Pass the Paloalto Networks Cloud Security Engineer PCCSE Questions and answers with CertsForce

Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two of the following are required to be entered on the IdP side when setting up SSO in Prisma Cloud? (Choose two.)

Options:

A.

Username


B.

SSO Certificate


C.

Assertion Consumer Service (ACS) URL


D.

SP (Service Provider) Entity ID


Expert Solution
Questions # 12:

Which of the following is a reason for alert dismissal?

Options:

A.

SNOOZED_AUTO_CLOSE


B.

ALERT_RULE_ADDED


C.

POLICY_UPDATED


D.

USER_DELETED


Expert Solution
Questions # 13:

Which command correctly outputs scan results to stdout in tabular format and writes scan results to a JSON file while still sending the results to Console?

Options:

A.

$ twistcli images scan

--address

--user

--password

--stdout-tabular

--output-file scan-results.json

nginx:latest


B.

$ twistcli images scan

--address

--username

--password

--details

--json-output scan-results.json

nginx:latest


C.

$ twistcli images scan

--address

--user

--password

--details

--file-output scan-results.json

nginx:latest


D.

$ twistcli images scan

--address

--u

--p

--details

--output-file scan-results.json

nginx:latest


Expert Solution
Questions # 14:

A customer wants to turn on Auto Remediation.

Which policy type has the built-in CLI command for remediation?

Options:

A.

Anomaly


B.

Audit Event


C.

Network


D.

Config


Expert Solution
Questions # 15:

The security auditors need to ensure that given compliance checks are being run on the host. Which option is a valid host compliance policy?

Options:

A.

Ensure functions are not overly permissive.


B.

Ensure host devices are not directly exposed to containers.


C.

Ensure images are created with a non-root user.


D.

Ensure compliant Docker daemon configuration.


Expert Solution
Questions # 16:

What is a benefit of the Cloud Discovery feature?

Options:

A.

It does not require any specific permissions to be granted before use.


B.

It helps engineers find all cloud-native services being used only on AWS.


C.

It offers coverage for serverless functions on AWS only.


D.

It enables engineers to continuously monitor all accounts and report on the services that are unprotected.


Expert Solution
Questions # 17:

A customer wants to monitor its Amazon Web Services (AWS) accounts via Prisma Cloud, but only needs the resource configuration to be monitored at present.

Which two pieces of information are needed to onboard this account? (Choose two.)

Options:

A.

External ID


B.

CloudTrail


C.

Active Directory ID


D.

RoleARN


Expert Solution
Questions # 18:

Which component of a Kubernetes setup can approve, modify, or reject administrative requests?

Options:

A.

Kube Controller


B.

Terraform Controller


C.

Admission Controller


D.

Control plane


Expert Solution
Questions # 19:

The development team wants to fail CI jobs where a specific CVE is contained within the image. How should the development team configure the pipeline or policy to produce this outcome?

Options:

A.

Set the specific CVE exception as an option in Jenkins or twistcli.


B.

Set the specific CVE exception as an option in Defender running the scan.


C.

Set the specific CVE exception as an option using the magic string in the Console.


D.

Set the specific CVE exception in Console’s CI policy.


Expert Solution
Questions # 20:

What are the three states of the Container Runtime Model? (Choose three.)

Options:

A.

Initiating


B.

Learning


C.

Active


D.

Running


E.

Archived


Expert Solution
Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions