Weekend Special Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

PSE-PrismaCloud PSE Palo Alto Networks System Engineer Professional - Prisma Cloud Questions and Answers

Questions 4

How can you use Prisma Public Cloud to identify Amazon EC2 instances that have been tagged as "Private?

Options:

A.

Create an RQL config query to identify resources with the tag "Private."

B.

Create an RQL network query to identify traffic from resources tagged "Private."

C.

Open the Asset Dashboard, filter on tags: and choose "Private."

D.

Generate a CIS compliance report and review the "Asset Summary."

Buy Now
Questions 5

Match the logging service with its cloud provider.

Options:

Buy Now
Questions 6

Which type of Prisma Cloud Enterprise alert supports autoremediation?

Options:

A.

network

B.

audit

C.

anomaly

D.

config

Buy Now
Questions 7

How does Prisma Cloud Enterprise autoremediate unwanted violations to public cloud infrastructure?

Options:

A.

It inspects the application program interface (API) call made to public cloud and blocks the change if a policy violation is found.

B.

It makes changes after a policy violation has been identified in monitoring.

C.

It locks all changes to public cloud infrastructure and stops any configuration changes without prior approval.

D.

It uses machine learning (ML) to identify unusual changes to infrastructure.

Buy Now
Questions 8

Which statement explains the correlation between the block and alert thresholds in a vulnerability management policy?

Options:

A.

The thresholds can be set to informational, low, medium, high, and critical.

B.

The alert threshold always has precedence over, and can be greater than, the block threshold.

C.

The block threshold must always be equal to or greater than the alert threshold.

D.

The block threshold always has precedence over, and can be less than, the alert threshold.

Buy Now
Questions 9

How can a range of dates in the Prisma Cloud default policy be modified?

Options:

A.

Clone the existing policy and change the value.

B.

Click the gear icon next to the policy name to open the "Edit Policy" dialog.

C.

Manually create the Resource Query Language (RQL) statement.

D.

Override the value and commit the configuration.

Buy Now
Questions 10

Which type of alert captures unusual user activity and excessive login failures?

Options:

A.

Anomaly

B.

Audit Event

C.

Configuration

D.

Network

Buy Now
Questions 11

What is a permanent public IP called on Amazon Web Services?

Options:

A.

Reserved IP

B.

PIP

C.

EIP

D.

Floating IP

Buy Now
Questions 12

What does Prisma Cloud execute to change public cloud infrastructure when autoremediation is enabled?

Options:

A.

local scripts to public cloud APIs

B.

remote function calls to host agents

C.

third-party integration tools

D.

public cloud CLI commands

Buy Now
Questions 13

Which Amazon Web Services security service can provide host vulnerability information to Prisma Public Cloud?

Options:

A.

Shield

B.

Inspector

C.

GuardDuty

D.

Amazon Web Services WAF

Buy Now
Questions 14

Which statement applies to vulnerability management policies?

Options:

A.

Host and serverless rules support blocking, whereas container rules do not.

B.

Rules explain the necessary actions when vulnerabilities are found in the resources of a customer environment.

C.

Policies for containers, hosts, and serverless functions are not separate.

D.

Rules are evaluated in an undefined order.

Buy Now
Questions 15

Which change represents a VM-Series NGFW license transfer?

Options:

A.

VM-100 BYOL on Microsoft Azure to VM-100 BYOL on Amazon Web Services

B.

VM-300 BYOL on Microsoft Azure to VM-300 PAY6 on Amazon Web Services

C.

VM-100 BYOL on Microsoft Azure to VM-300 BYOL on Microsoft Azure

D.

VM-100 BYOL on Microsoft Azure to VM-300 PAYG on Amazon Web Services

Buy Now
Questions 16

What is the default capacity license of a VM-Series NGFW being deployed from the Google Cloud Platform Marketplace?

Options:

A.

VM-GCP

B.

VM-100

C.

VM-500

D.

VM-300

Buy Now
Questions 17

Which three features are not supported by VM-Series NGFWs on Azure Stack? (Choose three.)

Options:

A.

Azure Application Insight

B.

Resource Group

C.

Azure Security Center

D.

Bootstrapping

E.

ARM Template

Buy Now
Questions 18

An image containing medium vulnerabilities that do not have available fixes is being deployed into the sock-shop namespace. Prisma Cloud has been configured for vulnerability management within the organization's continuous integration (CI) tool and registry.

What will occur during the attempt to deploy this image from the CI tool into the sock-shop namespace?

Options:

A.

The image will pass the CI policy, but will be blocked by the deployed policy; therefore, it will not be deployed.

B.

The CI policy will fail the build; therefore, the image will not be deployed.

C.

The image will be deployed successfully, and all vulnerabilities will be reported.

D.

The image will be deployed successfully, but no vulnerabilities will be reported.

Buy Now
Questions 19

How can all alerts related to "Amazon RDS" be quickly identified within the Prisma Cloud dashboard?

