Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

PSE-PrismaCloud PSE Palo Alto Networks System Engineer Professional - Prisma Cloud Questions and Answers

Questions 4

What does Prisma Cloud execute to change public cloud infrastructure when autoremediation is enabled?

Options:

A.

local scripts to public cloud APIs

B.

remote function calls to host agents

C.

third-party integration tools

D.

public cloud CLI commands

Buy Now
Questions 5

When an on-premises NGFW (customer gateway) is used to connect to the Virtual Gateway, which two IKE profiles cannot be used? (Choose two.)

Options:

A.

Group2 / SHA-1 / AES-128-CBC / IKE-V1

B.

Group2 / SHA-1 / AES-128-GCM / IKE-V1

C.

Group14 / SHA-256 / AES-256-GCM / IKE-V1

D.

Group2 / SHA-1 / AES-128-CBC

E.

Group14 / SHA-256 / AES-256-CBC / IKE-V1

Buy Now
Questions 6

can you create a custom compliance standard in Prisma Public Cloud?

Options:

A.

Generate a new Compliance Report.

B.

Create compliance framework in a spreadsheet then import into Prisma Public Cloud.

C.

From Compliance tab, clone a default framework and customize.

D.

From Compliance tab > Compliance Standards, click "Add New."

Buy Now
Questions 7

Which two deployment methods are supported for Prisma Cloud Compute (PCC) container Defenders? (Choose two.)

Options:

A.

Azure SQL database instances

B.

Google Kubernetes Engine

C.

Oracle Functions service

D.

Kubernetes DaemonSet

Buy Now
Questions 8

What are two valid image identifiers to designate trust? (Choose two.)

Options:

A.

repo

B.

trusted publisher

C.

registry

D.

base layer

Buy Now
Questions 9

Match the logging service with its cloud provider.

Options:

Buy Now
Questions 10

The following error is received when performing a manual twistcli scan on an image:

What is missing from the command?

Options:

A.

registry path for image name

B.

password

C.

console address

D.

username

Buy Now
Questions 11

What happens in Prisma Cloud after Training Model Threshold or Alert Disposition is changed?

Options:

A.

Changes will take effect after a new learning phase of 30 days.

B.

System will perform a reboot, deleting all past alerts.

C.

Existing alerts and new alerts are regenerated based on the new setting.

D.

New alerts are generated based on the new setting.

Buy Now
Questions 12

Which option is defined by the creation and change of public cloud services managed in a repeatable and predictable fashion?

Options:

A.

platform as a service

B.

infrastructure as a service

C.

software as code

D.

infrastructure as code

Buy Now
Questions 13

In which two ways can Prisma Cloud Compute (PCC) edition be installed? (Choose two.)

Options:

A.

self-managed in a customer's own container platform

B.

self-contained hardware appliance

C.

as a stand-alone Windows application

D.

Cloud-hosted as part of a Prisma Cloud Enterprise tenant from Palo Alto Networks

Buy Now
Questions 14

What are two benefits of Cloud Security Posture Management (CSPM) over other solutions? (Choose two.)

Options:

A.

guaranteed proof of concept (POC) extensions beyond 30 days

B.

native integration of network, endpoint, and cloud data to stop attacks

C.

elimination of blind spots

D.

proactive addressing of risks

Buy Now
Questions 15

Prisma Public Cloud enables compliance monitoring and reporting by mapping which configurations to compliance standards?

Options:

A.

RQL queries

B.

alert rules

C.

notification templates

D.

policies

Buy Now
Questions 16

Which RQL string using network query attributes returns all traffic destined for Internet or for Suspicious IPs that also exceeds 1GB?

Options:

A.

network where publicnetwork = ('Internet IPs', 'Suspicious IPs') AND bytes > 1000000000

B.

network where dest publicnetwork IN ('Internet IPs', 'Suspicious IPs') AND bytes > 1000000000

C.

show traffic where destination.network = ('Internet IPs', 'Suspicious IPs') AND bytes > 1000000000

D.

network where bytes > 1GB and destination = 'Internet IPs' OR 'Suspicious IPs'

Buy Now
Questions 17

Which two statements are true about CloudFormation? (Choose two.)

Options:

A.

CloudFormation is a procedural configuration management tool.

B.

CloudFormation templates can be used on both Amazon Web Services and Microsoft Azure

C.

CloudFormation templates can be written in JSON or YAML

D.

CloudFormation is a declarative orchestration tool.

Buy Now
Questions 18

What is a permanent public IP called on Amazon Web Services?

Options:

A.

Reserved IP

B.

PIP

C.

EIP

D.

Floating IP

Buy Now
Questions 19

Which two cloud-native providers are supported by Prisma Cloud? (Choose two.)

Options:

A.

DigitalOcean

B.

Azure

C.

IBM Cloud

D.

Oracle Cloud

Buy Now
Questions 20

Which type of Resource Query Language (RQL) query is used to create a custom policy that looks for untagged resources?

Options:

A.

config

B.

alert

C.

event

D.

data

Buy Now
Questions 21

A client has a sensitive internet-facing application server in Microsoft Azure and is concerned about resource exhaustion because of distributed denial-of-service attacks What can be configured on the VM-Series firewall to specifically protect this server against this type of attack?

Options:

A.

Custom threat signature

B.

Zone Protection Profile

C.

QoS Profile to limit incoming requests

D.

