Step2Study
IT & TechnologyPCCSE100% Free

Palo Alto Networks Certified Cloud Security Engineer (PCCSE)

Practice bank
200 Qs
Real exam
60 Qs
Time limit
90 min
Passing
A passing score is achieved by correctly answering a percentage of questions that is greater than or equal to the determined cut score.

Exam blueprint

Prisma Cloud Platform
20%
Cloud Security Posture Management (CSPM)
25%
Cloud Workload Protection Platform (CWPP)
25%
Cloud Infrastructure Entitlement Management (CIEM)
15%
DevSecOps and Shift Left Security
15%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 135 min · pass 70% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Palo Alto Networks Certified Cloud Security Engineer (PCCSE) practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A cloud security engineer needs to create a custom policy in Prisma Cloud to identify all EC2 instances across their AWS, Azure, and GCP environments that have been running for more than 90 days AND have no 'Owner' tag defined. Which RQL logical operator is essential for combining these two conditions to accurately filter the desired resources?

    Cloud Security Posture Management (CSPM)

    • A. NOT
    • B. AND
    • C. OR
    • D. LIKE
    Show answer

    B. AND

    The requirement specifies finding instances that meet *both* conditions: running for more than 90 days *and* lacking an 'Owner' tag. The 'AND' logical operator is used to combine multiple conditions where all must be true for a resource to be included in the results.

  2. 2. An organization is using Prisma Cloud to identify and prioritize security risks. They've identified several critical vulnerabilities on a publicly exposed virtual machine that also has high-privilege access to a sensitive database. Which Prisma Cloud feature would be most effective for visualizing the potential impact of compromising this VM and understanding the chain of interconnected risks?

    Cloud Security Posture Management (CSPM)

    • A. Resource Explorer
    • B. Asset Inventory
    • C. Attack Path Analysis
    • D. Compliance Policies
    Show answer

    C. Attack Path Analysis

    Attack Path Analysis is specifically designed to visualize and quantify the risk of interconnected vulnerabilities and misconfigurations. It helps understand how an attacker could move from an initial compromise (e.g., publicly exposed VM) to a high-value target (sensitive database) by chaining together various weaknesses.

  3. 3. A large enterprise uses Prisma Cloud to manage security posture across thousands of cloud resources. The security team needs to identify all EC2 instances in a specific AWS region (us-east-1) that have port 22 (SSH) open to the internet (0.0.0.0/0) AND are tagged with 'Environment:Production'. Which Prisma Cloud feature should they use for this ad-hoc, targeted query?

    Cloud Security Posture Management (CSPM)

    • A. Resource Explorer
    • B. Compliance Policies
    • C. Network Explorer
    • D. Alert Management
    Show answer

    A. Resource Explorer

    Resource Explorer allows security teams to perform ad-hoc, granular queries across their cloud assets using RQL (Resource Query Language) to filter by resource type, region, tags, network configurations, and more. This is ideal for specific, targeted searches not necessarily tied to a continuous compliance check.

  4. 4. A global organization uses Prisma Cloud to enforce compliance with GDPR across its AWS, Azure, and GCP environments. They have a specific requirement to identify all storage buckets that are publicly accessible AND are located in a region outside of the EU. Which RQL attribute is crucial for filtering resources based on their geographical location?

    Cloud Security Posture Management (CSPM)

    • A. resource.name
    • B. account.id
    • C. region
    • D. publicAccess.level
    Show answer

    C. region

    The 'region' attribute in RQL allows users to filter resources based on their deployment region, which is essential for enforcing data residency requirements like those implied by GDPR for EU data.

  5. 5. A security engineer is investigating a series of suspicious network flows originating from an unapproved region in their AWS environment. They need to visualize all network connections, security group rules, and network ACLs associated with these flows to understand potential lateral movement and egress points. Which Prisma Cloud feature is best suited for this comprehensive network visualization and analysis?

    Cloud Security Posture Management (CSPM)

    • A. Network Explorer
    • B. Resource Explorer
    • C. Attack Path Analysis
    • D. Alert Management
    Show answer

    A. Network Explorer

    The Network Explorer in Prisma Cloud is specifically designed to visualize network topology, connectivity, and traffic flows between cloud resources. It allows security engineers to see how resources are connected, what security rules govern those connections, and identify potential egress or lateral movement paths.

  6. 6. A security engineer receives an alert from Prisma Cloud about an 'Unrestricted Egress to Internet' policy on a security group associated with a critical database server. The engineer needs to quickly understand the potential impact by visualizing which other resources could be affected by this misconfiguration, including any inbound paths that might exploit it. Which Prisma Cloud feature is BEST suited for this task?

    Cloud Security Posture Management (CSPM)

    • A. Compliance Policies Dashboard
    • B. Resource Explorer
    • C. Alert Management Dashboard
    • D. Network Explorer
    Show answer

    D. Network Explorer

    Network Explorer provides a visual representation of network connectivity and potential attack paths within the cloud environment. It allows engineers to trace inbound and outbound traffic flows, identify risky connections, and understand the blast radius of network misconfigurations, making it ideal for visualizing the impact of unrestricted egress.

  7. 7. A security analyst uses Prisma Cloud to monitor for deviations from their organization's security baseline. They notice a significant number of alerts for a specific policy related to 'unencrypted S3 buckets' in a development environment. This policy is critical for production but causes too much noise in dev. The analyst wants to suppress these alerts for the development environment only, without disabling the policy entirely or affecting other environments. Which alert management capability should they use?

    Cloud Security Posture Management (CSPM)

    • A. Global alert suppression
    • B. Resource exemption
    • C. Policy disabling
    • D. Alert rule suppression
    Show answer

    D. Alert rule suppression

    Alert rule suppression allows you to define specific conditions (e.g., for a particular policy and a specific account/tag like a development environment) under which alerts will not be generated or will be automatically dismissed. This is more granular than disabling the policy and more flexible than resource exemption for a broad set of resources.

  8. 8. A security auditor is reviewing Prisma Cloud's alert management system and notices a significant number of 'Low' severity alerts for 'AWS EBS Volume Not Encrypted'. While these are true positives, they are generating excessive noise and obscuring higher-priority alerts. The auditor wants to reduce the volume of these specific alerts without disabling the policy entirely or ignoring critical EBS volumes. What is the MOST effective strategy within Prisma Cloud to achieve this?

    Cloud Security Posture Management (CSPM)

    • A. Adjust the global alert threshold for all 'Low' severity alerts.
    • B. Disable the 'AWS EBS Volume Not Encrypted' policy for all accounts.
    • C. Create an alert rule with a suppression mechanism based on resource tags, excluding non-critical volumes.
    • D. Change the policy severity to 'Informational' and filter alerts by severity.
    Show answer

    C. Create an alert rule with a suppression mechanism based on resource tags, excluding non-critical volumes.

    Creating an alert rule with a suppression mechanism based on resource tags is the most effective approach. This allows specific non-critical EBS volumes (e.g., tagged 'Environment:Dev' or 'DataClassification:None') to be excluded from generating alerts, while still enforcing the policy for critical volumes and maintaining visibility on other 'Low' severity alerts from different policies.

  9. 9. A security operations team is investigating a series of unusual activities across their Azure subscriptions. They need to quickly identify all resources (VMs, databases, storage accounts) associated with a specific tag 'project-alpha-critical' and review their configurations, network interfaces, and attached security groups. Which Prisma Cloud feature allows for this comprehensive, detailed exploration of specific resources?

    Cloud Security Posture Management (CSPM)

    • A. Cloud Security Governance
    • B. Attack Path Analysis
    • C. Resource Explorer
    • D. Asset Inventory
    Show answer

    C. Resource Explorer

    Resource Explorer is designed for deep dives into individual cloud resources. It allows users to query for specific resources (e.g., by tag) and then view all their associated configurations, relationships, and metadata in a single, detailed view.

  10. 10. A security architect is analyzing a potential attack path identified by Prisma Cloud. The path shows an exposed EC2 instance, leading to an unpatched vulnerability, which then could grant access to a database containing sensitive customer data. The architect wants to determine the MOST effective single action that would break this specific attack path, assuming all identified components are part of the path.

