Palo Alto Networks Systems Engineer Professional - Prisma Cloud Free Sample Questions

20 free sample questions269 in the full practice test

Try simulator

PSE-PRISMA Sample Questions

  1. Question 1

    A financial services firm is using Prisma Cloud to monitor its AWS environment. A security administrator needs to create a policy that alerts whenever an S3 bucket is created without server-side encryption enabled. The policy must also provide a one-click remediation option for the security operations team. Which type of policy and remediation approach should be configured?

    Answer and explanation

    Correct answer: B

    Config policies are used to assess resource configurations against security best practices. Prisma Cloud provides built-in RQL templates for common misconfigurations like unencrypted S3 buckets. Marking the policy as 'Remediable' and using a supported remediation command allows for one-click fixes directly from the alert.

  2. Question 2

    A DevOps team is deploying containerized applications on a self-managed Kubernetes cluster. To enforce runtime security, they have deployed Prisma Cloud Defenders as a DaemonSet. During a security review, an analyst observes that Defenders are not reporting any runtime events for a specific node in the cluster. All other nodes are reporting correctly. What is the MOST likely cause of this issue?

    Answer and explanation

    Correct answer: C

    In Kubernetes, taints are applied to nodes to repel pods, while tolerations are applied to pods to allow them to be scheduled on nodes with matching taints. If a node has a specific taint (e.g., for GPU resources or a specific role), and the Defender DaemonSet manifest does not include a corresponding toleration, the Kubernetes scheduler will not place a Defender pod on that node, resulting in a lack of visibility and event reporting.

  3. Question 3

    Multiple answers

    A company is using Prisma Cloud's CI/CD scanning capabilities to identify vulnerabilities in their application code before deployment. They want to ensure that any third-party libraries with high-severity vulnerabilities or restrictive licenses (e.g., GPL) are flagged. Which two features within the Application Security module should they primarily use? (Select TWO).

    Answer and explanation

    Correct answers: A, C

    Software Composition Analysis (SCA) is the specific feature designed to scan application dependencies and third-party libraries for known vulnerabilities (CVEs) and to identify their software licenses.

    CI/CD Posture Management provides the framework to define policies for vulnerabilities and license compliance within the CI/CD pipeline. It allows setting thresholds (e.g., fail build on high-severity CVEs or GPL licenses) that are enforced by the SCA scanner.

  4. Question 4

    A security architect is designing a threat detection strategy for a multi-cloud environment using Prisma Cloud. The primary goal is to identify anomalous user behavior, such as an administrator accessing resources from an unusual location or at an odd time. Which Prisma Cloud capability directly addresses this requirement by leveraging machine learning?

    Answer and explanation

    Correct answer: B

    Prisma Cloud's User and Entity Behavior Analytics (UEBA) capability uses machine learning algorithms to baseline normal user and service account activity. It then detects deviations from this baseline, such as unusual login times, locations, or resource access patterns, and generates anomaly alerts for potential threats.

  5. Question 5

    True or False: In Prisma Cloud, a single Defender can be used to protect containers, hosts, and serverless functions simultaneously if they are all running on the same underlying host machine.

    Answer and explanation

    Correct answer: B

    False. While a single Host Defender can protect both the host OS and the containers running on it, protecting serverless functions requires a specific Serverless Defender that is embedded directly into the function's code package. The deployment and protection models are distinct for each workload type.

  6. Question 6

    A SOC analyst is investigating a Prisma Cloud alert indicating that an EC2 instance is communicating with a known malicious IP address. To understand the context of this event, the analyst needs to determine what other internal and external systems the compromised instance has communicated with over the past 7 days. Which feature in Prisma Cloud provides this network-level visibility?

    Answer and explanation

    Correct answer: C

    The Investigate tab allows for ad-hoc querying of cloud data using RQL. A Network RQL query can filter on the specific EC2 instance and time range to visualize all ingress and egress network traffic flows, showing exactly which internal and external entities it communicated with. This is a primary tool for network forensics and incident investigation.

  7. Question 7

    Case Study

    A large e-commerce company, GlobalRetail, has fully migrated to a multi-cloud environment, using both AWS and Azure for their main application platform. The platform is built on Kubernetes (EKS in AWS, AKS in Azure) and uses various PaaS services like RDS, S3, and Azure Blob Storage. The CISO has mandated a unified security strategy that provides consistent visibility, compliance enforcement, and runtime protection across both clouds from a single console.

    The key requirements are:

    1. Enforce PCI DSS 4.0 compliance across all cloud resources.
    2. Scan all container images for critical vulnerabilities in their CI/CD pipeline before they are pushed to the registry.
    3. Protect the production Kubernetes applications against zero-day exploits and anomalous network connections.
    4. Discover and classify any credit card numbers accidentally stored in S3 or Blob storage.

    Which combination of Prisma Cloud modules offers the most comprehensive solution to meet all of GlobalRetail's requirements?

    Answer and explanation

    Correct answer: A

    This option correctly maps each requirement to the specific Prisma Cloud module designed to address it: CSPM for compliance standards like PCI DSS (Req 1), CWP for both shift-left image scanning and runtime protection (Req 2 & 3), and Data Security for discovering and classifying sensitive data in cloud storage (Req 4). This represents a complete, integrated solution.

  8. Question 8

    A security team needs to create a Prisma Cloud RQL query to find all publicly accessible virtual machines in their GCP project that are also tagged with 'Project: Phoenix'. Which RQL query correctly implements this logic?

    Answer and explanation

    Correct answer: D

    This RQL query correctly identifies the resource type via the API name (gcloud-compute-instances-list). It then uses json.rule to filter for instances with a public IP (type equals ONE_TO_ONE_NAT). Finally, it uses the AND operator to combine this with a filter for the specific label (labels.Project equals Phoenix), ensuring both conditions must be met.

  9. Question 9

    The command twistcli hosts scan --address --user --password is used to scan what type of asset for vulnerabilities?

    Answer and explanation

    Correct answer: B

    The twistcli hosts scan command is specifically designed to perform a vulnerability and compliance scan of the host operating system (Linux or Windows) on which the twistcli binary is executed. The results are then sent to the specified Prisma Cloud Console.

  10. Question 10

    A cloud administrator is configuring data source ingestion for their Prisma Cloud tenant. They want to ingest AWS CloudTrail logs to enable threat detection and anomaly policies. What is the recommended and most secure method for Prisma Cloud to gain the necessary access to these logs?

    Answer and explanation

    Correct answer: B

    Using a cross-account IAM role with an external ID is the AWS-recommended best practice for granting third-party services like Prisma Cloud access to your resources. It avoids the use of long-lived credentials (access keys) and mitigates the 'confused deputy' problem by ensuring that only Prisma Cloud can assume the role.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 269 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon