Prisma Cloud Practice Questions
Prepare for PSE-PRISMA with more than an answer.
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Prisma Cloud Platform Overview20%
- Cloud Security Posture Management (CSPM)25%
- Cloud Workload Protection (CWP)25%
- Cloud Network Security15%
- Data Security and Threat Detection15%
- 1
A security operations team uses a centralized SIEM for alert aggregation and incident management. They want to forward all high-severity runtime alerts from Prisma Cloud to their SIEM. Which Prisma Cloud feature should be configured to achieve this integration?
Show answer details
Correct answer: C
Prisma Cloud manages external integrations through its Alerting and Notification settings. An administrator can configure various integration channels, such as Splunk, ServiceNow, or a generic webhook, and then create an alert rule that specifies which alerts (e.g., high-severity runtime alerts) should be sent to that channel.
- 2
An organization wants to implement web application and API security (WAAS) for its containerized applications running in Kubernetes. Which Prisma Cloud component must be deployed to enable WAAS protection?
Show answer details
Correct answer: B
WAAS functionality is delivered by the Container Defender. It can be deployed in-line, either as an embedded defender within the application container or as a reverse proxy in front of the application, to inspect incoming HTTP/S traffic and block threats like SQL injection and cross-site scripting.
- 3
Case Study
HealthFirst Corp, a healthcare data analytics company, uses AWS Lambda for its data processing pipeline. Raw patient data is uploaded to an S3 bucket, which triggers a series of Lambda functions to process, anonymize, and store the results in a DynamoDB table. The entire infrastructure is defined using CloudFormation templates stored in a GitHub repository.
Due to strict HIPAA compliance requirements, the security team must ensure the following:
- The Lambda functions themselves do not contain any known vulnerabilities in their code packages or dependencies.
- The IAM roles assigned to the Lambda functions adhere to the principle of least privilege.
- The CloudFormation templates do not provision insecure resources (e.g., unencrypted S3 buckets or publicly accessible DynamoDB tables).
What is the most efficient and automated way to use Prisma Cloud to address all three security requirements within their existing DevOps workflow?
Show answer details
Correct answer: C
This is the most comprehensive and 'shift-left' approach. Integrating Prisma Cloud into the CI/CD pipeline (GitHub Actions) allows for automated scanning of the CloudFormation templates (Req 3) using IaC security, and scanning of the Lambda function code and its dependencies (Req 1) using Application Security (SCA) and Serverless Scanning. The serverless scan also analyzes the function's permissions, addressing the least privilege requirement (Req 2) before the code is ever deployed.
- 4
A security administrator needs to limit the scope of a Prisma Cloud role so that users assigned to it can only view compliance findings related to their 'Production' account group. They should not be able to see findings from 'Development' or 'Staging' account groups. Where in the Prisma Cloud console is this access control configured?
Show answer details
Correct answer: B
Prisma Cloud's Role-Based Access Control (RBAC) is managed under Settings > Access Control. When creating or editing a role, an administrator can assign specific Account Groups to that role. This ensures that any user assigned the role will have their visibility and permissions restricted to only the cloud accounts within the assigned group(s).
- 5
A security analyst is investigating a critical alert on an Azure VM that hosts a customer database. To understand the potential impact, the analyst needs to determine if the VM is exposed to the internet and what other sensitive resources a potential attacker could pivot to. Which Cortex Cloud feature provides this contextual, graph-based visualization of risk?
graph TD subgraph "Internet Exposure" Internet((Internet)) --> NSG[NSG: Allow Port 3389] NSG --> VM_NIC[NIC] end subgraph "Lateral Movement Potential" VM[Azure VM with High Vuln] Identity[Managed Identity] KeyVault[(Key Vault: Customer Keys)] Storage[(Storage Account: Backups)] end VM_NIC --> VM VM --> Identity Identity -- Access Policy --> KeyVault Identity -- Storage Contributor --> StorageShow answer details
Correct answer: C
Attack Path Analysis is the feature designed specifically for this purpose. It correlates data from multiple sources—misconfigurations, vulnerabilities, network exposure, and identity permissions—to create a visual graph. This graph, like the one shown, illustrates how an attacker could potentially exploit a chain of weaknesses to move from an initial entry point (like an exposed VM) to critical assets (like a key vault or storage account).
- 6
A financial services firm is using Prisma Cloud to monitor its AWS environment. A security administrator needs to create a policy that alerts whenever an S3 bucket is created without server-side encryption enabled. The policy must also provide a one-click remediation option for the security operations team. Which type of policy and remediation approach should be configured?
Show answer details
Correct answer: B
Config policies are used to assess resource configurations against security best practices. Prisma Cloud provides built-in RQL templates for common misconfigurations like unencrypted S3 buckets. Marking the policy as 'Remediable' and using a supported remediation command allows for one-click fixes directly from the alert.
- 7
A DevOps team is deploying containerized applications on a self-managed Kubernetes cluster. To enforce runtime security, they have deployed Prisma Cloud Defenders as a DaemonSet. During a security review, an analyst observes that Defenders are not reporting any runtime events for a specific node in the cluster. All other nodes are reporting correctly. What is the MOST likely cause of this issue?
Show answer details
Correct answer: C
In Kubernetes, taints are applied to nodes to repel pods, while tolerations are applied to pods to allow them to be scheduled on nodes with matching taints. If a node has a specific taint (e.g., for GPU resources or a specific role), and the Defender DaemonSet manifest does not include a corresponding toleration, the Kubernetes scheduler will not place a Defender pod on that node, resulting in a lack of visibility and event reporting.
- 8
A company is using Prisma Cloud's CI/CD scanning capabilities to identify vulnerabilities in their application code before deployment. They want to ensure that any third-party libraries with high-severity vulnerabilities or restrictive licenses (e.g., GPL) are flagged. Which two features within the Application Security module should they primarily use? (Select TWO).
Show answer details
Correct answer: A, C
Software Composition Analysis (SCA) is the specific feature designed to scan application dependencies and third-party libraries for known vulnerabilities (CVEs) and to identify their software licenses.
CI/CD Posture Management provides the framework to define policies for vulnerabilities and license compliance within the CI/CD pipeline. It allows setting thresholds (e.g., fail build on high-severity CVEs or GPL licenses) that are enforced by the SCA scanner.
- 9
A security architect is designing a threat detection strategy for a multi-cloud environment using Prisma Cloud. The primary goal is to identify anomalous user behavior, such as an administrator accessing resources from an unusual location or at an odd time. Which Prisma Cloud capability directly addresses this requirement by leveraging machine learning?
Show answer details
Correct answer: B
Prisma Cloud's User and Entity Behavior Analytics (UEBA) capability uses machine learning algorithms to baseline normal user and service account activity. It then detects deviations from this baseline, such as unusual login times, locations, or resource access patterns, and generates anomaly alerts for potential threats.
- 10
True or False: In Prisma Cloud, a single Defender can be used to protect containers, hosts, and serverless functions simultaneously if they are all running on the same underlying host machine.
Show answer details
Correct answer: B
False. While a single Host Defender can protect both the host OS and the containers running on it, protecting serverless functions requires a specific Serverless Defender that is embedded directly into the function's code package. The deployment and protection models are distinct for each workload type.
