Pass the Paloalto Networks Cloud Security Engineer PCCSE Questions and answers with CertsForce

Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions
Questions # 31:

What is the purpose of Incident Explorer in Prisma Cloud Compute under the "Monitor" section?

Options:

A.

To sort through large amounts of audit data manually in order to identify developing attacks


B.

To store large amounts of forensic data on the host where Console runs to enable a more rapid and effective

response to incidents


C.

To correlate individual events to identify potential attacks and provide a sequence of process, file system, and network events for a comprehensive view of an incident


D.

To identify and suppress all audit events generated by the defender


Expert Solution
Questions # 32:

A DevOps lead reviewed some system logs and notices some odd behavior that could be a data exfiltration attempt. The DevOps lead only has access to vulnerability data in Prisma Cloud Compute, so the DevOps lead passes this information to SecOps.

Which pages in Prisma Cloud Compute can the SecOps lead use to investigate the runtime aspects of this attack?

Options:

A.

The SecOps lead should investigate the attack using Vulnerability Explorer and Runtime Radar.


B.

The SecOps lead should use Incident Explorer and Compliance Explorer.


C.

The SecOps lead should use the Incident Explorer page and Monitor > Events > Container Audits.


D.

The SecOps lead should review the vulnerability scans in the CI/CD process to determine blame.


Expert Solution
Questions # 33:

Which component(s), if any, will Palo Alto Networks host and run when a customer purchases Prisma Cloud Enterprise Edition?

Options:

A.

Defenders


B.

Console


C.

Jenkins


D.

twistcli


Expert Solution
Questions # 34:

Which three types of runtime rules can be created? (Choose three.)

Options:

A.

Processes


B.

Network-outgoing


C.

Filesystem


D.

Kubernetes-audit


E.

Waas-request


Expert Solution
Questions # 35:

What are two ways to scan container images in Jenkins pipelines? (Choose two.)

Options:

A.

twistcli


B.

Jenkins Docker plugin


C.

Compute Jenkins plugin


D.

Compute Azure DevOps plugin


E.

Prisma Cloud Visual Studio Code plugin with Jenkins integration


Expert Solution
Questions # 36:

A customer has a requirement to terminate any Container from image topSecret:latest when a process named ransomWare is executed.

How should the administrator configure Prisma Cloud Compute to satisfy this requirement?

Options:

A.

set the Container model to manual relearn and set the default runtime rule to block for process protection.


B.

set the Container model to relearn and set the default runtime rule to prevent for process protection.


C.

add a new runtime policy targeted at a specific Container name, add ransomWare process into the denied process list, and set the action to “prevent”.


D.

choose “copy into rule” for the Container, add a ransomWare process into the denied process list, and set the action to “block”.


Expert Solution
Questions # 37:

What is an automatically correlated set of individual events generated by the firewall and runtime sensors to identify unfolding attacks?

Options:

A.

policy


B.

incident


C.

audit


D.

anomaly


Expert Solution
Questions # 38:

The compliance team needs to associate Prisma Cloud policies with compliance frameworks. Which option should the team select to perform this task?

Options:

A.

Custom Compliance


B.

Policies


C.

Compliance


D.

Alert Rules


Expert Solution
Questions # 39:

An administrator needs to detect and alert on any activities performed by a root account.

Which policy type should be used?

Options:

A.

config-run


B.

config-build


C.

network


D.

audit event


Expert Solution
Questions # 40:

Under which tactic is “Exploit Public-Facing Application” categorized in the ATT&CK framework?

Options:

A.

Defense Evasion


B.

Initial Access


C.

Execution


D.

Privilege Escalation


Expert Solution
Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions