WorksheetsTraining Test PA-PSE
Total questions: 60
Worksheet time: 28mins
Which two cloud-native service providers are supported by Prisma Cloud? (Choose two).
Oracle Cloud
DigitalOcean
IBM Cloud
Azure
Which onboarding scope or method is used to automatically onboard new AWS accounts into Prisma Cloud?
AWS Account
AWS Organization
CronJobs
Account Groups
Which application security category displays secrets found in source code?
SBOM
Projects
CI/CD Risks
Technologies
What is a business outcome benefit of Prisma Cloud?
Autoconfiguring network policies
Improving security operations productivity
Increasing remediation time
Eliminating customer chum
In the Prisma Cloud dashboard, how can alerts related to Amazon RDS be quickly identified?
Generate a CIS compliance report and search for Amazon RDS policy violations
View the alert data on the "Asset Inventory" dashboard, then filter on Amazon RDS
Create a custom RQL configuration report that includes Amazon RDS
In the "Alerts" tab, filter on Amazon RDS as a service
How are violations to public cloud infrastructure autoromedigted by Prismna Cloud Enterprise?
By making changes after the violation has been identified in monitoring
By stopping any configurations without prior authorization and locking all changes to public cloud infrastructure
By using machine learning (ML) to identify unusual infrastructure modifications
By inspecting the API call made to public cloud and blocking the change if a determination is made that there has been a policy violation
Which two data sources are ingested by Prisma Cloud? (Choose two)
Compute resource configuration metadata
Database instance table list
Strata Logging Service
Network flow logs
What are the five areas that help make a Prisma Cloud solutions architect a trusted advisor by developing a deep understanding of customer security needs?
Understanding the customer's business, organization, cloud journey, cniticality / nature of cloud applications, and security use cases
Understanding the customer's organization, budget requirements, leadership, cloud journey, and criticality / nature of cloud applications
Understanding the customer's business, organization, budget requirements, leadership, and industry trends
Understanding the custom's organization, criticality / nature of cloud applications, industry trends, and security use cases
The Trusted Images security control feature allows declaration of how to respond to which scenario?
There are trusted images started in the environment
There are unsigned images in the environment
There are untrusted images started in the environment
There are images with malware or cryptominers in the environment
Which resource is included in the Prisma Cloud Enterprise licensing count?
NAT gateways
Shared rules
Security groups
CloudFront distributions
Which template is supported by Cloud Code Security scan service?
Github
HTML
Terraform
NAT
Which Prisma Cloud module can identify misconfigured infrastructure-as-code that leads to insecure runtime cloud services?
IaC scanning in the application security module
CI pipeline scanning in the runtime module
Vulnerability scanning in the runtime or Cloud Security Module
Compliance scanning in the Cloud Security Module
Which action allows Prisma Cloud to be enabled to proactively help developers secure code and provide proactive developer feedback regarding code issues?
Setting up agentless scanning to view the results
Enabling automatic learning
Viewing console logs within Prisma Cloud
Setting up an IDE plugin and running the first scan
Which feature is exclusive to Prisma Cloud Compute Edition?
Centralized policy management
Integration with third-party tools
Self-hosted management console
Automated compliance reporting
In a vulnerability management policy, what is the correlation between the block and alert thresholds?
The block threshold must always be equal to or greater than the alert threshold
Both thresholds can be set to informational, low, medium, high, and critical
The alert threshold always has precedence over, and can be greater than, the block threshold
The block threshold always has precedence over, and can be less than, the alert threshold
A year has passed since an AWS Organization has been onboarded into Prisma Cloud New Prisma Cloud features have been released that require additional permissions from the cloud accounts
Which actions will ensure the necessary permissions are available across the IAM roles?
Generate a new Prisma Cloud onboarding template and delete the existing stacks from the AWS Organization
Trigger a Jenkins automation that will automatically upgrade all Defenders regardless of N-2 support policy
Generate a new Prisma Cloud onboarding template and apply it to existing stacks in the AWS Organization
Redeploy all Defenders and check for version type
Which tool is used to onboard an AWS account into Prisma Cloud using the provided template?
Terraform
Ansible
AWS CloudFormation
AWS CodeCommit
What are two benefits to organizations that deploy Prisma Cloud? (Choose two)
On-premises infrastructure costs decrease exponentially year-over-year
Security outcomes are improved by consolidating security management
Adopted security practices improve efficiency for cloud security enforcement
Data is automatically prepared and enriched, then uniquely stitched into security intelligence
Which action is appropriate when configuring Prisma Cloud to scan a registry?
