wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

alto 3

Total questions: 41

Worksheet time: 21mins

Name
Class
Date
1.

Which of the following is not a phase of implementing security in virtualized data centers:

a)

Consolidating servers across trust levels

b)

Consolidating servers within trust levels

c)

Selective network security virtualization

d)

Implementing a static and flat computing fabric

2.

Data that moves in and out of the virtualized environment from the host network or a corresponding traditional data center is also known as:

a)

North-South

b)

Unknown

c)

North-East

d)

East-West

3.

Intra-VM traffic is also known as:

a)

North-South

b)

Unknown

c)

North-East

d)

East-West

4.

The first phase of implementing security in virtualized data centers consists of:

a)

Consolidating servers across trust levels

b)

Consolidating servers within trust levels

c)

Selectively virtualizing network security functions

d)

Implementing a dynamic computing fabric

5.

An added benefit of using virtual firewalls for east-west protection is the unprecedented traffic and threat visibility that the virtualized security device can now provide.

a)

True

b)

False

6.

Which of the 4 Cs of cloud native security provides the trusted computing base for a Kubernetes cluster. If the cluster is built on a foundation that is inherently vulnerable or configured with poor security controls, then the other layers cannot be properly secured.

a)

Clusters

b)

Containers

c)

Code

d)

Cloud

7.

Development and Operations teams meet regularly, share analytics, and co-own projects from beginning to end.

a)

True

b)

False

8.

The Cloud Native Computing Foundation (CNCF) Kubernetes project defines a container security model for Kubernetes in the context of cloud native security. This model is referred to as “the 4 C’s of Cloud Native security”.

a)

True

b)

False

9.

The CI/CD pipeline integrates Development and Operations teams to improve productivity by automating infrastructure and workflows as well as continuously measuring application performance.

a)

True

b)

False

10.

Ensuring your cloud resources and SaaS applications are correctly configured and adhere to your organization’s security standards from day one is essential to prevent successful attacks.

a)

True

b)

False

11.

The term “cloud native” refers to an approach to building and running applications that takes full advantage of a cloud computing delivery model instead of an on-premises data center.

a)

True

b)

False

12.

Which platform provides all three cloud native characteristics by default and, while assembled from many more generic components, are highly optimized for container workloads.

a)

Serverless

b)

Container as a Service

c)

Thin VMs

d)

On-Demand Containers

13.

Which cloud native technology balances separation, excellent compatibility with existing apps, and a high degree of operational control with good density potential and easy integration into software development flows.

a)

Thin VMs

b)

Serverless

c)

Containers

d)

CaaS

14.

In which cloud native technology do applications rely on managed services that abstract away the need to manage, patch, and secure infrastructure and virtual machines?

a)

Serverless

b)

Thin VMs

c)

Containers

d)

CaaS

15.

Which consideration is not associated with secure virtualization?

a)

Dormant VMs

b)

Hypervisor Sprawl

c)

Hypervisor Vulnerabilities

d)

Intra-VM Communication

16.

A hypervisor allows multiple, virtual (“guest”) operating systems to run concurrently on a single physical host computer.

a)

True

b)

False

17.

In the serverless model, applications rely on managed services that abstract away the need to manage, patch, and secure infrastructure and virtual machines.

a)

True

b)

False

18.

The benefit of moving toward a cloud computing model is that it improves operational efficiencies and lowers capital expenditures.

a)

True

b)

False

19.

Which cloud computing deployment model is used exclusively by a single organization?

a)

Private

b)

Community

c)

Public

d)

Hybrid

20.

Which cloud computing service model is not defined by NIST?

a)

Software as a Service (SaaS)

b)

Infrastructure as a Service (IaaS)

c)

Desktop as a Service (DaaS)

d)

Platform as a Service (PaaS)

21.

The cloud computing service model in which a provider’s applications run on a cloud infrastructure and the consumer does not manage or control the underlying infrastructure is known as:

a)

Infrastructure as a Service (IAAS)

b)

Software as a Service (SAAS)

c)

Platform as a Service (PAAS)

d)

Identity as a Service (IDAAS)

22.

Which cloud deployment model is bound by standardized or proprietary technology that enables data and application portability (for example, fail over to a secondary data center for disaster recovery or content delivery networks across multiple clouds)?

a)

Public

b)

Community

c)

Private

d)

Hybrid

23.

Platform as a Service - PaaS – is best described as:

a)

An online space where customers can develop, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app.

b)

An underlying network infrastructure that virtualizes physical computing resources, data partitioning, scaling, security, backup.

c)

A licensing and delivery model in which software is licensed on a subscription basis and is centrally hosted.

24.

Which security-as-a-service layer in Prisma Access SASE capability provides visibility into SaaS application usage, understands where their sensitive data resides, enforces company policies for user access, and protects their data from hackers?

a)

Threat Prevention

b)

Data Loss Prevention - DLP

c)

Cloud Access Security Broker - CASB

d)

Secure Web Gateway - SWG

25.

Which Cortex Cloud capability decouples workload identity from IP addresses, leverages tags and metadata to assign a logical identity to applications and workloads, and then uses it to enforce ID-based micro-segmentation and security policies that adapt to your dynamic environments?

a)

Identity and access management (IAM)

b)

UEBA

c)

Access management

d)

Machine identity

26.

Which Prisma Access SASE capability can be used to block inappropriate content - such as pornography and gambling - or websites that businesses simply don’t want users accessing while at work, such as streaming services like Netflix?

a)

Cloud Access Security Broker (CASB)

b)

Secure Web Gateway (SWG)

c)

Virtual Private Network (VPN)

d)

Identity and access management (IAM)

27.

To safely enable SaaS usage in your organization, start by clearly defining the SaaS applications that should be used and which behaviors within those applications are allowed. Which category of applications are not allowed, then controlling their usage with granular policies.

a)

Tolerated

b)

Unsanctioned

c)

Sanctioned

d)

Permitted

28.

Select the type of cybersecurity solution or feature that discovers threats by identifying activity that deviates from a baseline.

a)

Software configuration management - SCM

b)

Firewall

c)

Antivirus

d)

Intrusion Detection System (IDS)

e)

User and entity behavior analytics - UEBA

29.

Prisma SaaS is an inline service, so it doesn’t impact latency, bandwidth, or end-user experience.

a)

True

b)

False

30.

Sanctioned SaaS applications fulfill a legitimate business need, but certain usage restrictions may be necessary to reduce risk.

a)

True

b)

False

31.

A cloud access security broker – CASB - is software that monitors activity and enforces security policies on traffic between an organization’s users and cloud-based applications and services.

a)

True

b)

False

32.

Which key capability of Cortex Cloud identity security decouples workload identity from IP addresses?

a)

Access Management

b)

IAM Security

c)

UEBA

d)

Machine Identity

33.

Which of the following add-ons for Prisma Access SASE provides native end-to-end visibility and insights for SASE, and can automate remediation of remote user digital experience problems?

a)

DNS_Sec

b)

FWaaS

c)

ADEM

d)

CASB

34.

Which of the following is NOT a strength of Prisma Access - SASE cloud-delivered management?

a)

Continuous Configuration Assessment

b)

Visibility Into the Management Options

c)

Rapid Application Development

d)

Flexible Management Options

35.

Which of the following would NOT be an element for discussion in a Prisma Access SASE design review?

a)

Website Enrollments

b)

Service Connections

c)

Authentication Capabilities

d)

Default Routes

36.

Which Prisma Access capability offers simplified workflows with secure out-of-the-box configurations?

a)

Access and Protection

b)

Security Protection

c)

Best-in-Class-Security

d)

Cloud Management

37.

Which Cortex Cloud Pillar Enforce machine learning-based runtime protection to protect applications and workloads in real time?

a)

Identity Security

b)

Network Protection

c)

Compute Security

38.

Which Prisma SaaS applications are allowed because of a legitimate business need, with restrictions, but not provided by IT?

a)

Sanctioned

b)

Visible

c)

Unsanctioned

d)

Tolerated

39.

Which term refers to an approach to building and running applications that takes full advantage of a cloud computing delivery model instead of an on-premises data center?

a)

Cloud-Native

b)

Cloud-Agnostic

c)

Cloud-Centric

40.

Which Pillar of Cortex Cloud monitors and leverages user and entity behavior analytics - UEBA - across your environments to detect and block malicious actions?

a)

Compute Security

b)

Visibility, Governance, and Compliance

c)

Network Protection

d)

Identity Security

41.

Which of the following serves as Prisma Access SASE security policy enforcement points and helps organizations discover where their data resides across multiple SaaS applications, cloud services environments, on-premises data centers and mobile workers?

a)

FWaaS

b)

CASB

c)

DNS_Sec

d)

ADEM