a Container running as root?

a)

Create a Vulnerability Management Policy with the Alert eftect on Containers running as root

b)

Create a Compliance Rule with the Block effect on Containers running as root

c)

Configure an Alert effect on Containers running as root

d)

Configure a Block eftect on all Containers

22.

Which use case is typical for Prisma Cloud?

a)

Using machine learning (ML) algorithms to predict and protect against HTTP-based threats

b)

Discover and quarantine malicious files within only Linux file systems

c)

Building and testing new software applications using integration testing methodology

d)

Monitoring and securing resources across multiple cloud platforms

23.

When deciding between Prisma Cloud Compute Edition and Prisma Cloud Enterprise Edition, what is a primary factor to consider?

a)

Type of cloud service provider currently in use

b)

Availability of mobile device support from the company's IT department

c)

Deployment model and location of management components

d)

Need for API security management

24.

Prevention against which type of attack is configurable in Web-Application and API Security (WAAS)?

a)

XSS

b)

DDoS

c)

Shoulder surfing

d)

Credential stuffing

25.

Why is it important to understand how a customer's cloud infrastructure team creates and deploys new cloud resources?

a)

Because Prisma Cloud provides visibility and secure cloud resources throughout the system and software development lifecycle

b)

Because Prisma Cloud requires agents to be deployed in order to secure new cloud resources

c)

Because Prisma Cloud will require the cloud infrastructure team to change their existing deployment process

d)

Because Prisma Cloud will only be able to provide visibility and security for the cloud services which have already been deployed

26.

Which use case is applicable to Prisma Cloud?

a)

Requiring continuous monitoring and analysis and creating permissions and entitlements across cloud environment

b)

Designing and prototyping Web 2 0 product designs

c)

Needing the ability to fix risk immediately in the cloud or request a permanent fix in code

d)

Identifying misconfigured AWS Cloud Templates in GCP projects

27.

What is an essential step when planning and architecting a Prisma Cloud deployment to ensure effective runtime protection?

a)

Deploying Defender agents on supported hosts

b)

Implementing log management solutions

c)

Configuring automated compliance reports

d)

Setting up API integrations with monitoring tools

28.

How can Prisma Cloud Compute edition be installed?

a)

As a self-contained hardware appliance

b)

Imported from a customer's existing CASB

c)

As a stand-alone Windows application

d)

Self-managed in a customer's own container platform

29.

Which deployment method is supported for Prisma Cloud Compute container Defenders?

a)

Oracle Functions service

b)

VMware NSX

c)

Kubernetes DaemonSet

d)

Azure SQL database instances

30.

Prisma Cloud Compute's API protection addresses which security challenge?

a)

Front end bias

b)

API abuse and vulnerabilities

c)

Multifactor authentication

d)

User interface (UI) latency

31.

What does Infrastructure as Code (laC) collect to enable automation?

a)

Orchestrated workflows to enable deployment of infrastructure by cross-functional teams

b)

Modern representation formats that describe and deploy infrastructure

c)

Images for easy replication and management of infrastructure

d)

Infrastructure monitoring tool sets

32.

What will onboarding a version control system, such as Git Hub, into Prisma Cloud allow an organization to observe?

a)

High level code changes on running Amazon EC2

b)

Vulnerabilities within an AWS Lambda environment

c)

Code issues

d)

Agentless scans

33.

What must a customer do before connecting Prisma Cloud to their cloud environment?

a)

Create a set of IAM access keys in the cloud service provider's console

b)

Create a unique external ID for each intended user

c)

Install and initialize the cloud service provider's CLI tool

d)

Create an IAM role with appropriate permissions mapped to the role

34.

What are two business values of Cloud Code Security? (Choose two)

a)

Consistent controls from build time to runtime

b)

Prebuilt and customizable polices to detect data such as personally identifiable information (PII) in publicly exposed objects

c)

Support for multiple languages, runtimes and frameworks

d)

continuous monitoring of all could resources for vulnerabilities, misconfigurations, and other threats

35.

Which filter can be selected to assign policies in an alert rule?

a)

Compliance Requirement

b)

Compliance Standard

c)

Category

d)

Remediable

36.

What are the prerequisites for installing the Jenkins plugin to Prisma Cloud? (Choose two)

a)

Jenkins host must reach the Prisma Cloud Console

b)

Jenkins host must reach the Defender

c)

Jenkins version must meet the maximum system requirements

d)

Jenkins version must meet the minimum system requirements

38.

What are the reasons a customer would choose Panorama over Strata Cloud Manager to manage their Prisma Access?

a)

Panorama manages Prisma SD-WAN policies

b)

Managed by Panorama for ADEM

c)

NGFWs are managed by Panorama

d)

Standard security policies across multiple platforms

39.

Which two of the following are capabilities of Prisma Cloud? (choose two)

a)

Data Security Posture Management

b)

Cloud Workload Protection

c)

Intelligent Data Foundation

d)

Cloud SaaS Access and Security

40.

What is required to determine net effective permissions in AWS? (Choose two)

a)

Management Group

b)

AWS Account

c)

Role Trust Relationships

d)

AWS IAM Group

41.

Which features are included in the WAAS (Web Application and API Security) module? (Choose two)

a)

Geo Access Control

b)

Penalty Box

c)

Reverse Shell Attacks

d)

File Upload Protection

42.

What type of applications does Prisma Cloud secure using the Runtime WAAS capability?

a)

Office applications managed by CSPs

b)

Custom web applications deployed in CSPs

c)

SaaS services deployed and managed by CSPs

d)

AI/ML applications deployed in CSPs

43.

When analyzing for unusual user activity, what does Prisma Cloud monitor?

a)

Operating System

b)

Location

c)

Browser

d)

Address Group

44.

What does Infrastructure as Code (IaC) collect to enable automation?

a)

modern representation formats that describe and deploy infrastructure

b)

orchestrated workflows to enable cross-functional teams to deploy infrastructure

c)

images to easily replicate and manage infrastructure

d)

infrastructure monitoring tool sets

45.

What is the Palo Alto Networks recommended setting for the Prisma Cloud Training Model Threshold?

a)

Low

b)

Baseline

c)

High

d)

Through

46.

Which two template formats are supported by the Prisma Cloud infrastructure as code (IaC) scan service? (Choose two)

a)

XML

b)

ARM

c)

JSON

d)

YAML

47.

Which pillar of the Prisma Cloud plattorm provides support for both public and private clouds as well as flexible agentless scanning and agent-based protection?

a)

Cloud Security Posture Management

b)

Cloud Workload Protection (CWP)

c)

Cloud Network Security

d)

Cloud Identity Security

48.

Which two resources provide operational insight within the Prisma Cloud Asset Inventory? (Choose two)

a)

Compute Engine instance

b)

Prisma Access Gateways

c)

Cloud Storage buckets

d)

Cortex Data Lake

49.

Which pillar of the Prisma Cloud platform can secure outbound traffic, stop lateral attack movement, and block inbound threats?

a)

Cloud Identity Security

b)

Cloud Network Security

c)

Cloud Code Security

d)

Cloud Workload Protection (CWP)

50.

Which type of Resource Query Language (RQL) query is used to create a custom policy that looks for untagged resources?

a)

Config

b)

Event

c)

Data

d)

Alert

51.

In which two ways can Prisma Cloud Compute (PCC) edition be installed? (Choose two)

a)

As a stand-alone Windows application

b)

Self-managed in a customer's own container platform

c)

Self-contained hardware appliance

d)

Cloud-hosted a part of a Prisma Cloud Enterprise tenant from Palo Alto Networks

52.

Which Amazon Web Services (AWS) service supplies information for Prisma Cloud "event where" Resource Query Language (RQL) queries?

a)

CloudTrail Audit Logs

b)

Inspector

c)

Activity Logs

d)

Guard Duty

53.

Which two cloud providers provide egress load balancing? (Choose two)

a)

Microsoft Azure

b)

Amazon Web Services

c)

Oracle Cloud

d)

Alibaba Cloud

54.

What does Prisma Cloud execute to change public cloud infrastructure when autoremediation is enabled?

a)

local scripts to public cloud APIs

b)

remote function calls to host agents

c)

third-party integration tools

d)

public cloud CLI commands

55.

Which Resource Query Language (RQL) query returns a list of all Azure SQL Databases that have transparent data encryption turned on?

a)

config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule = transparentDataEncryption is false

b)

config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule transparentDataEncryption is true

c)

config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule transparentDataEncryption is on

d)

config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule = transparentDataEncryption = true

56.

What occurs with the command twistcli when scanning images?

a)

If options are listed after the image name, they will be ignored

b)

If option "--user" is used, it is mandatory to use option "--password."

c)

If option "--address" is unspecified, all images are scanned

d)

Option "--output-file" cannot be used in conjunction with option "--details."

57.

An image containing medium vulnerabilities that do not have available fixes is being deployed into the sock-shop namespace. Prisma Cloud has been configured for vulnerability management within the organization's continuous integration (CI) tool and registry.

What will occur during the attempt to deploy this image from the CI tool into the sock-shop namespace?

a)

The image will pass the CI policy, but will be blocked by the deployed policy; therefore, it will not be deployed

b)

The CI policy will fail the build; therefore, the image will not be deployed

c)

The image will be deployed successfully, and all vulnerabilities will be reported

d)

The image will be deployed successfully, but no vulnerabilities will be reported

58.

Which statement is specific for Prisma Cloud when integrating into cloud environments?

a)

An AutoFocus license is included in Prisma Cloud

b)

For multi-cloud environment licenses are required for the number of Prisma Cloud instances

c)

Can be natively integrated into Prisma Access

d)

No agents or proxies are required

59.

How can a range of dates in the Prisma Cloud default policy be modified?

a)

Clone the existing policy and change the value

b)

Click the gear icon next to the policy name to open the "Edit Policy" dialog

c)

Manually create the Resource Query Language (RQL) statement

d)

Override the value and commit the configuration

60.

What are two examples of outbound traffic flow? (Choose two)

a)

web server inside Amazon Web Services receiving web requests from internet

b)

outgoing Prisma Public Cloud API calls

c)

Microsoft Windows inside Azure requesting a security patch

d)

issue yum update command on an instance inside Amazon Web Services