Official Bank 0/258

Palo Alto Networks Cloud Security Professional (Palo Alto Networks Cloud Security Professional) - PaloAlto Networks Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
258 Total Questions
1
Question
On which cloud service providers can you receive new API release information for Prisma Cloud?
Options
A AWS, Azure, GCP, IBM, Alibaba
B AWS, Azure, GCP, Oracle, Alibaba
C AWS, Azure, GCP, Oracle, IBM
D AWS, Azure, GCP, IBM
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Which option shows the steps to install the Console in a Kubernetes Cluster?
Options
A Download and extract release tarball Download the YAML for Console Deploy Console YAML using
kubectl
B Download and extract release tarball Generate YAML for ConsoleDeploy Console YAML using
kubectl
C Download the Console and Defender image Generate YAML for DefenderDeploy Defender YAML using kubectl
D Download the Console and Defender image Download YAML for Defender from the document site Deploy Defender YAML using kubectl
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which step should a SecOps engineer implement in order to create a network exposure policy that identifies instances accessible from any untrusted internet sources?
Options
A In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name.Severity->
Configure RQL query "config from network where source.network = UNTRUSTJNTERNET and
dest.resource.type = 'Instance' and dest.cloud.type = 'AWS'" -> Define recommendation for
remediation & save.
B In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name.Severity->
Configure RQL query "network from vpc.flow_record where source.publicnetwork IN ('Suspicious
IPs', 'Internet IPs') and dest.resource IN (resource where role IN ('Instance ))" -> define compliance
standard -> Define recommendation for remediation & save.
C In Policy Section-> Add Policy-> Config type -> Define Policy details Like Name,Severity-> Configure
RQL query "config from network where source.network = UNTRUSTJNTERNET and dest.resource.type
= 'Instance' and dest.cloud.type = 'AWS*" -> define compliance standard -> Define recommendation
for remediation & save.
D In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name.Severity->
Configure RQL query "network from vpc.flow_record where source.publicnetwork IN ('Suspicious
IPs', 'Internet IPs') and dest.resource IN (resource where role IN ( Instance ))" -> define compliance
standard -> Define recommendation for remediation & save.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
What should be used to associate Prisma Cloud policies with compliance frameworks?
Options
A Policies
B Custom compliance
C Compliance
D Alert rules
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A customer has a requirement to terminate any Container from image topSecret:latest when a process named ransomWare is executed.

How should the administrator configure Prisma Cloud Compute to satisfy this requirement?
Options
A choose “copy into rule” for the Container, add a ransomWare process into the denied process list,
and set the action to “block”.
B set the Container model to relearn and set the default runtime rule to prevent for process protection.
C set the Container model to manual relearn and set the default runtime rule to block for process protection.
D add a new runtime policy targeted at a specific Container name, add ransomWare process into the denied process list, and set the action to “prevent”.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.