Prisma Certified Cloud Security Engineer Free Sample Questions

20 free sample questions337 in the full practice test Other version: Cloud-Security-Professional(196)

Try simulator

PCCSE Sample Questions

  1. Question 1

    A financial services company has deployed Prisma Cloud to monitor its AWS environment. A security architect needs to create a custom policy to detect any S3 bucket that is publicly accessible but does NOT have a 'data-classification' tag with the value 'public'. Which RQL query correctly identifies these non-compliant S3 buckets?

    Answer and explanation

    Correct answer: C

    This RQL query correctly identifies the target resources. It uses the aws-s3-bucket-list API to get bucket configurations, checks if publicAccess is true, and then uses a logical OR to find buckets where the 'data-classification' tag is either not equal to 'public' or is not defined at all. This combination accurately captures the security requirement.

  2. Question 2

    A SecOps team is investigating a container runtime incident where an anomalous process, kdevtmpfsi, was detected and blocked by a Host Defender. To perform forensic analysis, the team needs to find the original container image that was used to launch the compromised container. Which Prisma Cloud feature provides the most direct path to identify the source image for a specific runtime event?

    Answer and explanation

    Correct answer: D

    The Incident Explorer is designed for this exact purpose. It correlates runtime audit events with the source entity. When viewing the details of the specific process anomaly incident, Prisma Cloud provides rich contextual information, including the container ID, the host it ran on, and most importantly, the full name and hash of the source image, which is crucial for forensic analysis.

  3. Question 3

    A DevOps team is using a Jenkins pipeline to build and push container images to a private registry. They need to configure a step that fails the build if the image contains any vulnerabilities with a CVSS score of 9.0 or higher, or if it uses a package with a non-compliant license such as GPL-3.0. Which twistcli command structure correctly implements these dual conditions?

    Answer and explanation

    Correct answer: C

    This command correctly uses two separate flags to control the failure thresholds. --vulnerability-threshold critical fails the build for vulnerabilities with a CVSS score of 9.0-10.0 (critical). --compliance-threshold high fails the build for compliance issues, such as non-approved licenses, that are rated as high severity or above. This combination precisely meets the stated requirements.

  4. Question 4

    A cloud administrator is configuring a Prisma Cloud Enterprise tenant and needs to integrate it with an external SAML 2.0 Identity Provider (IdP) for Single Sign-On (SSO). The IdP requires a unique identifier for the Service Provider (SP), which is Prisma Cloud in this case. Where in the Prisma Cloud console can the administrator find the 'Audience URI (SP Entity ID)' required by the IdP?

    Answer and explanation

    Correct answer: B

    When configuring SSO in Prisma Cloud, the required Service Provider (SP) metadata is generated and displayed directly in the user interface. The administrator must navigate to Settings > Enterprise Settings, select the SSO tab, and enable it. The 'Audience URI (SP Entity ID)' and other necessary values like the 'Assertion Consumer Service (ACS) URL' will be presented there to be copied into the IdP configuration.

  5. Question 5

    Multiple answers

    A security team is deploying Prisma Cloud WAAS to protect a web application running on a Kubernetes cluster. They want to prevent common injection attacks. Which of the following WAAS features should be configured to achieve this? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  6. Question 6

    True or False: When a Prisma Cloud Container Defender is deployed using a DaemonSet in a Kubernetes cluster, it automatically scales and protects new nodes as they are added to the cluster without manual intervention.

    Answer and explanation

    Correct answer: A

    This is the primary function of a Kubernetes DaemonSet. It ensures that all (or a subset of) nodes run a copy of a pod. When a new node is added to the cluster, the DaemonSet controller automatically schedules a Defender pod on that node, ensuring continuous security coverage as the cluster scales.

  7. Question 7

    A healthcare organization is using Prisma Cloud's Data Security module to discover and classify sensitive patient data in their AWS S3 buckets. After an initial scan, they find that many objects containing Protected Health Information (PHI) have been misclassified. They need to create a new, highly accurate data pattern for identifying National Provider Identifier (NPI) numbers, which are 10-digit numbers that may or may not have a checksum. What is the most effective way to improve classification accuracy for this specific data type?

    Answer and explanation

    Correct answer: B

    Prisma Cloud's Data Security module allows for the creation of custom data patterns to identify proprietary or specific data formats. Using a precise RegEx (e.g., \b\d{10}\b) to match the 10-digit structure, combined with proximity keywords, provides a highly accurate method for the classification engine to identify NPI numbers within files, significantly reducing false positives compared to generic patterns.

  8. Question 8

    A cloud security engineer needs to establish a network baseline for an application and then enforce a strict microsegmentation policy. The application consists of three tiers: a web front-end, an application logic tier, and a database tier, all running as separate services in a Kubernetes namespace. What is the correct sequence of steps using Prisma Cloud's Cloud Network Security (CNS) capabilities?

    Answer and explanation

    Correct answer: B

    This sequence follows the recommended best practice for implementing microsegmentation. First, Defenders must be deployed to collect network data. Second, the system observes actual traffic to understand legitimate communication patterns, which are visualized in the Radar. Third, Prisma Cloud can automatically generate policy recommendations based on this observed traffic. Finally, the engineer must review these recommendations, fine-tune them as needed (e.g., removing unnecessary connections), and then enforce them to lock down communication.

  9. Question 9

    A company has onboarded its AWS Organization to Prisma Cloud. A junior cloud engineer, who is part of a team that only manages the 'Staging' OU, needs access to view compliance findings for accounts within that OU. However, they must be prevented from seeing findings for the 'Production' OU. Which Prisma Cloud feature should be used to enforce this granular access control?

    Answer and explanation

    Correct answer: C

    Prisma Cloud's RBAC model allows administrators to create Account Groups, which can be defined based on criteria like AWS OUs, tags, or individual account IDs. By creating an Account Group for the 'Staging' OU and another for 'Production', a custom role can be created that grants permissions (e.g., 'Cloud Security Viewer') only on the 'Staging' Account Group. This effectively segments visibility and control within the platform.

  10. Question 10

    Multiple answers

    A security analyst is reviewing a high-priority alert in Prisma Cloud titled 'Anomalous Compute Provisioning Activity'. The alert indicates that an unusually high number of VMs were launched in a short period by an IAM user. The analyst needs to quickly assess the potential impact and gather more context. Which TWO actions within the alert details would be most effective for this initial investigation? (Select TWO)

    Answer and explanation

    Correct answers: A, C

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 533 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon