Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

PSE Palo Alto Networks System Engineer Professional - Prisma Cloud Question and Answers

PSE Palo Alto Networks System Engineer Professional - Prisma Cloud

Last Update Sep 22, 2025
Total Questions : 115

We are offering FREE PSE-PrismaCloud Paloalto Networks exam questions. All you do is to just go and sign up. Give your details, prepare PSE-PrismaCloud free exam questions and then go for complete pool of PSE Palo Alto Networks System Engineer Professional - Prisma Cloud test questions that will help you more.

PSE-PrismaCloud pdf

PSE-PrismaCloud PDF

$42  $104.99
PSE-PrismaCloud Engine

PSE-PrismaCloud Testing Engine

$50  $124.99
PSE-PrismaCloud PDF + Engine

PSE-PrismaCloud PDF + Testing Engine

$66  $164.99
Questions 1

In which two ways does Palo Alto Networks VM orchestration help service providers automatically provision security instances and policies? (Choose two.)

Options:

A.  

fully instrumented API

B.  

Aperture Orchestration Engine

C.  

VM Orchestration Policy Editor

D.  

support for Dynamic Address Groups

Discussion 0
Questions 2

Which three services can Google Cloud Security Scanner assess? (Choose three.)

Options:

A.  

Google Kubernetes Engine

B.  

BigQuery

C.  

Compute Engine

D.  

App Engine

E.  

Google Virtual Private Cloud

Discussion 0
Questions 3

Which subcommand invokes the scan for images built with Jenkins in an OpenShift environment?

Options:

A.  

> twistcli project scan

B.  

> twistcli scar, projects

C.  

> twistcli hosts scan

D.  

> twistcli scar, hosts

Discussion 0
Questions 4

What are two examples of Amazon Web Services logging services? (Choose two.)

Options:

A.  

CloudLog

B.  

CloudEvent

C.  

CloudWatch

D.  

CIoudTrail

Discussion 0
Questions 5

An image containing medium vulnerabilities that do not have available fixes is being deployed into the sock-shop namespace. Prisma Cloud has been configured for vulnerability management within the organization's continuous integration (CI) tool and registry.

What will occur during the attempt to deploy this image from the CI tool into the sock-shop namespace?

Options:

A.  

The image will pass the CI policy, but will be blocked by the deployed policy; therefore, it will not be deployed.

B.  

The CI policy will fail the build; therefore, the image will not be deployed.

C.  

The image will be deployed successfully, and all vulnerabilities will be reported.

D.  

The image will be deployed successfully, but no vulnerabilities will be reported.

Discussion 0
Questions 6

When an on-premises NGFW (customer gateway) is used to connect to the Virtual Gateway, which two IKE profiles cannot be used? (Choose two.)

Options:

A.  

Group2 / SHA-1 / AES-128-CBC / IKE-V1

B.  

Group2 / SHA-1 / AES-128-GCM / IKE-V1

C.  

Group14 / SHA-256 / AES-256-GCM / IKE-V1

D.  

Group2 / SHA-1 / AES-128-CBC

E.  

Group14 / SHA-256 / AES-256-CBC / IKE-V1

Discussion 0
Questions 7

Which Resource Query Language (RQL) query returns a list of all TERMINATED Google Compute Engine (GCE) instances?

Options:

A.  

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = status == TERMINATED

B.  

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = TERMINATED

C.  

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = status contains TERMINATED

D.  

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = is TERMINATED

Discussion 0
Questions 8

What is the Palo Alto Networks recommended setting for the Prisma Cloud Training Model Threshold?

Options:

A.  

Low

B.  

Thorough

C.  

High

D.  

Baseline

Discussion 0
Questions 9

Palo Alto Networks recommends which two options for outbound HA design in Amazon Web Services using VM-Series NGFW? (Choose two.)

Options:

A.  

iLB-as-next-hop

B.  

transit gateway and security VPC with VM-Series

C.  

traditional active/standby HA on VM-Series

D.  

transit VPC and security VPC with VM-Series

Discussion 0
Questions 10

Which Amazon Web Services security service can provide host vulnerability information to Prisma Public Cloud?

Options:

A.  

Shield

B.  

Inspector

C.  

GuardDuty

D.  

Amazon Web Services WAF

Discussion 0
Questions 11

How does Prisma Cloud Enterprise autoremediate unwanted violations to public cloud infrastructure?

Options:

A.  

It inspects the application program interface (API) call made to public cloud and blocks the change if a policy violation is found.

B.  

It makes changes after a policy violation has been identified in monitoring.

C.  

It locks all changes to public cloud infrastructure and stops any configuration changes without prior approval.

D.  

It uses machine learning (ML) to identify unusual changes to infrastructure.

Discussion 0
Questions 12

Which two cloud providers provide egress load balancing? (Choose two.)

Options:

A.  

Microsoft Azure

B.  

Alibaba Cloud

C.  

Amazon Web Services

D.  

Oracle Cloud

Discussion 0
Questions 13

The customer has an Amazon Web Services Elastic Computing Cloud that provides a service to the internet directly and needs to secure that cloud with a VM-Series NGFW.

Which component handles address translation?

Options:

A.  

The server VMs have private use only (RFC 1918) IPs. Amazon's cloud infrastructure translates those addresses to publicly accessible IP addresses. The VM-Series NGFW has publicly accessible IP addresses.

B.  

The server VMs have private use only (RFC 1918) IPs. The VM-Series NGFW translates those addresses to publicly accessible IP addresses.

C.  

The server VMs and the VM-Series NGFW have private use only (RFC 1918) IPs. Amazons cloud infrastructure translates those addresses to publicly accessible IP addresses

D.  

The servers and VM-Series NGFW have publicly accessible IP addresses for management purposes.

Discussion 0
Questions 14

What is Prisma Public Cloud licensing based on?

Options:

A.  

number of alerts generated

B.  

number of accounts onboarded

C.  

number of monitored workloads

D.  

volume of flow logs consumed

Discussion 0
Questions 15

Which pillar of the Prisma Cloud platform provides support for both public and private clouds as well as flexible agentless scanning and agent-based protection?

Options:

A.  

Cloud Network Security

B.  

Cloud Security Posture Management

C.  

Cloud Identity Security

D.  

Cloud Workload Protection (CWP)

Discussion 0
Questions 16

Which type of Prisma Cloud Enterprise alert supports autoremediation?

Options:

A.  

network

B.  

audit

C.  

anomaly

D.  

config

Discussion 0
Questions 17

What are the two options to dynamically register tags used by Dynamic Address Groups that are referenced in policy? (Choose two.)

Options:

A.  

VM Monitoring

B.  

External Dynamic List

C.  

CFT Template

D.  

XML API

Discussion 0
Questions 18

A customer has deployed a VM-Series NGFW on Amazon Web Services using a PAYG license. What is the sequence required by the customer to switch to a BYOL license?

Options:

Discussion 0
Questions 19

What are three examples of outbound traffic flow? (Choose three.)

Options:

A.  

issue yum update command on an instance inside Amazon Web Services

B.  

Microsoft Windows inside Azure requesting a security patch

C.  

web server inside Amazon Web Services receiving web requests from internet

D.  

issue apt-get install command on an instance inside Amazon Web Services

E.  

outgoing Prisma Public Cloud API calls

Discussion 0
Questions 20

What are the asset severity levels within Prisma Cloud asset inventory?

Options:

A.  

Low, Medium, and High

B.  

Low, Medium, High, and Critical

C.  

Informational, Low, Medium, and High

D.  

Low, Medium, High, Severe, and Critical

Discussion 0
Questions 21

What are two business values of Cloud Code Security? (Choose two.)

Options:

A.  

consistent controls from build time to runtime

B.  

prebuilt and customizable polices to detect data such as personally identifiable information (PII) in publicly exposed objects

C.  

support for multiple languages, runtimes and frameworks

D.  

continuous monitoring of all could resources for vulnerabilities, misconfigurations, and other threats

Discussion 0
Questions 22

What configuration on AWS is required in order for VM-Series to forward traffic between its network interfaces?

Options:

A.  

Both Source and Destination Checks are disabled

B.  

Both Source and Destination Checks are enabled

C.  

Source Check is disabled and Destination Check is enabled

D.  

Source Check is enabled and Destination Check is disabled

Discussion 0
Questions 23

Which Google Cloud Platform project shares its VPC networks with other projects?

Options:

A.  

Service project

B.  

Host project

C.  

Admin project

D.  

Subscribing project

Discussion 0
Questions 24

Which three requirements are needed to register a PAYG VM-Series NGFW at the Palo Alto Networks Customer Support website? (Choose three.)

Options:

A.  

Serial Number

B.  

CPU ID

C.  

Auth Code

D.  

License Key

E.  

UUID

Discussion 0
Questions 25

Match the logging service with its cloud provider.

Options:

Discussion 0
Questions 26

Which framework in Prisma Public Cloud can be used to provide general best practices when no specific legal requirements or regulatory standards need to be met?

Options:

A.  

HIPAA

B.  

CIS Benchmark

C.  

Payment Card Industry DSS V3

D.  

GDPR

Discussion 0
Questions 27

Which two deployment methods are supported for Prisma Cloud Compute (PCC) container Defenders? (Choose two.)

Options:

A.  

Azure SQL database instances

B.  

Google Kubernetes Engine

C.  

Oracle Functions service

D.  

Kubernetes DaemonSet

Discussion 0
Questions 28

Which type of Resource Query Language (RQL) query is used to create a custom policy that looks for untagged resources?

Options:

A.  

config

B.  

alert

C.  

event

D.  

data

Discussion 0
Questions 29

Which three types of security checks can Prisma Public Cloud perform? (Choose three.)

Options:

A.  

compliance where

B.  

network where

C.  

user where

D.  

config where

E.  

event where

Discussion 0
Questions 30

Which RQL query should be used to quickly identify any events related to an organization's Google Cloud Platform Big Query database the last 24 hours?

Options:

A.  

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'Google Bigtable Instance'

B.  

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'cloudsql.googleapis.com'

C.  

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'bigquery.googleapis.com'

D.  

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'dataproc.googleapis.com'

Discussion 0
Questions 31

An Azure VNet has the IP network 10.0.0.0/16 with two subnets, 10.0.1.0/24 (used for web servers) and 10.0.2.0/24 (used for database servers). Which is a valid IP address to manage the VM-Series NGFW?

Options:

A.  

10.0.1.254

B.  

10.0.2.1

C.  

10.0.3.255

D.  

10.0.3.1

Discussion 0
Questions 32

What are two benefits of Cloud Security Posture Management (CSPM) over other solutions? (Choose two.)

Options:

A.  

guaranteed proof of concept (POC) extensions beyond 30 days

B.  

native integration of network, endpoint, and cloud data to stop attacks

C.  

elimination of blind spots

D.  

proactive addressing of risks

Discussion 0
Questions 33

Which two cloud-native providers are supported by Prisma Cloud? (Choose two.)

Options:

A.  

DigitalOcean

B.  

Azure

C.  

IBM Cloud

D.  

Oracle Cloud

Discussion 0
Questions 34

All Amazon Regional Database Service (RDS)-deployed resources and the regions in which they are deployed can be identified by prisma Cloud using which two methods? (Choose two.)

Options:

A.  

Configure an Inventory report from the "Alerts" tab.

B.  

Write an RQL query from the "Investigate" tab.

C.  

Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.

D.  

Generate a compliance report from the Compliance dashboard.

Discussion 0