CloudSec-Pro Palo Alto Networks Cloud Security Professional (CloudSec-Pro) Practice Questions
Prepare for CloudSec-Pro with more than an answer.
- 1
A security engineer needs to configure a Web Application and API Security (WAAS) policy to protect a new REST API. The API is experiencing high volumes of automated bot traffic scraping pricing data. Which specific WAAS feature should be enabled to mitigate this threat?
Show answer details
Correct answer: D
Bot Defense (often including Rate Limiting and behavioral analysis) is the specific WAAS capability designed to identify and block automated scraping tools and bots.
- 2
When integrating Cortex Cloud with a CI/CD pipeline, the 'Secrets Scanning' feature fails a build. What is the most likely reason for this failure?
Show answer details
Correct answer: B
Secrets Scanning looks for high-entropy strings and known patterns of credentials (like 'AKIA...') committed to the codebase to prevent accidental exposure.
- 3
Case Study:
GlobalHealth Inc. is migrating its patient portal to a serverless architecture using AWS Lambda and Azure Functions. The security team has the following requirements:
- Prevent malicious code injection into the serverless functions.
- Gain visibility into the function's execution flow and external network calls.
- Ensure that the functions are not over-privileged with IAM permissions.
Which combination of Cortex Cloud modules addresses all three requirements?
Show answer details
Correct answer: C
Serverless Security (a subset of CWP) provides runtime defense (code injection prevention, process monitoring) for Lambda/Functions. CIEM addresses the requirement to analyze and right-size IAM permissions (over-privileged check).
- 4
A large financial institution is utilizing the Cortex Cloud platform to secure its multi-cloud environment. The security team has observed a spike in alerts related to 'Shadow AI' usage, where developers are spinning up unapproved AI models in AWS and Azure. The CISO requires a solution that not only detects these resources but also analyzes the training data for sensitive information exposure. Which module within the Cloud Posture Security domain should the team leverage to meet this specific requirement?
Show answer details
Correct answer: A
AI Security Posture Management (AI-SPM) is specifically designed to discover AI models, analyze their configurations, and inspect the data associated with them (such as training datasets) for sensitive information or exposure. CWP focuses on workload runtime, DSPM focuses on general data, and KSPM on Kubernetes.
- 5
A Cloud Security Administrator is configuring agentless scanning for a production environment containing 500+ EC2 instances. The goal is to detect vulnerabilities without impacting the performance of running applications. Which statement correctly describes the operational mechanism of agentless scanning in this context?
Show answer details
Correct answer: A
Agentless scanning operates by taking point-in-time snapshots of cloud block storage (volumes), analyzing those snapshots in a side-scanning environment for vulnerabilities and risks, and then discarding the snapshots. This avoids any performance impact on the live workload.
- 6
During a SOC investigation, an analyst identifies a suspicious container in a Kubernetes cluster that is attempting to establish a reverse shell connection to an external IP. The cluster is protected by Cortex Cloud Runtime Security. Which specific capability should be configured to automatically block this activity based on the deviation from the container's learned behavior model?
Show answer details
Correct answer: D
Drift Prevention (or Anti-Malware/Runtime Defense depending on exact module versioning, but Drift is key here) ensures that only the executables and processes that were part of the original container image or added to an allow list can run. Any deviation (drift), such as a reverse shell binary or script dropped at runtime, is blocked.
