Palo Alto Networks PCCSE Exam Practice Questions (P. 5)
- Full Access (252 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
The security team wants to protect a web application container from an SQLi attack.
Which type of policy should the administrator create to protect the container?
Which type of policy should the administrator create to protect the container?
- ACNAFMost Voted
- BRuntime
- CCompliance
- DCNNF
Correct Answer:
A
Reference:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/20-09/prisma-cloud-compute-edition-admin/firewalls/waas
A
Reference:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/20-09/prisma-cloud-compute-edition-admin/firewalls/waas
send
light_mode
delete
Question #22
An S3 bucket within AWS has generated an alert by violating the Prisma Cloud Default policy `AWS S3 buckets are accessible to public`. The policy definition follows: config where cloud.type = 'aws' AND api.name='aws-s3api-get-bucket-acl' AND json.rule="((((acl.grants[?(@.grantee=='AllUsers')] size > 0) or policyStatus.isPublic is true) and publicAccessBlockConfiguration does not exist) or ((acl.grants[?(@.grantee=='AllUsers')] size > 0) and publicAccessBlockConfiguration.ignorePublicAcis is false) or (policyStatus.isPublic is true and publicAccessBlockConfiguration.restrictPublicBuckets is false)) and websiteConfiguration does not exist"
Why did this alert get generated?
Why did this alert get generated?
- Aan event within the cloud account
- Bnetwork traffic to the S3 bucket
- Cconfiguration of the S3 bucketMost Voted
- Danomalous behaviors
Correct Answer:
B
B
send
light_mode
delete
Question #23
DRAG DROP -
Which order of steps map a policy to a custom compliance standard?
(Drag the steps into the correct order of occurrence, from the first step to the last.)
Select and Place:

Which order of steps map a policy to a custom compliance standard?
(Drag the steps into the correct order of occurrence, from the first step to the last.)
Select and Place:

send
light_mode
delete
Question #24
A customer is interested in PCI requirements and needs to ensure that no privilege containers can start in the environment.
Which action needs to be set for `do not use privileged containers`?
Which action needs to be set for `do not use privileged containers`?
- APrevent
- BAlert
- CBlockMost Voted
- DFail
Correct Answer:
(133)A
Reference:
https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/prisma/prisma-cloud/prisma-cloud-policy-reference/prisma-cloud-policy- reference.pdf
(133)A
Reference:
https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/prisma/prisma-cloud/prisma-cloud-policy-reference/prisma-cloud-policy- reference.pdf
send
light_mode
delete
Question #25
Given an existing ECS Cluster, which option shows the steps required to install the Console in Amazon ECS?
- AThe console cannot natively run in an ECS cluster. A onebox deployment should be used.
- BDownload and extract the release tarball Ensure that each node has its own storage for Console data Create the Console task definition Deploy the task definition
- CDownload and extract release tarball Download task from AWS Create the Console task definition Deploy the task definition
- DDownload and extract the release tarball Create an EFS file system and mount to each node in the cluster Create the Console task definition Deploy the task definitionMost Voted
Correct Answer:
D
Reference:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/19-11/prisma-cloud-compute-edition-admin/install/install_amazon_ecs.html
D
Reference:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/19-11/prisma-cloud-compute-edition-admin/install/install_amazon_ecs.html
send
light_mode
delete
All Pages