DoS Protection Profile with specific session counts

Buy Now
Questions 22

Which RQL string searches for all EBS volumes that do not have a "DataClassification" tag?

Options:

A.

config where api.name = 'aws-ec2-describe-volumes, AND json.rule = tags[*]key contains DataClassification

B.

config where api.name = ,aws-ec2-describe-volumes' AND json.rule = tags[*]key != DataClassification

C.

config where api.name = ,aws-ec2-describe-volumes' AND json.rule = tags[*].key exists

D.

config where api.name = 'aws-ec2-describe-volumes' AND json.rule = tags[*].key = 1

Buy Now
Questions 23

What subcommand invokes the Prisma Cloud Compute (PCC) edition image scanner?

Options:

A.

> twistcli images scan

B.

> twistcli project scan

C.

> twistcli scan projects

D.

> twistcli scan images

Buy Now
Questions 24

Which Resource Query Language (RQL) query returns a list of all Azure SQL Databases that have transparent data encryption turned in?

Options:

A.

config from cloud.resource where api.name = 'gcloud-compute-instances-list' and json.rule = is TERMINATED

B.

config from cloud.resource where api.name = 'gcloud-compute-instances-list' = TERMINATED

C.

config from cloud.resource where api.name = 'gcloud-compute-instances-list* and json.rule == status TERMINATED

D.

config from cloud.resource where api.name = 'gcloud-compute-instances-list' and json.rule = status contains TERMINATED

Buy Now
Questions 25

All Amazon Regional Database Service (RDS)-deployed resources and the regions in which they are deployed can be identified by prisma Cloud using which two methods? (Choose two.)

Options:

A.

Configure an Inventory report from the "Alerts" tab.

B.

Write an RQL query from the "Investigate" tab.

C.

Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.

D.

Generate a compliance report from the Compliance dashboard.

Buy Now
Questions 26

What are two ways to initially deploy a VM-Series NGFW in Microsoft Azure? (Choose two.)

Options:

A.

through ARM Templates in the GitHub Repository

B.

through Solution Templates in the Azure Marketplace

C.

through Expedition in the Customer Success Portal

D.

through Iron Skillets in the GitHub Repository

Buy Now
Questions 27

Which pattern syntax will add all images to a trusted images rule within a registry?

Options:

A.

*.acme.com

B.

acme/*

C.

acme.com/myrepo/allimages:/*

D.

registry.acme.com/*

Buy Now
Questions 28

The customer has an Amazon Web Services Elastic Computing Cloud that provides a service to the internet directly and needs to secure that cloud with a VM-Series NGFW.

Which component handles address translation?

Options:

A.

The server VMs have private use only (RFC 1918) IPs. Amazon's cloud infrastructure translates those addresses to publicly accessible IP addresses. The VM-Series NGFW has publicly accessible IP addresses.

B.

The server VMs have private use only (RFC 1918) IPs. The VM-Series NGFW translates those addresses to publicly accessible IP addresses.

C.

The server VMs and the VM-Series NGFW have private use only (RFC 1918) IPs. Amazons cloud infrastructure translates those addresses to publicly accessible IP addresses

D.

The servers and VM-Series NGFW have publicly accessible IP addresses for management purposes.

Buy Now
Questions 29

An administrator deploys a VM-Series firewall into Amazon Web Services. Which attribute must be disabled on the data-plane elastic network interface for the instance to handle traffic that is not destined to its own IP address?

Options:

A.

security group

B.

tags

C.

elastic ip address

D.

source/destination checking

Buy Now
Questions 30

Which pillar of the Prisma Cloud platform can secure outbound traffic, stop lateral attack movement, and block inbound threats?

Options:

A.

Cloud Workload Protection (CWP)

B.

Cloud Code Security

C.

Cloud Network Security

D.

Cloud Identity Security

Buy Now
Questions 31

Amazon Web Services WAF can be enabled on which two resources?(Choose two.)

Options:

A.

AWS CDN

B.

AWS NAT Gateway

C.

AWS ALB

D.

AWS NLB

Buy Now
Questions 32

Which two template formats are supported by the Prisma Cloud infrastructure as code (laC) scan service? (Choose two.)

Options:

A.

ARM

B.

XML

C.

YAML

D.

JSON

Buy Now
Questions 33

Which pillar of the Prisma Cloud platform allows cloud entitlements to be quickly audited and secured?

Options:

A.

Cloud Security Posture Management

B.

Cloud Identity Security

C.

Cloud Network Security

D.

Cloud Code Security

Buy Now
Questions 34

How can you use Prisma Public Cloud to identify Amazon EC2 instances that have been tagged as "Private?

Options:

A.

Create an RQL config query to identify resources with the tag "Private."

B.

Create an RQL network query to identify traffic from resources tagged "Private."

C.

Open the Asset Dashboard, filter on tags: and choose "Private."

D.

Generate a CIS compliance report and review the "Asset Summary."

Buy Now
Exam Code: PSE-PrismaCloud
Exam Name: PSE Palo Alto Networks System Engineer Professional - Prisma Cloud
Last Update: Feb 22, 2025
Questions: 115
PSE-PrismaCloud pdf

PSE-PrismaCloud PDF

$25.5  $84.99
PSE-PrismaCloud Engine

PSE-PrismaCloud Testing Engine

$30  $99.99
PSE-PrismaCloud PDF + Engine

PSE-PrismaCloud PDF + Testing Engine

$40.5  $134.99