Worksheetsalto 3
Total questions: 41
Worksheet time: 21mins
Which of the following is not a phase of implementing security in virtualized data centers:
Consolidating servers across trust levels
Consolidating servers within trust levels
Selective network security virtualization
Implementing a static and flat computing fabric
Data that moves in and out of the virtualized environment from the host network or a corresponding traditional data center is also known as:
North-South
Unknown
North-East
East-West
Intra-VM traffic is also known as:
North-South
Unknown
North-East
East-West
The first phase of implementing security in virtualized data centers consists of:
Consolidating servers across trust levels
Consolidating servers within trust levels
Selectively virtualizing network security functions
Implementing a dynamic computing fabric
An added benefit of using virtual firewalls for east-west protection is the unprecedented traffic and threat visibility that the virtualized security device can now provide.
True
False
Which of the 4 Cs of cloud native security provides the trusted computing base for a Kubernetes cluster. If the cluster is built on a foundation that is inherently vulnerable or configured with poor security controls, then the other layers cannot be properly secured.
Clusters
Containers
Code
Cloud
Development and Operations teams meet regularly, share analytics, and co-own projects from beginning to end.
True
False
The Cloud Native Computing Foundation (CNCF) Kubernetes project defines a container security model for Kubernetes in the context of cloud native security. This model is referred to as “the 4 C’s of Cloud Native security”.
True
False
The CI/CD pipeline integrates Development and Operations teams to improve productivity by automating infrastructure and workflows as well as continuously measuring application performance.
True
False
Ensuring your cloud resources and SaaS applications are correctly configured and adhere to your organization’s security standards from day one is essential to prevent successful attacks.
True
False
The term “cloud native” refers to an approach to building and running applications that takes full advantage of a cloud computing delivery model instead of an on-premises data center.
True
False
Which platform provides all three cloud native characteristics by default and, while assembled from many more generic components, are highly optimized for container workloads.
Serverless
Container as a Service
Thin VMs
On-Demand Containers
Which cloud native technology balances separation, excellent compatibility with existing apps, and a high degree of operational control with good density potential and easy integration into software development flows.
Thin VMs
Serverless
Containers
CaaS
In which cloud native technology do applications rely on managed services that abstract away the need to manage, patch, and secure infrastructure and virtual machines?
Serverless
Thin VMs
Containers
CaaS
Which consideration is not associated with secure virtualization?
Dormant VMs
Hypervisor Sprawl
Hypervisor Vulnerabilities
Intra-VM Communication
A hypervisor allows multiple, virtual (“guest”) operating systems to run concurrently on a single physical host computer.
True
False
In the serverless model, applications rely on managed services that abstract away the need to manage, patch, and secure infrastructure and virtual machines.
True
False
The benefit of moving toward a cloud computing model is that it improves operational efficiencies and lowers capital expenditures.
True
False
Which cloud computing deployment model is used exclusively by a single organization?
Private
Community
Public
Hybrid
Which cloud computing service model is not defined by NIST?
Software as a Service (SaaS)
Infrastructure as a Service (IaaS)
Desktop as a Service (DaaS)
Platform as a Service (PaaS)
The cloud computing service model in which a provider’s applications run on a cloud infrastructure and the consumer does not manage or control the underlying infrastructure is known as:
Infrastructure as a Service (IAAS)
Software as a Service (SAAS)
Platform as a Service (PAAS)
Identity as a Service (IDAAS)
Which cloud deployment model is bound by standardized or proprietary technology that enables data and application portability (for example, fail over to a secondary data center for disaster recovery or content delivery networks across multiple clouds)?
Public
Community
Private
Hybrid
Platform as a Service - PaaS – is best described as:
An online space where customers can develop, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app.
An underlying network infrastructure that virtualizes physical computing resources, data partitioning, scaling, security, backup.
A licensing and delivery model in which software is licensed on a subscription basis and is centrally hosted.
Which security-as-a-service layer in Prisma Access SASE capability provides visibility into SaaS application usage, understands where their sensitive data resides, enforces company policies for user access, and protects their data from hackers?
Threat Prevention
Data Loss Prevention - DLP
Cloud Access Security Broker - CASB
Secure Web Gateway - SWG
Which Cortex Cloud capability decouples workload identity from IP addresses, leverages tags and metadata to assign a logical identity to applications and workloads, and then uses it to enforce ID-based micro-segmentation and security policies that adapt to your dynamic environments?
Identity and access management (IAM)
UEBA
Access management
Machine identity
Which Prisma Access SASE capability can be used to block inappropriate content - such as pornography and gambling - or websites that businesses simply don’t want users accessing while at work, such as streaming services like Netflix?
Cloud Access Security Broker (CASB)
Secure Web Gateway (SWG)
Virtual Private Network (VPN)
Identity and access management (IAM)
To safely enable SaaS usage in your organization, start by clearly defining the SaaS applications that should be used and which behaviors within those applications are allowed. Which category of applications are not allowed, then controlling their usage with granular policies.
Tolerated
Unsanctioned
Sanctioned
Permitted
Select the type of cybersecurity solution or feature that discovers threats by identifying activity that deviates from a baseline.
Software configuration management - SCM
Firewall
Antivirus
Intrusion Detection System (IDS)
User and entity behavior analytics - UEBA
Prisma SaaS is an inline service, so it doesn’t impact latency, bandwidth, or end-user experience.
True
False
Sanctioned SaaS applications fulfill a legitimate business need, but certain usage restrictions may be necessary to reduce risk.
True
False
A cloud access security broker – CASB - is software that monitors activity and enforces security policies on traffic between an organization’s users and cloud-based applications and services.
True
False
Which key capability of Cortex Cloud identity security decouples workload identity from IP addresses?
Access Management
IAM Security
UEBA
Machine Identity
Which of the following add-ons for Prisma Access SASE provides native end-to-end visibility and insights for SASE, and can automate remediation of remote user digital experience problems?
DNS_Sec
FWaaS
ADEM
CASB
Which of the following is NOT a strength of Prisma Access - SASE cloud-delivered management?
Continuous Configuration Assessment
Visibility Into the Management Options
Rapid Application Development
Flexible Management Options
Which of the following would NOT be an element for discussion in a Prisma Access SASE design review?
Website Enrollments
Service Connections
Authentication Capabilities
Default Routes
Which Prisma Access capability offers simplified workflows with secure out-of-the-box configurations?
Access and Protection
Security Protection
Best-in-Class-Security
Cloud Management
Which Cortex Cloud Pillar Enforce machine learning-based runtime protection to protect applications and workloads in real time?
Identity Security
Network Protection
Compute Security
Which Prisma SaaS applications are allowed because of a legitimate business need, with restrictions, but not provided by IT?
Sanctioned
Visible
Unsanctioned
Tolerated
Which term refers to an approach to building and running applications that takes full advantage of a cloud computing delivery model instead of an on-premises data center?
Cloud-Native
Cloud-Agnostic
Cloud-Centric
Which Pillar of Cortex Cloud monitors and leverages user and entity behavior analytics - UEBA - across your environments to detect and block malicious actions?
Compute Security
Visibility, Governance, and Compliance
Network Protection
Identity Security
Which of the following serves as Prisma Access SASE security policy enforcement points and helps organizations discover where their data resides across multiple SaaS applications, cloud services environments, on-premises data centers and mobile workers?
FWaaS
CASB
DNS_Sec
ADEM
