Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Cloud Security Engineer CloudSec-Pro Questions and answers with CertsForce

Viewing page 8 out of 8 pages
Viewing questions 71-80 out of questions
Questions # 71:

Which type of compliance check is available for rules under Defend > Compliance > Containers and Images > CI?

Options:

A.

Host


B.

Container


C.

Functions


D.

Image


Expert Solution
Questions # 72:

Based on the following information, which RQL query will satisfy the requirement to identify VM hosts deployed to organization public cloud environments exposed to network traffic from the internet and affected by Text4Shell RCE (CVE-2022-42889) vulnerability?

• Network flow logs from all virtual private cloud (VPC) subnets are ingested to the Prisma Cloud Enterprise Edition tenant.

• All virtual machines (VMs) have Prisma Cloud Defender deployed.

A)

B)

C)

D)

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 73:

Which three fields are mandatory when authenticating the Prisma Cloud plugin in the IntelliJ application? (Choose three.)

Options:

A.

Secret Key


B.

Prisma Cloud API URL


C.

Tags


D.

Access Key


E.

Asset Name


Expert Solution
Questions # 74:

Which statement applies to Adoption Advisor?

Options:

A.

It helps adopt security capabilities at a fixed pace regardless of the organization's needs.


B.

It only provides guidance during the deploy phase of the application lifecycle.


C.

It is only available for organizations that have completed the cloud adoption journey.


D.

It includes security capabilities from subscriptions for CSPM, CWP, CCS, OEM, and Data Security.


Expert Solution
Questions # 75:

Which Prisma Cloud policy type can protect against malware?

Options:

A.

Event


B.

Network


C.

Config


D.

Data


Expert Solution
Questions # 76:

The security team wants to enable the “block” option under compliance checks on the host.

What effect will this option have if it violates the compliance check?

Options:

A.

The host will be taken offline.


B.

Additional hosts will be prevented form starting.


C.

Containers on a host will be stopped.


D.

No containers will be allowed to start on that host.


Expert Solution
Questions # 77:

Which RQL query will help create a custom identity and access management (1AM) policy to alert on Lambda functions that have permission to terminate EC2 instances?

Options:

A.

iam from cloud.resource where dest.cloud.type = ’AWS’ AND source.cloud.service.name = ’lambda’ AND source.cloud.resource.type = ’function’ AND dest.cloud.service.name = ’ec2’ AND action.name = ’ec2:TerminateInstances’


B.

config from iam where dest.cloud.type = ’AWS’ AND source.cloud.service.name = ’ec2’ AND source.cloud.resource.type = ’instance’ AND dest.cloud.service.name = ’lambda’ AND action.name = ’ec2:TerminateInstances’


C.

iam from cloud.resource where cloud.type equals ’AWS’ AND cloud.resource.type equals ’lambda function’ AND cloud.service.name = ’ec2’ AND action.name equals ’ec2:TerminateInstances’


D.

config from iam where dest.cloud.type = ’AWS’ AND source.cloud.service.name = ’lambda’ AND source.cloud.resource.type = ’function’ AND dest.cloud.service.name = ’ec2’ AND action.name = ’ec2:TerminateInstances’


Expert Solution
Viewing page 8 out of 8 pages
Viewing questions 71-80 out of questions