New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Cloud Security Engineer CloudSec-Pro Questions and answers with CertsForce

Viewing page 3 out of 8 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which three OWASP protections are part of Prisma Cloud Web-Application and API Security (WAAS) rule? (Choose three.)

Options:

A.

DoS Protection


B.

Local file inclusion


C.

SQL injection


D.

Suspicious binary


E.

Shellshock


Expert Solution
Questions # 22:

A customer wants to scan a serverless function as part of a build process. Which twistcli command can be used to scan serverless functions?

Options:

A.

twistcli function scan


B.

twistcli scan serverless


C.

twistcli serverless AWS


D.

twiscli serverless scan


Expert Solution
Questions # 23:

Which step should a SecOps engineer implement in order to create a network exposure policy that identifies instances accessible from any untrusted internet sources?

Options:

A.

In Policy Section-> Add Policy-> Config type -> Define Policy details Like Name,Severity-> Configure RQL query "config from network where source.network = UNTRUSTJNTERNET and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS*" -> define compliance standard -> Define recommendation for remediation & save.


B.

In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name.Severity-> Configure RQL query "network from vpc.flow_record where source.publicnetwork IN ('Suspicious IPs', 'Internet IPs') and dest.resource IN (resource where role IN ('Instance ))" -> define compliance standard -> Define recommendation for remediation & save.


C.

In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name.Severity-> Configure RQL query "network from vpc.flow_record where source.publicnetwork IN ('Suspicious IPs', 'Internet IPs') and dest.resource IN (resource where role IN ( Instance ))" -> define compliance standard -> Define recommendation for remediation & save.


D.

In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name.Severity-> Configure RQL query "config from network where source.network = UNTRUSTJNTERNET and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS'" -> Define recommendation for remediation & save.


Expert Solution
Questions # 24:

Which step is included when configuring Kubernetes to use Prisma Cloud Compute as an admission controller?

Options:

A.

copy the Console address and set the config map for the default namespace.


B.

create a new namespace in Kubernetes called admission-controller.


C.

enable Kubernetes auditing from the Defend > Access > Kubernetes page in the Console.


D.

copy the admission controller configuration from the Console and apply it to Kubernetes.


Expert Solution
Questions # 25:

Which ROL query is used to detect certain high-risk activities executed by a root user in AWS?

Options:

A.

event from cloud.audit_logs where operation IN ( 'ChangePassword', 'ConsoleLogin', 'DeactivateMFADevice', 'DeleteAccessKey' , 'DeleteAlarms' ) AND user = 'root'


B.

event from cloud.security_logs where operation IN ( 'ChangePassword', 'ConsoleLogin', 'DeactivateMFADevice', 'DeleteAccessKey' , 'DeleteAlarms' ) AND user = 'root'


C.

config from cloud.audit_logs where operation IN ( 'ChangePassword', 'ConsoleLogin', 'DeactivateMFADevice', 'DeleteAccessKey', 'DeleteAlarms' ) AND user = 'root'


D.

event from cloud.audit_logs where Risk.Level = 'high' AND user = 'root'


Expert Solution
Questions # 26:

Prisma Cloud supports sending audit event records to which three targets? (Choose three.)

Options:

A.

SNMP Traps


B.

Syslog


C.

Stdout


D.

Prometheus


E.

Netflow


Expert Solution
Questions # 27:

An administrator has been tasked with creating a custom service that will download any existing compliance report from a Prisma Cloud Enterprise tenant.

In which order will the APIs be executed for this service?

(Drag the steps into the correct order of occurrence, from the first step to the last.)

Question # 27


Expert Solution
Questions # 28:

Prisma Cloud cannot integrate which of the following secrets managers?

Options:

A.

IBM Secret Manager


B.

AzureKey Vault


C.

HashiCorp Vault


D.

AWS Secret Manager


Expert Solution
Questions # 29:

Which component(s), if any, will Palo Alto Networks host and run when a customer purchases Prisma Cloud Enterprise Edition?

Options:

A.

Defenders


B.

Console


C.

Jenkins


D.

twistcli


Expert Solution
Questions # 30:

Which API calls can scan an image named myimage: latest with twistcli and then retrieve the results from Console?

Options:

A.

$ twistcli images scan \--address \--user \--password \--verbose \myimage: latest


B.

$ twistcli images scan \--address \--user \--password \--details \myimage: latest


C.

$ twistcli images scan \--address \--user \--password \myimage: latest


D.

$ twistcli images scan \--address \--user \--password \--console \myimage: latest


Expert Solution
Viewing page 3 out of 8 pages
Viewing questions 21-30 out of questions