    Cloud Security Posture Management (CSPM)

    • A. Implement network segmentation around the database.
    • B. Disable public access to the EC2 instance.
    • C. Apply the security patch to the EC2 instance.
    • D. Encrypt the database containing sensitive data.
    Show answer

    B. Disable public access to the EC2 instance.

    While all options are good security practices, disabling public access to the EC2 instance would immediately break the initial entry point of the attack path, preventing an attacker from reaching the unpatched vulnerability in the first place. This is often the most direct and effective way to disrupt an attack path originating from external exposure.

  11. 11. A financial institution uses Prisma Cloud to enforce strict compliance with PCI DSS. They need to ensure that all data stores containing cardholder data are encrypted at rest. Due to specific audit requirements, they must generate an audit trail of all policy violations related to unencrypted data stores, including who made the change that caused the violation. Which Prisma Cloud integration is crucial for capturing the 'who' and 'when' of configuration changes that lead to policy violations?

    Cloud Security Posture Management (CSPM)

    • A. SIEM Integration
    • B. Ticketing System Integration
    • C. Cloud Service Provider (CSP) Audit Log Integration
    • D. Identity Provider (IdP) Integration
    Show answer

    C. Cloud Service Provider (CSP) Audit Log Integration

    Prisma Cloud's integration with Cloud Service Provider (CSP) audit logs (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is crucial for capturing detailed event data, including the user identity, timestamp, and API call that resulted in a configuration change leading to a policy violation. This provides the necessary audit trail for 'who' and 'when'.

  12. 12. A security operations center (SOC) analyst is investigating a series of unusual activities across their Azure environment. They need to quickly identify all virtual machines (VMs) that have public IP addresses and are running an outdated operating system version. Which Prisma Cloud feature, combined with appropriate filtering, would be most effective for this task?

    Cloud Security Posture Management (CSPM)

    • A. Network Explorer
    • B. Resource Explorer
    • C. Attack Path Analysis
    • D. Alert Management
    Show answer

    B. Resource Explorer

    The Resource Explorer in Prisma Cloud allows analysts to search, filter, and view details of all cloud resources. It is ideal for identifying specific types of resources (VMs) with particular attributes (public IP, outdated OS) across the entire cloud estate.

  13. 13. A security engineer is tasked with performing a comprehensive security audit of a newly deployed application in AWS. They need to identify all potential paths an attacker could take from an internet-exposed resource (e.g., a public S3 bucket or an EC2 instance with an open port) to a critical database containing sensitive customer data. Which Prisma Cloud feature is specifically designed to visualize and prioritize these potential attack vectors?

    Cloud Security Posture Management (CSPM)

    • A. Resource Explorer
    • B. Compliance Policies
    • C. Attack Path Analysis
    • D. Network Explorer
    Show answer

    C. Attack Path Analysis

    Attack Path Analysis in Prisma Cloud is specifically designed to identify and visualize potential attack vectors, showing how an attacker could move from an initial point of compromise to high-value targets by chaining together misconfigurations and vulnerabilities.

  14. 14. A security engineer is tasked with integrating a new cloud environment (e.g., an Azure subscription) into Prisma Cloud. The primary objective is to gain visibility into all deployed resources and their configurations to assess compliance posture. What is the initial and fundamental step in this process?

    Cloud Security Posture Management (CSPM)

    • A. Creating custom RQL policies for specific compliance checks.
    • B. Generating compliance reports for existing industry benchmarks.
    • C. Configuring automated remediation actions for common misconfigurations.
    • D. Onboarding the cloud account by providing necessary access permissions.
    Show answer

    D. Onboarding the cloud account by providing necessary access permissions.

    The initial and fundamental step to gain any visibility or assess compliance posture in Prisma Cloud is to onboard the cloud account. This involves granting Prisma Cloud the necessary access permissions (e.g., via an Azure Service Principal or AWS IAM Role) to discover and collect data about resources.

  15. 15. A security team uses Prisma Cloud to monitor their GCP environment. They've discovered an alert indicating a 'Service Account with Admin Privileges' on a critical project. They want to automate the remediation of this issue by reducing the service account's permissions to the least privilege necessary. Which of the following Prisma Cloud remediation actions would be MOST appropriate for this scenario?

    Cloud Security Posture Management (CSPM)

    • A. Trigger a webhook to notify the security team via Slack.
    • B. Automatically delete the service account.
    • C. Initiate a Cloud Function to remove the 'roles/editor' role and assign a custom, more restricted role.
    • D. Create a Jira ticket for manual review and remediation.
    Show answer

    C. Initiate a Cloud Function to remove the 'roles/editor' role and assign a custom, more restricted role.

    Prisma Cloud's remediation capabilities can include triggering serverless functions (like AWS Lambda or GCP Cloud Functions) to perform complex, conditional actions. For reducing permissions, a Cloud Function can be programmed to remove the overly permissive role and assign a more appropriate, least-privilege role, automating the remediation while ensuring the service account remains functional.

  16. 16. A large enterprise has a strict data residency policy that mandates all data for a specific project must reside and be processed only within the EU (European Union) region. They are using Prisma Cloud to monitor their AWS, Azure, and GCP environments. How can Prisma Cloud best assist in continuously enforcing this data residency requirement?

    Cloud Security Posture Management (CSPM)

    • A. By creating custom policies using RQL to identify resources deployed in non-EU regions.
    • B. By manually reviewing cloud provider compliance reports for each region.
    • C. By enabling automated remediation to move non-compliant data to EU regions.
    • D. By configuring a global alert that flags any resource deployed outside the EU.
    Show answer

    A. By creating custom policies using RQL to identify resources deployed in non-EU regions.

    To continuously enforce a specific data residency requirement across multiple cloud providers, creating custom policies with RQL is the most effective method. RQL can query for the region attribute of resources across AWS, Azure, and GCP, allowing for precise identification of non-compliant deployments. While automated remediation might be a subsequent step, it's not the primary enforcement mechanism for *identifying* the non-compliance.

  17. 17. A security analyst is reviewing the asset inventory in Prisma Cloud for their GCP environment. They need to quickly find all Compute Engine instances that have external IP addresses assigned and are located in the 'us-central1' region. Which RQL query would accomplish this task?

    Cloud Security Posture Management (CSPM)

    • A. config from gcp.compute.instance where network.privateIp = false and region = 'us-central1'
    • B. config from gcp.compute.instance where network.externalIp and region = 'us-central1'
    • C. config from gcp.compute.instance where network.publicIp = true and region = 'us-central1'
    • D. config from gcp.compute.instance where externalIp is not null and region = 'us-central1'
    Show answer

    B. config from gcp.compute.instance where network.externalIp and region = 'us-central1'

    In Prisma Cloud's RQL for GCP Compute Engine instances, the presence of an external IP address is typically represented by the `network.externalIp` attribute. When this attribute exists (i.e., is not null or explicitly defined), it indicates an external IP. The `and region = 'us-central1'` correctly filters by region.

  18. 18. A cloud security architect is designing an automated remediation strategy for their AWS environment using Prisma Cloud. They have a critical policy that detects publicly accessible S3 buckets. Upon detecting such a bucket, they want Prisma Cloud to automatically modify the bucket policy to restrict public access. What is the MOST critical prerequisite for enabling this automated remediation in Prisma Cloud?

    Cloud Security Posture Management (CSPM)

    • A. Enable CloudTrail logging for S3 bucket events.
    • B. Onboard the AWS account with 'Remediation' access type.
    • C. Ensure the S3 bucket is tagged with 'remediate:true'.
    • D. Configure an external webhook for remediation actions.
    Show answer

    B. Onboard the AWS account with 'Remediation' access type.

    For Prisma Cloud to automatically remediate issues like modifying an S3 bucket policy, it requires the necessary permissions within the target AWS account. This is achieved by onboarding the account with a 'Remediation' access type, which grants Prisma Cloud the write/modify permissions needed to perform corrective actions.

  19. 19. A security operations center (SOC) analyst is investigating a high-severity alert generated by Prisma Cloud indicating 'Unrestricted Egress to Internet' from an EC2 instance. To understand the full impact and potential attack vectors, the analyst needs to visualize the network connections, security groups, and NACLs associated with the compromised instance and its communication paths. Which Prisma Cloud feature is purpose-built for this type of network visualization and analysis?

    Cloud Security Posture Management (CSPM)

    • A. Asset Inventory
    • B. Compliance Policies
    • C. Network Explorer
    • D. Resource Explorer
    Show answer

    C. Network Explorer

    The Network Explorer in Prisma Cloud provides a graphical representation of network topology, showing ingress/egress paths, security group rules, NACLs, and internet connectivity, which is precisely what's needed to analyze network connections related to the alert.

  20. 20. A financial institution uses Prisma Cloud to enforce strict compliance with PCI DSS. They have identified a requirement to ensure all databases storing cardholder data (CHD) are encrypted at rest. How can a security engineer MOST effectively create a custom policy in Prisma Cloud to specifically check for unencrypted RDS instances tagged as 'DataClassification:PCI-DSS' across all connected AWS accounts?

    Cloud Security Posture Management (CSPM)

    • A. Use a built-in compliance policy for PCI DSS and manually filter for RDS instances.
    • B. Develop a serverless function to poll AWS for unencrypted RDS instances and send findings to Prisma Cloud via API.
    • C. Utilize RQL in a Custom Policy to query for 'config from cloud.resource where resourceType = 'aws_rds_db_instance' and tags.DataClassification = 'PCI-DSS' and encrypted = false'.
    • D. Create a new alert rule in Alert Management to look for unencrypted RDS.
    Show answer

    C. Utilize RQL in a Custom Policy to query for 'config from cloud.resource where resourceType = 'aws_rds_db_instance' and tags.DataClassification = 'PCI-DSS' and encrypted = false'.

    Custom Policies in Prisma Cloud allow organizations to define their own compliance checks using RQL (Resource Query Language). This enables precise targeting of specific resource types, tags, and configuration attributes across all monitored accounts, making it the most effective way to enforce a custom, tagged-based encryption policy.

  21. 21. A global organization is utilizing Prisma Cloud for its multi-cloud environment. They have a strict compliance requirement to ensure that all S3 buckets storing sensitive customer data are encrypted with Server-Side Encryption with AWS Key Management Service (SSE-KMS) and that the KMS keys used are customer-managed (CMK), not AWS-managed (AMK). Which RQL query would accurately identify S3 buckets that are NOT encrypted with SSE-KMS using a customer-managed key?

    Cloud Security Posture Management (CSPM)

    • A. config from aws.s3.bucket where encryption.type = 'AES256'
    • B. config from aws.s3.bucket where encryption.type != 'aws:kms' or not encryption.kmsKeyId starts with 'arn:aws:kms:' or encryption.kmsKeyId contains ':alias/aws/'
    • C. config from aws.s3.bucket where encryption.type = 'aws:kms' and encryption.kmsKeyId starts with 'arn:aws:kms:' and not encryption.kmsKeyId ends with ':alias/aws/'
    • D. config from aws.s3.bucket where encryption.type != 'aws:kms' or encryption.kmsKeyId ends with ':alias/aws/'
    Show answer

    B. config from aws.s3.bucket where encryption.type != 'aws:kms' or not encryption.kmsKeyId starts with 'arn:aws:kms:' or encryption.kmsKeyId contains ':alias/aws/'

    The requirement is to find buckets NOT encrypted with SSE-KMS using a customer-managed key. This means we are looking for buckets where either the encryption type is not 'aws:kms' OR the KMS key ID does not start with 'arn:aws:kms:' (indicating it's not a KMS key) OR it's an AWS-managed key (indicated by ':alias/aws/'). Option D correctly captures these conditions using OR logic.

  22. 22. A security operations center (SOC) analyst is using Prisma Cloud to investigate a series of alerts related to suspicious API calls originating from a compromised IAM user in AWS. The analyst needs to reconstruct the sequence of events, including when the user was created, when suspicious activity started, and what resources were accessed. Which Prisma Cloud feature allows for a consolidated timeline view of these security events and configuration changes?

    Cloud Security Posture Management (CSPM)

    • A. Audit Logs
    • B. Cloud Security Governance
    • C. Alert Management
    • D. Asset Inventory
    Show answer

    A. Audit Logs

    Prisma Cloud integrates and normalizes audit logs (e.g., AWS CloudTrail, Azure Activity Logs) from various cloud providers. These logs provide a chronological record of all API calls, user activities, and configuration changes, which is crucial for reconstructing a timeline of events during an investigation.

  23. 23. A global organization uses Prisma Cloud to enforce compliance with GDPR across its AWS, Azure, and GCP environments. They need to create a custom compliance standard that maps specific Prisma Cloud policies to GDPR articles. Which of the following is the correct workflow to achieve this?

    Cloud Security Posture Management (CSPM)

    • A. Go to Policies > Compliance > Add New Compliance Standard, then manually create and assign policies.
    • B. Go to Compliance > Custom Standards > Add New, then import GDPR-specific policies from a template.
    • C. Go to Policies > Policy Management > Create Custom Policy, then tag policies with 'GDPR'.
    • D. Go to Compliance > Standards > Create New Standard, then map existing Prisma Cloud policies.
    Show answer

    D. Go to Compliance > Standards > Create New Standard, then map existing Prisma Cloud policies.

    In Prisma Cloud, custom compliance standards are created under 'Compliance > Standards'. Once a new standard is created, you can then map relevant Prisma Cloud policies (both default and custom) to the specific requirements or articles of that standard, such as GDPR.

  24. 24. A security analyst receives a high volume of alerts from Prisma Cloud related to 'S3 bucket not encrypted' for development environments. The team acknowledges that these specific buckets, used for temporary, non-sensitive data, do not require encryption at rest, and the alerts are causing unnecessary noise. What is the most effective Prisma Cloud feature to reduce these specific alerts without disabling the policy for other critical environments?

    Cloud Security Posture Management (CSPM)

    • A. Create an alert rule to automatically close these alerts.
    • B. Disable the 'S3 bucket not encrypted' compliance policy globally.
    • C. Modify the policy to exclude development environments.
    • D. Apply an alert suppression rule based on specific resource tags or account IDs.
    Show answer

    D. Apply an alert suppression rule based on specific resource tags or account IDs.

    Alert suppression rules allow organizations to filter out specific alerts based on criteria like resource tags, account IDs, or policy names, ensuring that legitimate alerts are still generated for other environments while reducing noise from known acceptable deviations.

  25. 25. A security analyst receives a high volume of alerts from Prisma Cloud related to 'S3 bucket public access' in a development environment. While these alerts are valid, the development team frequently creates and deletes public buckets for testing purposes, leading to alert fatigue. What is the most effective Prisma Cloud feature to manage this specific scenario without ignoring critical alerts from production environments?

    Cloud Security Posture Management (CSPM)

    • A. Alert Suppression
    • B. Compliance Policies
    • C. Automated Remediation
    • D. Cloud Security Governance
    Show answer

    A. Alert Suppression

    Alert Suppression allows security teams to define rules to filter out or snooze alerts based on specific criteria (e.g., environment, resource tags, policy). This is ideal for managing known, acceptable risks in non-production environments without affecting monitoring in production.

Palo Alto Networks Certified Cloud Security Engineer (PCCSE) flashcards

Tap a card to flip it. 146 flashcards in the full deck.

  • RQL Logical Operator: AND

    Flip card

    The 'AND' logical operator in Resource Query Language (RQL) is used to combine multiple conditions, requiring all specified conditions to be true for a resource to be included in the query results.

    • Requires all combined conditions to be met.
    • Used for narrowing down results based on multiple criteria.
    • Essential for precise filtering in custom policies.
    Study this card →
  • Prisma Cloud Attack Path Analysis

    Flip card

    A Prisma Cloud feature that identifies and visualizes potential attack vectors by chaining together misconfigurations, vulnerabilities, and overly permissive access between cloud resources.

    • Visualizes interconnected risks.
    • Quantifies the impact of a compromise.
    • Helps prioritize remediation efforts.
    Study this card →
  • Prisma Cloud Resource Explorer

    Flip card

    A Prisma Cloud feature enabling security teams to perform powerful, ad-hoc queries on their cloud asset inventory using RQL (Resource Query Language).

    • Uses RQL for flexible querying.
    • Allows filtering by resource type, region, tags, network details, and more.
    • Provides a comprehensive view of all inventoried cloud resources.
    Study this card →
  • RQL Region Attribute

    Flip card

    The 'region' attribute in Resource Query Language (RQL) allows users to filter and query cloud resources based on their geographical deployment region, enabling enforcement of data residency and compliance with regional regulations.

    • Filters resources by geographic location.
    • Crucial for data residency compliance (e.g., GDPR).
    • Applicable across all supported cloud providers.
    Study this card →
  • Prisma Cloud Network Explorer

    Flip card

    A visual tool within Prisma Cloud that maps network topology, security controls, and traffic flows across cloud environments.

    • Shows inter-resource connectivity.
    • Visualizes security group and NACL rules.
    • Helps identify potential lateral movement and egress points.
    Study this card →
  • Prisma Cloud Alert Suppression

    Flip card

    A mechanism to reduce alert noise by preventing alerts from being generated or by automatically dismissing them based on defined criteria.

    • Can be configured based on policies, accounts, tags, or resource types.
    • Helps focus on critical alerts.
    • More granular than disabling policies.
    Study this card →
  • Prisma Cloud Attack Path Remediation

    Flip card

    Identifying and implementing the most effective action to disrupt a potential attack path identified by Prisma Cloud's analysis.

    • Focuses on breaking the chain of compromise.
    • Often involves removing initial exposure or critical vulnerabilities.
    • Prioritizes actions with the highest impact on reducing risk.
    Study this card →
  • Prisma Cloud CSP Audit Log Integration

    Flip card

    Prisma Cloud integrates with Cloud Service Provider (CSP) audit logs (e.g., CloudTrail, Activity Log) to ingest activity data, providing detailed information about who made changes to cloud resources, when, and what API calls were involved, which is essential for forensic analysis and compliance.

    • Ingests native cloud audit logs.
    • Captures 'who', 'what', 'when' of changes.
    • Crucial for compliance and forensic investigations.
    Study this card →
  • Cloud Account Onboarding

    Flip card

    The foundational process of connecting a cloud environment to Prisma Cloud, granting it necessary permissions to discover and collect data about cloud resources.

    • First step for any CSPM activity.
    • Involves granting read-only access.
    • Enables resource discovery and data collection.
    Study this card →
  • Prisma Cloud Automated Remediation

    Flip card

    Prisma Cloud's capability to automatically correct security misconfigurations or policy violations, often through integrations with cloud-native automation services.

    • Can trigger serverless functions (Lambda, Cloud Functions).
    • Enables self-healing cloud environments.
    • Requires careful planning to avoid unintended service disruptions.
    Study this card →
  • Prisma Cloud Data Residency Enforcement (RQL)

    Flip card

    Using Prisma Cloud's Resource Query Language (RQL) to create custom policies that continuously monitor and enforce data residency requirements across multi-cloud environments.

    • Leverages RQL for granular region-based queries.
    • Applicable across AWS, Azure, GCP.
    • Ensures continuous monitoring for data residency compliance.
    Study this card →
  • RQL for GCP External IPs

    Flip card

    In Prisma Cloud's Resource Query Language (RQL), the `network.externalIp` attribute is used to identify GCP Compute Engine instances that have external (public) IP addresses assigned, allowing for filtering based on public exposure.

    • Identifies public IP presence on GCP instances.
    • Part of the `network` object for instances.
    • Crucial for assessing internet exposure.
    Study this card →
  • Prisma Cloud Automated Remediation Prerequisites

    Flip card

    Conditions that must be met for Prisma Cloud to successfully perform automated corrective actions on cloud resources.

    • Requires specific IAM permissions (Remediation access).
    • Policy must be configured for automated remediation.
    • Supported for specific resource types and cloud providers.
    Study this card →
  • Prisma Cloud Custom Policies

    Flip card

    User-defined compliance rules in Prisma Cloud, crafted using RQL, to enforce specific security standards and organizational requirements.

    • Leverage RQL for powerful and flexible rule creation.
    • Can target specific resource types, tags, and configuration attributes.
    • Enable enforcement of unique organizational policies beyond built-in standards.
    Study this card →
  • RQL for SSE-KMS CMK

    Flip card

    Resource Query Language (RQL) queries in Prisma Cloud can be used to identify S3 buckets based on their encryption configuration, specifically differentiating between Server-Side Encryption with AWS KMS (SSE-KMS) using customer-managed keys (CMKs) versus AWS-managed keys (AMKs).

    • SSE-KMS uses 'aws:kms' as encryption type.
    • CMKs have a specific ARN format and do not contain ':alias/aws/'.
    • AMKs often contain ':alias/aws/' in their key ID or are implicitly AWS managed.
    Study this card →
  • Prisma Cloud Audit Log Integration

    Flip card

    Prisma Cloud's capability to ingest, normalize, and analyze cloud provider audit logs (e.g., CloudTrail, Activity Logs) to provide a historical record of events and configuration changes.

    • Crucial for incident response and forensic analysis.
    • Provides a chronological timeline of user and API activity.
    • Helps identify root causes and scope of security incidents.
    Study this card →
  • Prisma Cloud Custom Compliance Standards

    Flip card

    Allows users to define new compliance frameworks and map existing Prisma Cloud policies to their specific requirements.

    • Extends Prisma Cloud's compliance reporting.
    • Maps to internal or external regulations (e.g., GDPR, HIPAA).
    • Provides a consolidated view of compliance posture against custom standards.
    Study this card →
  • Prisma Cloud Resource Query Language (RQL)

    Flip card

    A powerful query language used in Prisma Cloud to search, filter, and identify cloud resources based on their configurations, attributes, and relationships.

    • Enables precise resource identification.
    • Supports complex queries for tags, metadata, and configurations.
    • Used to build custom policies and investigate alerts.
    Study this card →
  • Prisma Cloud Asset Inventory

    Flip card

    A feature that continuously discovers, catalogs, and monitors all cloud resources across integrated cloud environments.

    • Automates resource discovery.
    • Provides a unified view of all cloud assets.
    • Feeds data to policies and other security features.
    Study this card →
  • Prisma Cloud AWS Onboarding

    Flip card

    The process of integrating an AWS account with Prisma Cloud for security monitoring, typically leveraging IAM roles for secure, granular access.

    • IAM roles are preferred over IAM users for cross-account access.
    • External ID enhances security by preventing the confused deputy problem.
    • Least privilege principle should always be applied to assigned policies.
    Study this card →
  • Prisma Cloud Onboarding Scope

    Flip card

    The ability to define specific cloud resources (e.g., by resource group, region, or tags) that Prisma Cloud will monitor during the initial account onboarding process.

    • Allows for granular control over ingested assets.
    • Reduces noise and focuses monitoring on critical resources.
    • Configured during the initial cloud account setup.
    Study this card →
  • Prisma Cloud Account Access Type

    Flip card

    The method and level of permissions granted to Prisma Cloud to access and ingest configuration data from a cloud environment during onboarding.

    • Crucial for comprehensive data collection.
    • Typically uses read-only IAM roles/service principals.
    • Determines visibility across regions and services.
    Study this card →
  • Prisma Cloud Compliance Policies

    Flip card

    Rules within Prisma Cloud that continuously monitor cloud resources against predefined security standards, regulatory frameworks, and custom organizational requirements.

    • Enforce industry standards (PCI DSS, HIPAA).
    • Provide continuous monitoring.
    • Generate reports on compliance posture.
    Study this card →
  • Prisma Cloud Custom Policy (RQL)

    Flip card

    User-defined policies created using Resource Query Language (RQL) to detect specific configurations or misconfigurations across cloud environments.

    • Provides maximum flexibility for detection.
    • Supports multi-cloud attribute-based filtering.
    • Can be integrated into compliance standards and automated remediation.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.