Cloud-Security-Professional Cloud Security Professional Practice Questions
Prepare for Cloud-Security-Professional with more than an answer.
Unlock the full exam and previous versions
- v1Palo Alto Networks Cloud Security Professional 196 questions Current
- PCCSELegacy Prisma Certified Cloud Security Engineer 337 questions Locked
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Security Operations Center (SOC) Fundamentals10%
- Cortex Fundamentals15%
- Cloud Posture Security29%
- Cloud Runtime Security26%
- Application Security20%
- 1
A container image has been scanned and pushed to a registry. The Cortex Cloud runtime policy is configured to block containers from running if they have known critical vulnerabilities. Later, a new, critical zero-day vulnerability is discovered in a package included in that image. What will happen when a user tries to deploy a new container from this existing image?
Show answer details
Correct answer: C
Cortex Cloud's runtime protection includes an admission controller that intercepts deployment requests. Even if an image was scanned and deemed safe in the past, the admission controller performs a final check against the very latest threat intelligence and vulnerability data at the moment of deployment. When the new zero-day vulnerability is added to the database, the admission controller will identify it in the image and block the container from running, enforcing the security policy.
- 2
A security team has configured Cortex Cloud to scan their GitHub repositories for hardcoded secrets. A developer accidentally commits an AWS access key to a feature branch. The scan detects the secret and generates a high-severity alert. What is the most important next step the security team must take to fully remediate the risk?
Show answer details
Correct answer: A
Once a secret is exposed, it must be considered compromised. Even if the commit is removed from the repository's history, it may have been cloned or cached. The only way to guarantee the credential cannot be abused is to revoke it at the source, in this case, by deactivating and deleting the access key in AWS IAM. This is the most critical and time-sensitive step. Removing the secret from Git history is also necessary but is secondary to revoking the credential itself.
- 3
A CSPM policy alert is generated for an Azure Storage Account that has 'Allow public access' enabled. This configuration is intentional and required for a specific public-facing web application. How can a security administrator handle this alert in Cortex Cloud to acknowledge the business need while still maintaining security oversight?
Show answer details
Correct answer: C
The correct way to handle intentional deviations from a security policy is to create a documented exception. In Cortex Cloud, you can create an exception for a specific resource against a specific policy. This requires a justification, which creates an audit trail, and allows for setting an expiration date, prompting a review in the future. This approach reduces alert noise while ensuring the business exception is tracked and managed.
- 4
An organization is using AI/ML models for critical business functions. The CISO is concerned about adversaries manipulating the models by submitting crafted input data during the training phase. Which specific threat is the AI-SPM module designed to help identify and mitigate in this scenario?
flowchart TD A[Adversary] -->|Injects Malicious Data| B(Training Dataset) B --> C{ML Model Training} C --> D(Compromised Model) D --> E{Incorrect Predictions}Show answer details
Correct answer: A
Data poisoning is an attack where an adversary intentionally pollutes the training data of an ML model to compromise its integrity. The AI-SPM module helps mitigate this by scanning training data sources for anomalies, monitoring the integrity of the ML pipeline, and detecting unusual shifts in model behavior that could indicate a poisoning attack has occurred.
- 5
A SOC analyst is investigating an alert from the CWP module that shows a container unexpectedly spawned a reverse shell. To understand the full attack chain, the analyst needs to correlate this runtime event with posture misconfigurations that may have enabled the initial compromise. Which Cortex Cloud feature provides this unified view of risk from posture to runtime?
Show answer details
Correct answer: D
Cloud Detection and Response (CDR) is specifically designed to correlate data from multiple sources, including posture (CSPM), identity (CIEM), and runtime (CWP). Its Attack Path Analysis feature visualizes how an attacker could chain together different weaknesses—like a public-facing asset with a vulnerability, an over-privileged IAM role, and a runtime exploit—to achieve their objective. This provides the exact context the analyst needs.
- 6
A financial institution is using Cortex Cloud's DSPM capabilities to classify data across their multi-cloud environment. A security analyst discovers that several newly provisioned AWS S3 buckets containing financial projections are not being scanned or classified. All existing buckets are scanned correctly. What is the most likely reason for this failure?
Show answer details
Correct answer: A
Cortex Cloud often relies on specific configurations for resource discovery, especially in large environments. A common practice is to configure the cloud account onboarding to only discover and scan resources that have a specific tag. This prevents accidental scanning of non-production or irrelevant assets. If new buckets are created without this tag, the DSPM scanner will ignore them, which is the most probable cause given that existing buckets are scanned correctly.
- 7
A DevOps team is managing a large-scale Kubernetes environment. A recent KSPM scan from Cortex Cloud flagged numerous workloads for violating the CIS Kubernetes Benchmark regarding immutable file systems. Which of the following configurations in a Kubernetes pod security context would proactively enforce this best practice?
Show answer details
Correct answer: B
The
readOnlyRootFilesystem: truesetting in a pod's security context directly enforces an immutable file system at the container level. This prevents any process, even one running as root inside the container, from writing to the root filesystem. This is a critical security control that aligns with the CIS Benchmark for Kubernetes and mitigates many runtime threats by preventing attackers from modifying binaries or configuration files. - 8
A security architect is designing a runtime protection strategy for a serverless application composed of AWS Lambda functions. The primary concern is detecting and blocking malicious activity, such as command injection, within the function's execution environment. Which Cortex Cloud Defender type is specifically designed for this purpose?
Show answer details
Correct answer: A
The Cortex Cloud Serverless Defender is specifically engineered to protect serverless functions like AWS Lambda. It is deployed as a Lambda layer, which allows it to be attached to the function without modifying the core application code. This layer instruments the runtime environment to monitor for and block malicious activities, enforce security policies, and provide visibility into vulnerabilities within the function's dependencies.
- 9
During a CI/CD pipeline run for a containerized application, the Cortex Cloud SCA scan fails the build. The scan report indicates a critical vulnerability (CVE-2024-XXXX) in an open-source library,
log-utils.js, which is a transitive dependency of a directly imported package. What is the most effective and immediate action a developer can take to remediate this issue and allow the pipeline to proceed securely?Show answer details
Correct answer: C
The most secure and proper way to fix a vulnerability in a transitive dependency is to update the direct dependency that pulls it in. Modern package managers will resolve the dependency tree and pull a patched, non-vulnerable version of the transitive dependency if one is available in the updated direct package. This addresses the root cause rather than simply suppressing an alert, ensuring the code is actually secure.
- 10
A SOC analyst receives a high-severity alert from Cortex CDR indicating suspicious lateral movement between two EC2 instances. The alert provides the source and destination IP addresses, the protocol used (SSH), and a MITRE ATT&CK mapping to T1021.004 (Remote Services: SSH). To effectively investigate and contain this threat, which TWO actions should the analyst perform first using the CDR module? (Select TWO)
Show answer details
Correct answer: D, E