Options:

A.

Generate a Center for Internet Security (CIS) compliance report and search for "Amazon RDS" policy violations.

B.

View the alert data on the "Asset Inventory" dashboard and filter on "Amazon RDS.

C.

Within the "Alerts" tab. filter on "Amazon RDS" as a service.

D.

Create a custom Resource Query Language (RQL) configuration report.

Buy Now
Questions 20

Which two types of Resource Query Language (RQL) queries can be used to create policies? (Choose two.)

Options:

A.

hose from

B.

network from

C.

system from

D.

event from

Buy Now
Questions 21

The following error is received when performing a manual twistcli scan on an image:

What is missing from the command?

Options:

A.

registry path for image name

B.

password

C.

console address

D.

username

Buy Now
Questions 22

What is required for an EC2 instance to access the internet directly from an AWS VPC?

Options:

A.

Internet Gateway

B.

Transit Gateway

C.

Virtual Private Gateway

D.

Customer Gateway

Buy Now
Questions 23

Which three types of security checks can Prisma Public Cloud perform? (Choose three.)

Options:

A.

compliance where

B.

network where

C.

user where

D.

config where

E.

event where

Buy Now
Questions 24

What happens in Prisma Cloud after Training Model Threshold or Alert Disposition is changed?

Options:

A.

Changes will take effect after a new learning phase of 30 days.

B.

System will perform a reboot, deleting all past alerts.

C.

Existing alerts and new alerts are regenerated based on the new setting.

D.

New alerts are generated based on the new setting.

Buy Now
Questions 25

Which RQL string returns a list of all Azure virtual machines that are not currently running?

Options:

A.

config where api.name = 'azure-vm-list' AND json.rule = powerState = "off'

B.

config where api.name = 'azure-vm-list' AND json.rule = powerState does not contain "running"

C.

config where api.name = 'azure-vm-list' AND json.rule = powerState = "running"

D.

config where api.name = 'azure-vm-list' AND json.rule = powerState contains "running"

Buy Now
Questions 26

All Amazon Regional Database Service (RDS)-deployed resources and the regions in which they are deployed can be identified by prisma Cloud using which two methods? (Choose two.)

Options:

A.

Configure an Inventory report from the "Alerts" tab.

B.

Write an RQL query from the "Investigate" tab.

C.

Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.

D.

Generate a compliance report from the Compliance dashboard.

Buy Now
Questions 27

Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?

Options:

A.

Create alert rules.

B.

Whitelist IP addresses.

C.

Configure User-ID.

D.

Define enterprise settings.

Buy Now
Questions 28

Which pattern syntax will add all images to a trusted images rule within a registry?

Options:

A.

*.acme.com

B.

acme/*

C.

acme.com/myrepo/allimages:/*

D.

registry.acme.com/*

Buy Now
Questions 29

Based on the diagram, how many routes will the virtual gateway advertise to the on-premises NGFW over the Amazon Web Services Direct Connect link?

Options:

A.

4

B.

5

C.

3

D.

1

Buy Now
Questions 30

Which three services can Google Cloud Security Scanner assess? (Choose three.)

Options:

A.

Google Kubernetes Engine

B.

BigQuery

C.

Compute Engine

D.

App Engine

E.

Google Virtual Private Cloud

Buy Now
Questions 31

Which cloud provider supports iLB-as-next-hop?

Options:

A.

Microsoft Azure

B.

Alibaba Cloud

C.

Oracle Cloud

D.

Amazon Web Services

Buy Now
Questions 32

What are three examples of outbound traffic flow? (Choose three.)

Options:

A.

issue yum update command on an instance inside Amazon Web Services

B.

Microsoft Windows inside Azure requesting a security patch

C.

web server inside Amazon Web Services receiving web requests from internet

D.

issue apt-get install command on an instance inside Amazon Web Services

E.

outgoing Prisma Public Cloud API calls

Buy Now
Questions 33

What are two ways to initially deploy a VM-Series NGFW in Microsoft Azure? (Choose two.)

Options:

A.

through ARM Templates in the GitHub Repository

B.

through Solution Templates in the Azure Marketplace

C.

through Expedition in the Customer Success Portal

D.

through Iron Skillets in the GitHub Repository

Buy Now
Questions 34

What are two valid image identifiers to designate trust? (Choose two.)

Options:

A.

repo

B.

trusted publisher

C.

registry

D.

base layer

Buy Now
Exam Code: PSE-PrismaCloud
Exam Name: PSE Palo Alto Networks System Engineer Professional - Prisma Cloud
Last Update: Feb 22, 2025
Questions: 115
PSE-PrismaCloud pdf

PSE-PrismaCloud PDF

$25.5  $84.99
PSE-PrismaCloud Engine

PSE-PrismaCloud Testing Engine

$30  $99.99
PSE-PrismaCloud PDF + Engine

PSE-PrismaCloud PDF + Testing Engine

$40.5  $134.99