Practice Test for PCCSE Certification Real 2022 Mock Exam
Prepare For Realistic PCCSE Dumps PDF - 100% Passing Guarantee
Palo Alto PCCSE Exam Certification Details:
| Passing Score | Variable (70-80 / 100 Approx.) |
| Duration | 90 minutes |
| Exam Code | PCCSE |
| Number of Questions | 75-85 |
| Exam Price | $175 USD |
| Exam Registration | PEARSON VUE |
| Exam Name | Cloud Security Engineer |
NEW QUESTION 50
A customer is reviewing Container audits, and an audit has identified a cryptominer attack. Which three options could have generated this audit? (Choose three.)
- A. The value of the mined currency exceeds $100.
- B. High CPU usage over time for the container is detected.
- C. Common cryptominer port usage was found.
- D. The mined currency is associated with a user token.
- E. Common cryptominer process name was found.
Answer: B,C,E
NEW QUESTION 51
Match the service on the right that evaluates each exposure type on the left.
(Select your answer from the pull-down list. Answers may be used more than once or not at all.)
Answer:
Explanation:
Reference:
https://www.paloaltonetworks.com/prisma/cloud/cloud-data-security
NEW QUESTION 52
How are the following categorized?
* Backdoor account access
* Hijacked processes
* Lateral movement
* Port scanning
- A. incidents
- B. admission controllers
- C. audits
- D. models
Answer: C
NEW QUESTION 53
Which statement is true regarding CloudFormation templates?
- A. Request-Header-Field 'cloudformation-version' is required to request a scan.
- B. A single template or a zip archive of template files cannot be scanned with a single API request.
- C. Scan support does not currently exist for nested references, macros, or intrinsic functions.
- D. Scan support is provided for JSON, HTML and YAML formats.
Answer: C
NEW QUESTION 54
Which component(s), if any will Palo Alto Networks host and run when a customer purchases Prisma Cloud Enterprise Edition?
- A. twistcli
- B. Defenders
- C. Jenkins
- D. Console
Answer: A
NEW QUESTION 55
A customer wants to be notified about port scanning network activities in their environment Which policy type detects this behavior?
- A. Port Scan
- B. Network
- C. Config
- D. Anomaly
Answer: D
NEW QUESTION 56
The Unusual protocol activity (Internal) network anomaly is generating too many alerts. An administrator has been asked to tune it to the option that will generate the least number of events without disabling it entirely.
Which strategy should the administrator use to achieve this goal?
- A. Set the Alert Disposition to Conservative
- B. Change the Training Threshold to Low
- C. Set Alert Disposition to Aggressive
- D. Disable the policy
Answer: B
Explanation:
Section: (none)
Explanation
NEW QUESTION 57
Which intensity setting for anomaly alerts is used for the measurement of 100 events over 30 days?
- A. High
- B. Very High
- C. Low
- D. Medium
Answer: D
NEW QUESTION 58
A customer has a requirement to automatically protect all Lambda functions with runtime protection. What is the process to automatically protect all the Lambda functions?
- A. Configure a manually embedded Lambda Defender.
- B. Configure a function scan policy from the Defend/Vulnerabilities/Functions page
- C. Configure a serveriess auto-protect rule for the functions.
- D. Configure serveriess radar from the Defend/Compliance/Cloud Platforms page
Answer: D
NEW QUESTION 59
An administrator sees that a runtime audit has been generated for a host.
The audit message is:
'Service postfix attempted to obtain capability SHELL by executing /bin/sh /usr/libexec/postfix/postfix-script stop. Low severity audit event is automatically added to the runtime mode'' Which runtime host policy rule is the root cause for this runtime audit?
- A. Custom rule with specific configuration for file integrity
- B. Custom rule with specific configuration for networking
- C. Default rule that alerts on suspicious runtime behavior
- D. Default rule that alerts on capabilities
Answer: C
NEW QUESTION 60
Which three steps are involved in onboarding an account for Data Security? (Choose three.)
- A. Create a Cloudtrail with SNS Topic
- B. Create a read-only role with in-line policies
- C. Enable Flow Logs
- D. Create a S3 bucket
- E. Enter the RoleARN and SNSARN
Answer: A,C,D
NEW QUESTION 61
A security team has been asked to create a custom policy.
Which two methods can the team use to accomplish this goal? (Choose two )
- A. disable an out-of-the-box policy
- B. add a new policy
- C. edit the query in the out-of-the-box policy
- D. clone an existing policy
Answer: A,D
NEW QUESTION 62
A Prisma Cloud administrator is tasked with pulling a report via API. The Prisma Cloud tenant is located on app2.prismacloud.io.
What is the correct API endpoint?
- A. https://api2.eu.prismacloud.io
- B. https://api2.prismacloud.io
- C. httsp://api.prismacloud.cn
- D. https://api.prismacloud.io
Answer: D
NEW QUESTION 63
Match the correct scanning mode for each given operation.
(Select your answer from the pull-down list. Answers may be used more than once or not at all.)
Answer:
Explanation:
Explanation
Diagram Description automatically generated
NEW QUESTION 64
The development team wants to fail CI jobs where a specific CVE is contained within the image. How should the development team configure the pipeline or policy to produce this outcome?
- A. Set the specific CVE exception as an option in Jenkins or twistcli.
- B. Set the specific CVE exception as an option in Defender running the scan.
- C. Set the specific CVE exception in Console's CI policy.
- D. Set the specific CVE exception as an option using the magic string in the Console.
Answer: D
NEW QUESTION 65
You wish to create a custom policy with build and run subtypes. Match the query types for each example.
(Select your answer from the pull-down list. Answers may be used more than once or not at all.)
Answer:
Explanation:

NEW QUESTION 66
A customer has a requirement to scan serverless functions for vulnerabilities. Which three settings are required to configure serverless scanning? (Choose three )
- A. Region
- B. Provider
- C. Credential
- D. Defender Name
- E. Console Address
Answer: B,D,E
NEW QUESTION 67
Which option shows the steps to install the Console in a Kubernetes Cluster?
- A. Download the Console and Defender image Download YAML for Defender from the document site Deploy Defender YAML using kubectl
- B. Download the Console and Defender image Generate YAML for Defender
Deploy Defender YAML using kubectl - C. Download and extract release tarball Download the YAML for Console Deploy Console YAML using kubectl
- D. Download and extract release tarball Generate YAML for Console
Deploy Console YAML using kubectl
Answer: D
NEW QUESTION 68
Which "kind" of Kubernetes object that is configured to ensure that Defender is acting as the admission controller?
- A. DestinationRules
- B. MutatingWebhookConfiguration
- C. ValidatingWebhookConfiguration
- D. PodSecurityPolicies
Answer: B
NEW QUESTION 69
......
Download PCCSE Exam Dumps Questions to get 100% Success: https://certkingdom.vce4dumps.com/PCCSE-latest-dumps.html