Pass the Paloalto Networks Cloud Security Engineer PCCSE Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

One of the resources on the network has triggered an alert for a Default Config policy.

Given the following resource JSON snippet:

Which RQL detected the vulnerability?

A)

Question # 41

B)

C)

D)

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 42:

Which ban for DoS protection will enforce a rate limit for users who are unable to post five (5) “. tar.gz" files within five (5) seconds?

Options:

A.

One with an average rate of 5 and file extensions match on “. tar.gz" on Web Application and API Security (WAAS)


B.

One with an average rate of 5 and file extensions match on “. tar.gz" on Cloud Native Network Firewall (CNNF)


C.

One with a burst rate of 5 and file extensions match on “. tar.gz" on Web Application and API Security (WAAS) *


D.

One with a burst rate of 5 and file extensions match on “. tar.gz" on Cloud Native Network Firewall (CNNF)


Expert Solution
Questions # 43:

Where are Top Critical CVEs for deployed images found?

Options:

A.

Defend → Vulnerabilities → Code Repositories


B.

Defend → Vulnerabilities → Images


C.

Monitor → Vulnerabilities → Vulnerabilities Explorer


D.

Monitor → Vulnerabilities → Images


Expert Solution
Questions # 44:

The exclamation mark on the resource explorer page would represent?

Options:

A.

resource has been deleted


B.

the resource was modified recently


C.

resource has alerts


D.

resource has compliance violation


Expert Solution
Questions # 45:

Which IAM RQL query would correctly generate an output to view users who enabled console access with both access keys and passwords?

Options:

A.

config from network where api.name = ‘aws-iam-get-credential-report’ AND json.rule = cert_1_active is true or cert_2_active is true and password_enabled equals "true"


B.

config from cloud.resource where api.name = 'aws-iam-get-credential-report' AND json.rule = access_key_1_active is true or access_key_2_active is true and password_enabled equals "true"


C.

config from cloud.resource where api.name = 'aws-iam-get-credential-report’ AND json.rule = access_key_1_active is false or access_key_2_active is true and password_enabled equals "*"


D.

config where api.name = ‘aws-iam-get-credential-report' AND json.rule= access_key_1_active is true or access_key_2_active is true and password_enabled equals “true”


Expert Solution
Questions # 46:

Which two integrated development environment (IDE) plugins are supported by Prisma Cloud as part of its Code Security? (Choose two.)

Options:

A.

Visual Studio Code


B.

IntelliJ


C.

BitBucket


D.

CircleCI


Expert Solution
Questions # 47:

Which policy type should be used to detect and alert on cryptominer network activity?

Options:

A.

Audit event


B.

Anomaly


C.

Config-build


D.

Config-run


Expert Solution
Questions # 48:

Put the steps involved to configure and scan using the IntelliJ plugin in the correct order.

Question # 48


Expert Solution
Questions # 49:

An administrator of Prisma Cloud wants to enable role-based access control for Docker engine.

Which configuration step is needed first to accomplish this task?

Options:

A.

Configure Docker’s authentication sequence to first use an identity provider and then Console.


B.

Set Defender’s listener type to TCP.


C.

Set Docker’s listener type to TCP.


D.

Configure Defender’s authentication sequence to first use an identity provider and then Console.


Expert Solution
Questions # 50:

Which of the following is not a supported external integration for receiving Prisma Cloud Code Security notifications?

Options:

A.

Splunk


B.

Cortex XSOAR


C.

Microsoft Teams


D.

ServiceNow


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions