Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

PSE-PrismaCloud PSE Palo Alto Networks System Engineer Professional - Prisma Cloud Questions and Answers

Questions 4

Where can rules be configured and viewed to configure trusted images?

Options:

A.

Monitor > Compliance > Trusted Images

B.

Monitor > Compliance > Images

C.

Defend > Compliance > Trusted Images

D.

Defend > Compliance > Images

Buy Now
Questions 5

What are two ways to initially deploy a VM-Series NGFW in Microsoft Azure? (Choose two.)

Options:

A.

through ARM Templates in the GitHub Repository

B.

through Solution Templates in the Azure Marketplace

C.

through Expedition in the Customer Success Portal

D.

through Iron Skillets in the GitHub Repository

Buy Now
Questions 6

How does Prisma Cloud Enterprise autoremediate unwanted violations to public cloud infrastructure?

Options:

A.

It inspects the application program interface (API) call made to public cloud and blocks the change if a policy violation is found.

B.

It makes changes after a policy violation has been identified in monitoring.

C.

It locks all changes to public cloud infrastructure and stops any configuration changes without prior approval.

D.

It uses machine learning (ML) to identify unusual changes to infrastructure.

Buy Now
Questions 7

Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?

Options:

A.

Create alert rules.

B.

Whitelist IP addresses.

C.

Configure User-ID.

D.

Define enterprise settings.

Questions 8

What is a permanent public IP called on Amazon Web Services?

Options:

A.

Reserved IP

B.

PIP

C.

EIP

D.

Floating IP

Buy Now
Questions 9

Which two resource types are included in the Prisma Cloud Enterprise licensing count? (Choose two.)

Options:

A.

Elastic Compute Cloud (EC2) instances

B.

Network Address Translation (NAT) gateways

C.

CloudFront distributions

D.

Security groups

Buy Now
Questions 10

How can a range of dates in the Prisma Cloud default policy be modified?

Options:

A.

Clone the existing policy and change the value.

B.

Click the gear icon next to the policy name to open the "Edit Policy" dialog.

C.

Manually create the Resource Query Language (RQL) statement.

D.

Override the value and commit the configuration.

Buy Now
Questions 11

Prevention against which type of attack is configurable in Web-Application and API Security (WAAS)?

Options:

A.

credential stuffing

B.

cross-site scripting (XSS)

C.

shoulder surfing

D.

distributed denial of service (DDoS)

Buy Now
Questions 12

A customer CSO has asked you to demonstrate how to identify all "Amazon RDS" resources deployed and the region that they are deployed in. What are two ways that Prisma Public Cloud can show the relevant information?(Choose two.)

Options:

A.

Generate a compliance report from the Compliance dashboard

B.

Write an RQL query from the "Investigate" tab.

C.

Configure an Inventory report from the "Alerts" tab

D.

Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.

Buy Now
Questions 13

Under which operating systems (OSs) is twistcli supported?

Options:

A.

Linux, macOS, and Windows

B.

Windows only

C.

Linux and Windows

D.

Linux, macOS, PAN-OS, and Windows

Buy Now
Questions 14

When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW Vulnerability Protection Profiles?

Options:

A.

Use the default Vulnerability Protection Profile to protect clients from all known critical, high, and medium-severity threats

B.

Clone the predefined Strict Profile, with packet capture settings disabled

C.

Use the default Vulnerability Protection Profile to protect servers from all known critical, high, and medium-severity threats

D.

Clone the predefined Strict Profile, with packet capture settings enabled

Buy Now
Questions 15

Which statement applies to optimization of registry scans with version pattern matching?

Options:

A.

It requires Linux images to rely on optimizing registry scans due to various Linux elements.

B.

It is only necessary in registries with tens of thousands of repositories and millions of images.

C.

It is best practice to always optimize registry scans for faster results.

D.

It is rarely successful in the Windows Operating System (OS).

Buy Now
Questions 16

What are two benefits of Cloud Security Posture Management (CSPM) over other solutions? (Choose two.)

Options:

A.

guaranteed proof of concept (POC) extensions beyond 30 days

B.

native integration of network, endpoint, and cloud data to stop attacks

C.

elimination of blind spots

D.

proactive addressing of risks

Buy Now
Questions 17

Which two cloud providers support Load Balancers as next hop configurations for outbound connections? (Choose two.)

Options:

A.

Google Cloud Platform

B.

Microsoft Azure

C.

Oracle Cloud

D.

Amazon Web Services

Buy Now
Questions 18

Which three requirements are needed to register a PAYG VM-Series NGFW at the Palo Alto Networks Customer Support website? (Choose three.)

Options:

A.

Serial Number

B.

CPU ID

C.

Auth Code

D.

License Key

E.

UUID

Buy Now
Questions 19

What are two business values of Cloud Code Security? (Choose two.)

