New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Cloud Security Engineer CloudSec-Pro Questions and answers with CertsForce

Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions
Questions # 31:

In Prisma Cloud for Azure Net Effective Permissions Calculation, the following Azure permission levels are supported by which three permissions? (Choose three).

Options:

A.

Resources


B.

Tenant


C.

Subscription


D.

Resource groups


E.

Management Group


Expert Solution
Questions # 32:

Which three actions are required in order to use the automated method within Azure Cloud to streamline the process of using remediation in the identity and access management (IAM) module? (Choose three.)

Options:

A.

Install boto3 & requests library.


B.

Configure IAM Azure remediation script.


C.

Integrate with Azure Service Bus.


D.

Configure IAM AWS remediation script.


E.

Install azure.servicebus & requests library.


Expert Solution
Questions # 33:

Per security requirements, an administrator needs to provide a list of people who are receiving e-mails for Prisma Cloud alerts.

Where can the administrator locate this list of e-mail recipients?

Options:

A.

Target section within an Alert Rule.


B.

Notification Template section within Alerts.


C.

Users section within Settings.


D.

Set Alert Notification section within an Alert Rule.


Expert Solution
Questions # 34:

Which “kind” of Kubernetes object is configured to ensure that Defender is acting as the admission controller?

Options:

A.

MutatingWebhookConfiguration


B.

DestinationRules


C.

ValidatingWebhookConfiguration


D.

PodSecurityPolicies


Expert Solution
Questions # 35:

Given the following information, which twistcli command should be run if an administrator were to exec into a running container and scan it from within using an access token for authentication?

• Console is located at https://prisma-console.mydomain.local

• Token is: TOKEN_VALUE

• Report ID is: REPORTJD

• Container image running is: myimage:latest

Options:

A.

twistcli images scan --address https://prisma-console.mydomain.local —token TOKENVALUE —containerized —details myimage:latest


B.

twistcli images scan —console-address https://prisma-console.mydomain.local —auth-token MY_TOKEN —local-scan —details myimage:latest


C.

twistcli images scan —address https://prisma-console.mydomain.local —token TOKEN_VALUE —containerized --details REPORT_ID


D.

twistcli images scan --console-address https://prisma-console.mydomain.local --auth-token TOKEN_VALUE —containerized —vulnerability-details REPORT_ID


Expert Solution
Questions # 36:

Which policy type in Prisma Cloud can protect against malware?

Options:

A.

Data


B.

Config


C.

Network


D.

Event


Expert Solution
Questions # 37:

Console is running in a Kubernetes cluster, and you need to deploy Defenders on nodes within this cluster.

Which option shows the steps to deploy the Defenders in Kubernetes using the default Console service name?

Options:

A.

From the deployment page in Console, choose pod name for Console identifier, generate DaemonSet file, and apply the DaemonSet to twistlock namespace.


B.

From the deployment page configure the cloud credential in Console and allow cloud discovery to auto-protect the Kubernetes nodes.


C.

From the deployment page in Console, choose twistlock-console for Console identifier, generate DaemonSet file, and apply DaemonSet to the twistlock namespace.


D.

From the deployment page in Console, choose twistlock-console for Console identifier, and run the curl | bash script on the master Kubernetes node.


Expert Solution
Questions # 38:

What are the subtypes of configuration policies in Prisma Cloud?

Options:

A.

Build and Deploy


B.

Monitor and Analyze


C.

Security and Compliance


D.

Build and Run


Expert Solution
Questions # 39:

An administrator sees that a runtime audit has been generated for a host. The audit message is:

“Service postfix attempted to obtain capability SHELL by executing /bin/sh /usr/libexec/postfix/postfix- script.stop. Low severity audit, event is automatically added to the runtime model”

Which runtime host policy rule is the root cause for this runtime audit?

Options:

A.

Custom rule with specific configuration for file integrity


B.

Custom rule with specific configuration for networking


C.

Default rule that alerts on capabilities


D.

Default rule that alerts on suspicious runtime behavior


Expert Solution
Questions # 40:

Which options show the steps required after upgrade of Console?

Options:

A.

Uninstall Defenders Upgrade Jenkins PluginUpgrade twistcli where applicableAllow the Console to redeploy the Defender


B.

Update the Console image in the Twistlock hosted registry Update the Defender image in the Twistlock hosted registry Uninstall Defenders


C.

Upgrade Defenders Upgrade Jenkins Plugin Upgrade twistcli where applicable


D.

Update the Console image in the Twistlock hosted registry Update the Defender image in the Twistlock hosted registry Redeploy Console


Expert Solution
Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions