CLOUDSEC-PRO: Palo Alto Networks Certified Cloud S… Practice Exam
QuestionQ1
Cortex Fundamentals
Save question
A threat-intelligence team determines that IP addresses associated with brute-force attacks against the VPN gateways have historical links to a ransomware campaign.
Which two Cortex features can be configured to trigger alerts for malicious objects and for specified system processes associated with the threat actors’ tactics, techniques, and procedures (TTPs)?
Choose two
AExternal dynamic list
BSecurity event anomaly
CBehavioral indicator of compromise (BIOC)
DIndicator of compromise (IOC)
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Cloud Runtime Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Security Operations Center (SOC) Fundamentals
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Application Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ6
Security Operations Center (SOC) Fundamentals
0
Community Discussion
No comments yet. Be the first to start the discussion!
That's the end of the preview
It's free
100% of the questions are free for all users. No strings attached.
A DevSecOps team needs CVE visibility in developer code repositories, whereas the cloud security team needs CVE visibility in developer applications at runtime.
Which Cortex Cloud capability is unique to the cloud security team’s requirement?
AStatic application security testing (SAST)
BVulnerability management
CCode to Cloud
DSoftware composition analysis (SCA)
Which operational status identifies all endpoints whose agents are not functioning properly because of insufficient resources?
AUnprotected
BNot Protected
CLimited Protection
DLocal Resource Impact
Which two methods are used to initiate pull request scans?
Choose two
ABy version control system (VCS) event trigger
BAutomatically at set intervals
CUsing webhooks
DManually using “scan now”
Which concept proactively improves internal incident-response and incident-management processes against known threats?
AThreat intelligence
BSecurity Information and Event Management (SIEM)
CUser and Entity Behavior Analytics (UEBA)
DEndpoint detection and response (EDR)
QuestionQ7
Cortex Fundamentals
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ8
Application Security
QuestionQ9
Cloud Runtime Security
QuestionQ10
Application Security
QuestionQ11
Cortex Fundamentals
QuestionQ12
Cloud Posture Security
QuestionQ13
Cloud Runtime Security
QuestionQ14
Cloud Posture Security
QuestionQ15
Cloud Posture Security
QuestionQ16
Application Security
QuestionQ17
Cloud Posture Security
QuestionQ18
Cloud Posture Security
QuestionQ19
Cloud Runtime Security
QuestionQ20
Cloud Runtime Security
QuestionQ21
Security Operations Center (SOC) Fundamentals
QuestionQ22
Security Operations Center (SOC) Fundamentals
QuestionQ23
Application Security
QuestionQ25
Cloud Runtime Security
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A security engineer must transfer dashboard configurations among the company’s Cortex Cloud environments for its Asia, Europe, and North America divisions to streamline onboarding.
Which condition would stop this action?
ADashboards are based on custom infrastructure.
BDashboards are in JSON format.
CPredefined dashboards cannot be exported.
DDashboards include XQL widgets.
In which location of the Inventory menu under Endpoints can Web Application and API Security (WAAS) profiles be configured?
APrevention
BCloud Workload Rules
CRule Groups
DSettings
A user sees new Amazon EKS cluster endpoints connected to the Cortex Cloud console and wants to examine the Cortex XDR agent YAML file used for deployment.
Where can the user locate this file?
AData Sources
BHost Inventory
CInstallations
DHost Firewalls
A developer creates a serverless application that extracts a field from a file in an S3 bucket. The Lambda function has the S3FullAccess managed policy assigned.
Refer to the scenario to answer this question:
The serverless function fails to sanitize its inputs, allowing code injection. As a result, malware is downloaded by a backend API server that is supposed to receive the API key from the function.
Which two capabilities could the API server use to detect the malware?
Choose two
ACloud Security Posture Management (CSPM)
BAttack surface
CCloud Detection and Response (CDR)
DAgentless disk scanning
When creating a customer chatbot to help them understand their spending habits, which datasets can Cortex Cloud help protect when they are used to locate customer transactions and deliver contextually accurate answers?
AModel
BTraining
CInference
DNatural language processing
A company has an Amazon S3 bucket that contains personally identifiable information (PII) and must determine whether the resource has any misconfigurations or is publicly exposed.
Based on the image below, which data source type should be investigated?
AAmazon Web Services (AWS)
BAmazon CloudWatch
CAmazon S3
DMicrosoft Azure
How can a user identify how many applications are affected by a particular vulnerability and determine whether an endpoint agent is installed?
ABy viewing the Top Risky Vulnerabilities widget and filtering for the CVE
BBrowsing to the host inventory and viewing the vulnerabilities under Host Insights
CBy creating an asset group and a Cloud Security Assessment report
DBy creating an endpoint group and saving it as an agent management report
A customer that has a large cloud environment must conduct a vulnerability assessment. In this situation, the customer is not authorized to install agents but owns the cloud environments.
Which capability satisfies the customer’s requirements?
ACortex Agent for Cloud
BAgentless discovery engine
CCortex VM Broker
DAgentless disk scanning
A company experiences a costly ransomware incident in its Azure infrastructure after an employee is phished while using an unpatched personal computer to download company bank statements.
Which two Cloud Security Management modules are best able to mitigate these incidents and help the company strengthen its security posture?
Choose two
AVulnerability security
BData security
CApplication security
DIdentity security
An administrator finds that certain text files in the company GitHub repository are not scanned for secrets. Further inspection shows that the unscanned files were encrypted with AES-256.
What action is required to ensure the files are scanned for secrets?
AConnect the key management service as a data source.
BUpload the decrypting certificate to the portal.
CDecrypt the non-scanned files back to plaintext.
DUpload the PGP private key to GitHub.
A company receives a critical vulnerability finding with a CVSS score of 10 on a workload that has been virtually patched using a WAF. The security team must track the issue appropriately based on the risk to the company environment and in alignment with its risk-management approach.
Which action can the security team take in Cortex Cloud?
AFail builds containing the vulnerability in CI/CD pipelines.
BRecast the CVSS score and vulnerability severity.
CTag the vulnerability as “Ignored”.
DEnsure the issue is sent to the SOC for analysis.
A company using Cortex Cloud Data Security Posture Management (DSPM) has issues caused by insufficient secure controls on its Amazon S3 buckets. An administrator wants to investigate S3 buckets in the XQL editor but cannot view any data in the Cortex Cloud console.
How can the administrator make sure that data is being ingested?
AInstall the DSPM module into the cloud environment.
BInstall the Cortex XDR agent for cloud on the S3 buckets.
CVerify that S3 is added as a data source.
DVerify that the data source is properly onboarded.
Based on the Path to Runtime tab in Application Security Posture Management (ASPM), how are ingested code repositories linked to deployed cloud assets?
ABy applying infrastructure as code (IaC) tags
BBy directly linking through the Network Transporter
CBy enabling the Cortex Cloud DevSecOps bot
DBy creating custom networking in the cloud service provider (CSP)
Which lightweight solution provides runtime visibility into an OpenShift cluster?
ACortex XDR for Cloud
BData broker
CAgentless disk scanning
DKubernetes Connector
A company’s SOC and network security teams work independently, but the CISO has directed them to collaborate more closely because insufficient cross-team coordination causes problems. Incident response is often delayed because analysts on both teams unknowingly work on the same alerts.
Which solution will improve security metrics and outcomes while meeting the CISO’s directive?
AImplement network segmentation techniques combined with log analysis and periodic manual threat hunting
BIntegrate automated threat intelligence
CIntegrate and consolidate visibility and response capabilities across the company attack surface
DImplement a Unified Threat Management (UTM) system
For which two use cases is using a SIEM more appropriate than using a SOAR solution to investigate a user who signs in from a malicious IP address?
Choose two
AUsing predefined rules and patterns to identify data points
BEnriching data and triaging alert information
CContinuously monitoring data for pattern recognition
DMapping external threats to SOC incidents
In which scenario is application security more appropriate than data security?
ADetecting sensitive data
BAccessing visibility to cloud assets
CProtecting data in real time
DMonitoring CI/CD pipelines
A large hospitality chain uses Cortex Cloud to cut runtime misconfigurations in its patient portal application from 100 to only 10 with each new release, while increasing developer productivity.
Which management module was used to achieve this goal?
Community Discussion