Options:

A.

consistent controls from build time to runtime

B.

prebuilt and customizable polices to detect data such as personally identifiable information (PII) in publicly exposed objects

C.

support for multiple languages, runtimes and frameworks

D.

continuous monitoring of all could resources for vulnerabilities, misconfigurations, and other threats

Buy Now
Questions 20

Based on the diagram, prioritize the order in which the Virtual Gateway evaluates the best route based on the deterministic B6P Path selection process.

Options:

Buy Now
Questions 21

All Amazon Regional Database Service (RDS)-deployed resources and the regions in which they are deployed can be identified by prisma Cloud using which two methods? (Choose two.)

Options:

A.

Configure an Inventory report from the "Alerts" tab.

B.

Write an RQL query from the "Investigate" tab.

C.

Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.

D.

Generate a compliance report from the Compliance dashboard.

Buy Now
Questions 22

Which two templates are supported by Cloud Code Security scan service? (Choose two.)

Options:

A.

Azure Resource Manager (ARM)

B.

Hyper Text Markup Language (HTML)

C.

GitHub

D.

Terraform

Buy Now
Questions 23

Which Resource Query Language (RQL) query monitors all "delete" activities for the user "user1"?

Options:

A.

event where crud = 'delete’ AND subject = 'user1'

B.

event where crud = 'delete'

C.

event where crud = 'delete' AND subject = 'user1' AND cloud.type = 'aws'

D.

event where subject = 'user1'

Buy Now
Questions 24

An Azure VNet has the IP network 10.0.0.0/16 with two subnets, 10.0.1.0/24 (used for web servers) and 10.0.2.0/24 (used for database servers). Which is a valid IP address to manage the VM-Series NGFW?

Options:

A.

10.0.1.254

B.

10.0.2.1

C.

10.0.3.255

D.

10.0.3.1

Buy Now
Questions 25

Which statement applies to vulnerability management policies?

Options:

A.

Host and serverless rules support blocking, whereas container rules do not.

B.

Rules explain the necessary actions when vulnerabilities are found in the resources of a customer environment.

C.

Policies for containers, hosts, and serverless functions are not separate.

D.

Rules are evaluated in an undefined order.

Buy Now
Questions 26

Which two resources provide operational insight within the Prisma Cloud Asset Inventory? (Choose two.)

Options:

A.

Cortex Data Lake

B.

Cloud Storage buckets

C.

Prisma Access Gateways

D.

Compute Engine instance

Buy Now
Questions 27

Which statement explains the correlation between the block and alert thresholds in a vulnerability management policy?

Options:

A.

The thresholds can be set to informational, low, medium, high, and critical.

B.

The alert threshold always has precedence over, and can be greater than, the block threshold.

C.

The block threshold must always be equal to or greater than the alert threshold.

D.

The block threshold always has precedence over, and can be less than, the alert threshold.

Buy Now
Questions 28

Which two cloud providers provide egress load balancing? (Choose two.)

Options:

A.

Microsoft Azure

B.

Alibaba Cloud

C.

Amazon Web Services

D.

Oracle Cloud

Buy Now
Questions 29

What are two ways to enable interface swap when deploying a VM-Series NGFW in Google Cloud Platform? (Choose two.)

Options:

A.

run the PAN-OS CLI command: set system mgmt-interface-swap enable yes

B.

run the PAN-OS CLI command: set system mgmt-interface-swap setting enable yes

C.

create a bootstrap file that includes the mgmt-interface-swap command

D.

in the Google Cloud Console Metadata Field, enter a key-value pair where mgmt-interface-swap is the key and enable is the value

Questions 30

Match the query type with its corresponding search

Options:

Buy Now
Questions 31

In which two ways can Prisma Cloud Compute (PCC) edition be installed? (Choose two.)

Options:

A.

self-managed in a customer's own container platform

B.

self-contained hardware appliance

C.

as a stand-alone Windows application

D.

Cloud-hosted as part of a Prisma Cloud Enterprise tenant from Palo Alto Networks

Buy Now
Questions 32

Which two data sources are ingested by Prisma Cloud? (Choose two.)

Options:

A.

network flow logs

B.

list of all database instances' tables

C.

metadata about compute resources' configuration

D.

Cortex Data Lake

Buy Now
Questions 33

Which type of Resource Query Language (RQL) query is used to create a custom policy that looks for untagged resources?

Options:

A.

config

B.

alert

C.

event

D.

data

Buy Now
Questions 34

Which pattern syntax will add all images to a trusted images rule within a registry?

Options:

A.

*.acme.com

B.

acme/*

C.

acme.com/myrepo/allimages:/*

D.

registry.acme.com/*

Buy Now
Exam Code: PSE-PrismaCloud
Exam Name: PSE Palo Alto Networks System Engineer Professional - Prisma Cloud
Last Update: Feb 22, 2025
Questions: 115

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99