Allow automatic optimization of registry scans with version pattern matching
Determine the predefined version pattern-matching algorithm
Explicitly specify the Defender to perform the task
Block Defender image manifest generation
What are two benefits of Cloud Security Posture Management (CSPM) over other solutions? (Choose two)
Addressing risks proactively
Native integration of network, endpoint, and cloud data to stop attacks
Elimination of blind spots
Guaranteed proof of concept (POC) extensions beyond 30 days
Which action will block a Container running as root?
Create a Vulnerability Management Policy with the Alert eftect on Containers running as root
Create a Compliance Rule with the Block effect on Containers running as root
Configure an Alert effect on Containers running as root
Configure a Block eftect on all Containers
Which use case is typical for Prisma Cloud?
Using machine learning (ML) algorithms to predict and protect against HTTP-based threats
Discover and quarantine malicious files within only Linux file systems
Building and testing new software applications using integration testing methodology
Monitoring and securing resources across multiple cloud platforms
When deciding between Prisma Cloud Compute Edition and Prisma Cloud Enterprise Edition, what is a primary factor to consider?
Type of cloud service provider currently in use
Availability of mobile device support from the company's IT department
Deployment model and location of management components
Need for API security management
Prevention against which type of attack is configurable in Web-Application and API Security (WAAS)?
XSS
DDoS
Shoulder surfing
Credential stuffing
Why is it important to understand how a customer's cloud infrastructure team creates and deploys new cloud resources?
Because Prisma Cloud provides visibility and secure cloud resources throughout the system and software development lifecycle
Because Prisma Cloud requires agents to be deployed in order to secure new cloud resources
Because Prisma Cloud will require the cloud infrastructure team to change their existing deployment process
Because Prisma Cloud will only be able to provide visibility and security for the cloud services which have already been deployed
Which use case is applicable to Prisma Cloud?
Requiring continuous monitoring and analysis and creating permissions and entitlements across cloud environment
Designing and prototyping Web 2 0 product designs
Needing the ability to fix risk immediately in the cloud or request a permanent fix in code
Identifying misconfigured AWS Cloud Templates in GCP projects
What is an essential step when planning and architecting a Prisma Cloud deployment to ensure effective runtime protection?
Deploying Defender agents on supported hosts
Implementing log management solutions
Configuring automated compliance reports
Setting up API integrations with monitoring tools
How can Prisma Cloud Compute edition be installed?
As a self-contained hardware appliance
Imported from a customer's existing CASB
As a stand-alone Windows application
Self-managed in a customer's own container platform
Which deployment method is supported for Prisma Cloud Compute container Defenders?
Oracle Functions service
VMware NSX
Kubernetes DaemonSet
Azure SQL database instances
Prisma Cloud Compute's API protection addresses which security challenge?
Front end bias
API abuse and vulnerabilities
Multifactor authentication
User interface (UI) latency
What does Infrastructure as Code (laC) collect to enable automation?
Orchestrated workflows to enable deployment of infrastructure by cross-functional teams
Modern representation formats that describe and deploy infrastructure
Images for easy replication and management of infrastructure
Infrastructure monitoring tool sets
What will onboarding a version control system, such as Git Hub, into Prisma Cloud allow an organization to observe?
High level code changes on running Amazon EC2
Vulnerabilities within an AWS Lambda environment
Code issues
Agentless scans
What must a customer do before connecting Prisma Cloud to their cloud environment?
Create a set of IAM access keys in the cloud service provider's console
Create a unique external ID for each intended user
Install and initialize the cloud service provider's CLI tool
Create an IAM role with appropriate permissions mapped to the role
What are two business values of Cloud Code Security? (Choose two)
Consistent controls from build time to runtime
Prebuilt and customizable polices to detect data such as personally identifiable information (PII) in publicly exposed objects
Support for multiple languages, runtimes and frameworks
continuous monitoring of all could resources for vulnerabilities, misconfigurations, and other threats
Which filter can be selected to assign policies in an alert rule?
Compliance Requirement
Compliance Standard
Category
Remediable
What are the prerequisites for installing the Jenkins plugin to Prisma Cloud? (Choose two)
Jenkins host must reach the Prisma Cloud Console
Jenkins host must reach the Defender
Jenkins version must meet the maximum system requirements
Jenkins version must meet the minimum system requirements
Which of the following is the correct Prisma Cloud registry?
What are the reasons a customer would choose Panorama over Strata Cloud Manager to manage their Prisma Access?
Panorama manages Prisma SD-WAN policies
Managed by Panorama for ADEM
NGFWs are managed by Panorama
Standard security policies across multiple platforms
Which two of the following are capabilities of Prisma Cloud? (choose two)
Data Security Posture Management
Cloud Workload Protection
Intelligent Data Foundation
Cloud SaaS Access and Security
What is required to determine net effective permissions in AWS? (Choose two)
Management Group
AWS Account
Role Trust Relationships
AWS IAM Group
Which features are included in the WAAS (Web Application and API Security) module? (Choose two)
Geo Access Control
Penalty Box
Reverse Shell Attacks
File Upload Protection
What type of applications does Prisma Cloud secure using the Runtime WAAS capability?
Office applications managed by CSPs
Custom web applications deployed in CSPs
SaaS services deployed and managed by CSPs
AI/ML applications deployed in CSPs
When analyzing for unusual user activity, what does Prisma Cloud monitor?
Operating System
Location
Browser
Address Group
What does Infrastructure as Code (IaC) collect to enable automation?
modern representation formats that describe and deploy infrastructure
orchestrated workflows to enable cross-functional teams to deploy infrastructure
images to easily replicate and manage infrastructure
infrastructure monitoring tool sets
What is the Palo Alto Networks recommended setting for the Prisma Cloud Training Model Threshold?
Low
Baseline
High
Through
Which two template formats are supported by the Prisma Cloud infrastructure as code (IaC) scan service? (Choose two)
XML
ARM
JSON
YAML
Which pillar of the Prisma Cloud plattorm provides support for both public and private clouds as well as flexible agentless scanning and agent-based protection?
Cloud Security Posture Management
Cloud Workload Protection (CWP)
Cloud Network Security
Cloud Identity Security
Which two resources provide operational insight within the Prisma Cloud Asset Inventory? (Choose two)
Compute Engine instance
Prisma Access Gateways
Cloud Storage buckets
Cortex Data Lake
Which pillar of the Prisma Cloud platform can secure outbound traffic, stop lateral attack movement, and block inbound threats?
Cloud Identity Security
Cloud Network Security
Cloud Code Security
Cloud Workload Protection (CWP)
Which type of Resource Query Language (RQL) query is used to create a custom policy that looks for untagged resources?
Config
Event
Data
Alert
In which two ways can Prisma Cloud Compute (PCC) edition be installed? (Choose two)
As a stand-alone Windows application
Self-managed in a customer's own container platform
Self-contained hardware appliance
Cloud-hosted a part of a Prisma Cloud Enterprise tenant from Palo Alto Networks
Which Amazon Web Services (AWS) service supplies information for Prisma Cloud "event where" Resource Query Language (RQL) queries?
CloudTrail Audit Logs
Inspector
Activity Logs
Guard Duty
Which two cloud providers provide egress load balancing? (Choose two)
Microsoft Azure
Amazon Web Services
Oracle Cloud
Alibaba Cloud
What does Prisma Cloud execute to change public cloud infrastructure when autoremediation is enabled?
local scripts to public cloud APIs
remote function calls to host agents
third-party integration tools
public cloud CLI commands
Which Resource Query Language (RQL) query returns a list of all Azure SQL Databases that have transparent data encryption turned on?
config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule = transparentDataEncryption is false
config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule transparentDataEncryption is true
config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule transparentDataEncryption is on
config from cloud.resource where api.name = 'azure-sql-db-list' and json.rule = transparentDataEncryption = true
What occurs with the command twistcli when scanning images?
If options are listed after the image name, they will be ignored
If option "--user" is used, it is mandatory to use option "--password."
If option "--address" is unspecified, all images are scanned
Option "--output-file" cannot be used in conjunction with option "--details."
An image containing medium vulnerabilities that do not have available fixes is being deployed into the sock-shop namespace. Prisma Cloud has been configured for vulnerability management within the organization's continuous integration (CI) tool and registry.
What will occur during the attempt to deploy this image from the CI tool into the sock-shop namespace?
The image will pass the CI policy, but will be blocked by the deployed policy; therefore, it will not be deployed
The CI policy will fail the build; therefore, the image will not be deployed
The image will be deployed successfully, and all vulnerabilities will be reported
The image will be deployed successfully, but no vulnerabilities will be reported
Which statement is specific for Prisma Cloud when integrating into cloud environments?
An AutoFocus license is included in Prisma Cloud
For multi-cloud environment licenses are required for the number of Prisma Cloud instances
Can be natively integrated into Prisma Access
No agents or proxies are required
How can a range of dates in the Prisma Cloud default policy be modified?
Clone the existing policy and change the value
Click the gear icon next to the policy name to open the "Edit Policy" dialog
Manually create the Resource Query Language (RQL) statement
Override the value and commit the configuration
What are two examples of outbound traffic flow? (Choose two)
web server inside Amazon Web Services receiving web requests from internet
outgoing Prisma Public Cloud API calls
Microsoft Windows inside Azure requesting a security patch
issue yum update command on an instance inside Amazon Web Services
