Skip to content

PCCSE Prisma Certified Cloud Security Engineer Practice Questions

Prepare for PCCSE with more than an answer.

337 questions in the full set20 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Palo Alto Networks Cloud Security Professional 196 questions Locked
  • PCCSELegacy Prisma Certified Cloud Security Engineer 337 questions Current
Exam fee
$175 USD
Time limit
75 minutes
Questions on the exam
75-85
Passing score
70 (scale 0-100)
Level
Engineer
Valid for
2 years
Domains covered on the exam 6
  1. Prisma Cloud Administration19%
  2. Cloud Security Posture Management (CSPM)25%
  3. Cloud Workload Protection (CWP)20%
  4. Data Security and Compliance15%
  5. Network Security11%
  6. SecOps and Incident Response10%
  1. 1

    True or False: The Prisma Cloud agentless scanning feature for hosts provides the same real-time runtime protection capabilities as a deployed Host Defender.

    Show answer details

    Correct answer: B

    Agentless scanning works by taking snapshots of host volumes at intervals and analyzing them for vulnerabilities and misconfigurations. It is a point-in-time assessment. A deployed Host Defender is an active agent that provides continuous, real-time monitoring and protection of runtime activities like process execution, network connections, and file system changes. Agentless scanning cannot provide this real-time runtime defense.

  2. 2

    A developer needs to scan a container image stored on their local workstation before pushing it to a registry. The developer has been provided with credentials and the address for the company's Prisma Cloud Compute Console. Which command should the developer use to perform this scan and output detailed results?

    Show answer details

    Correct answer: B

    The twistcli utility is the command-line tool for interacting with the Prisma Cloud Compute Console. The images scan subcommand is used for scanning. The --address, --user, and --password flags provide the necessary connection and authentication details. The --details flag is crucial for getting a comprehensive report of all findings, not just a summary. The final argument is the name and tag of the local image to be scanned.

  3. 3

    A retail company uses Prisma Cloud to secure its e-commerce application hosted on Google Kubernetes Engine (GKE). During a security review, an auditor requires evidence that all network traffic between the 'payment-processing' pods and the 'customer-database' pods is encrypted using mTLS. Which Prisma Cloud feature can provide this evidence without instrumenting the application code?

    Show answer details

    Correct answer: A

    Prisma Cloud's CNNS capability, powered by the Container Defender, inspects network traffic at the host level. It can identify the protocol being used (e.g., HTTPS, TLS) for connections between pods. By reviewing the CNNS Firewall audits or the Radar view, an operator can filter for traffic between the specified services and verify that the connections are indeed encrypted, providing the necessary evidence for the audit.

  4. 4

    A consultant is demonstrating Prisma Cloud's capabilities to a potential customer. The customer is concerned about misconfigurations in their Terraform IaC templates. To demonstrate the value of 'shift-left' security, the consultant wants to scan a Terraform file and show how Prisma Cloud can identify a security group that allows unrestricted SSH access. Which tool or integration is designed for this specific purpose?

    Show answer details

    Correct answer: C

    The Prisma Cloud VS Code Extension is specifically designed for developers and DevOps engineers to scan IaC files (like Terraform, CloudFormation, etc.) directly within their IDE. It connects to the Prisma Cloud backend, applies the relevant security policies, and highlights misconfigurations in the code, providing immediate feedback and remediation guidance. This is the ideal tool for demonstrating shift-left security for IaC.

  5. 5

    A Case Study for a Global Logistics Company

    Company Background:
    Global Logistics Inc. (GLI) is a multinational shipping and logistics company that manages a complex supply chain using a proprietary application suite. To improve agility and scalability, GLI is migrating this suite to a microservices architecture running on Azure Kubernetes Service (AKS). The environment is hybrid, with some legacy databases remaining on-premises, connected via an ExpressRoute circuit. The company is subject to various international data residency and privacy regulations.

    Current Situation:
    GLI has deployed Prisma Cloud Enterprise to secure their new AKS environment and existing Azure footprint. They have onboarded their Azure subscription and deployed Container Defenders as a DaemonSet on their AKS clusters. Initial vulnerability scans of their container images have revealed a large number of critical vulnerabilities in third-party libraries. The development teams are overwhelmed and are pushing back on fixing everything at once. Additionally, security has observed unencrypted traffic from some pods in the AKS cluster to the on-premises databases.

    Security & Compliance Requirements:

    1. A risk-based approach must be implemented for vulnerability management. Only vulnerabilities that are proven to be in loaded libraries within running containers should be prioritized for immediate remediation.
    2. All network traffic between the AKS cluster and the on-premises databases must be encrypted and strictly controlled.
    3. The company needs to prevent any container image from a public, untrusted registry (like Docker Hub) from being deployed in the production namespace.
    4. A compliance report must be generated quarterly that demonstrates adherence to GDPR principles, specifically focusing on data location and access.

    Problem:
    As the lead cloud security engineer, you are tasked with designing and implementing a set of controls within Prisma Cloud to meet all of GLI's security and compliance requirements. Which of the following proposals BEST addresses all the stated requirements?

    graph TD subgraph Azure Cloud AKS[AKS Cluster] AppGW[Application Gateway] end subgraph On-Premises Data Center DB[(Legacy Databases)] end Internet --> AppGW --> AKS AKS |ExpressRoute| DB
    Show answer details

    Correct answer: B

    This solution correctly addresses all four requirements. 1) 'Runtime Vulnerability Analysis' (also known as active vulnerability analysis) directly solves the prioritization problem by focusing on packages that are actually loaded in memory. 2) A CNNS policy is the correct tool to monitor and control network flows, including checking for encryption. 3) A Container Runtime Policy can control which image registries are trusted, effectively blocking deployments from public sources. 4) The built-in GDPR compliance standard and the Data Security module are the designated features for tracking data-related compliance.

  6. 6

    A financial services company has deployed Prisma Cloud to monitor its AWS environment. A security architect needs to create a custom policy to detect any S3 bucket that is publicly accessible but does NOT have a 'data-classification' tag with the value 'public'. Which RQL query correctly identifies these non-compliant S3 buckets?

    Show answer details

    Correct answer: C

    This RQL query correctly identifies the target resources. It uses the aws-s3-bucket-list API to get bucket configurations, checks if publicAccess is true, and then uses a logical OR to find buckets where the 'data-classification' tag is either not equal to 'public' or is not defined at all. This combination accurately captures the security requirement.

  7. 7

    A SecOps team is investigating a container runtime incident where an anomalous process, kdevtmpfsi, was detected and blocked by a Host Defender. To perform forensic analysis, the team needs to find the original container image that was used to launch the compromised container. Which Prisma Cloud feature provides the most direct path to identify the source image for a specific runtime event?

    Show answer details

    Correct answer: D

    The Incident Explorer is designed for this exact purpose. It correlates runtime audit events with the source entity. When viewing the details of the specific process anomaly incident, Prisma Cloud provides rich contextual information, including the container ID, the host it ran on, and most importantly, the full name and hash of the source image, which is crucial for forensic analysis.

  8. 8

    A DevOps team is using a Jenkins pipeline to build and push container images to a private registry. They need to configure a step that fails the build if the image contains any vulnerabilities with a CVSS score of 9.0 or higher, or if it uses a package with a non-compliant license such as GPL-3.0. Which twistcli command structure correctly implements these dual conditions?

    Show answer details

    Correct answer: C

    This command correctly uses two separate flags to control the failure thresholds. --vulnerability-threshold critical fails the build for vulnerabilities with a CVSS score of 9.0-10.0 (critical). --compliance-threshold high fails the build for compliance issues, such as non-approved licenses, that are rated as high severity or above. This combination precisely meets the stated requirements.

  9. 9

    A cloud administrator is configuring a Prisma Cloud Enterprise tenant and needs to integrate it with an external SAML 2.0 Identity Provider (IdP) for Single Sign-On (SSO). The IdP requires a unique identifier for the Service Provider (SP), which is Prisma Cloud in this case. Where in the Prisma Cloud console can the administrator find the 'Audience URI (SP Entity ID)' required by the IdP?

    Show answer details

    Correct answer: B

    When configuring SSO in Prisma Cloud, the required Service Provider (SP) metadata is generated and displayed directly in the user interface. The administrator must navigate to Settings > Enterprise Settings, select the SSO tab, and enable it. The 'Audience URI (SP Entity ID)' and other necessary values like the 'Assertion Consumer Service (ACS) URL' will be presented there to be copied into the IdP configuration.

  10. 10

    A security team is deploying Prisma Cloud WAAS to protect a web application running on a Kubernetes cluster. They want to prevent common injection attacks. Which of the following WAAS features should be configured to achieve this? (Select TWO)

    Show answer details

    Correct answer: A, C

Create an account to continue.