New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Cloud Security Engineer CloudSec-Pro Questions and answers with CertsForce

Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions
Questions # 11:

The development team is building pods to host a web front end, and they want to protect these pods with an application firewall.

Which type of policy should be created to protect this pod from Layer7 attacks?

Options:

A.

The development team should create a WAAS rule for the host where these pods will be running.


B.

The development team should create a WAAS rule targeted at all resources on the host.


C.

The development team should create a runtime policy with networking protections.


D.

The development team should create a WAAS rule targeted at the image name of the pods.


Expert Solution
Questions # 12:

The security team wants to target a CNAF policy for specific running Containers. How should the administrator scope the policy to target the Containers?

Options:

A.

scope the policy to Image names.


B.

scope the policy to namespaces.


C.

scope the policy to Defender names.


D.

scope the policy to Host names.


Expert Solution
Questions # 13:

You are an existing customer of Prisma Cloud Enterprise. You want to onboard a public cloud account and immediately see all of the alerts associated with this account based off ALL of your tenant’s existing enabled policies. There is no requirement to send alerts from this account to a downstream application at this time.

Which option shows the steps required during the alert rule creation process to achieve this objective?

Options:

A.

Ensure the public cloud account is assigned to an account group Assign the confirmed account group to alert ruleSelect “select all policies” checkbox as part of the alert rule Confirm the alert rule


B.

Ensure the public cloud account is assigned to an account group Assign the confirmed account group to alert ruleSelect one or more policies checkbox as part of the alert rule Confirm the alert rule


C.

Ensure the public cloud account is assigned to an account group Assign the confirmed account group to alert ruleSelect one or more policies as part of the alert rule Add alert notificationsConfirm the alert rule


D.

Ensure the public cloud account is assigned to an account group Assign the confirmed account group to alert ruleSelect “select all policies” checkbox as part of the alert rule Add alert notificationsConfirm the alert rule


Expert Solution
Questions # 14:

Which policy type provides information about connections from suspicious IPs in a customer database?

Options:

A.

Anomaly


B.

Threat detection


C.

Network


D.

AutoFocus


Expert Solution
Questions # 15:

Given the following RQL:

event from cloud.audit_logs where operation IN (‘CreateCryptoKey’, ‘DestroyCryptoKeyVersion’, ‘v1.compute.disks.createSnapshot’)

Which audit event snippet is identified?

A)

Question # 15

B)

C)

Question # 15

D)

Question # 15

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 16:

Which role must be assigned to DevOps users who need access to deploy Container and Host Defenders in Compute?

Options:

A.

Cloud Provisioning Admin


B.

Build and Deploy Security


C.

System Admin


D.

Developer


Expert Solution
Questions # 17:

Which two integrations enable ingesting host findings to generate alerts? (Choose two.)

Options:

A.

Splunk


B.

Tenable


C.

JIRA


D.

Qualys


Expert Solution
Questions # 18:

An administrator has deployed Console into a Kubernetes cluster running in AWS. The administrator also has configured a load balancer in TCP passthrough mode to listen on the same ports as the default Prisma Compute Console configuration.

In the build pipeline, the administrator wants twistcli to talk to Console over HTTPS. Which port will twistcli need to use to access the Prisma Compute APIs?

Options:

A.

8084


B.

443


C.

8083


D.

8081


Expert Solution
Questions # 19:

Move the steps to the correct order to set up and execute a serverless scan using AWS DevOps.

Question # 19


Expert Solution
Questions # 20:

The InfoSec team wants to be notified via email each time a Security Group is misconfigured. Which Prisma Cloud tab should you choose to complete this request?

Options:

A.

Notifications


B.

Policies


C.

Alert Rules


D.

Events


Expert Solution
Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions