ExamGecko

Palo Alto Networks PCCSE Practice Test - Questions Answers, Page 24

Question list
Search
Search

List of questions

Search

Which three options for hardening a customer environment against misconfiguration are included in Prisma Cloud Compute compliance enforcement for hosts? (Choose three.)

A.
Serverless functions
A.
Serverless functions
Answers
B.
Docker daemon configuration
B.
Docker daemon configuration
Answers
C.
Cloud provider tags
C.
Cloud provider tags
Answers
D.
Host configuration
D.
Host configuration
Answers
E.
Hosts without Defender agents
E.
Hosts without Defender agents
Answers
Suggested answer: B, D, E

Explanation:

Prisma Cloud scans all hosts for compliance issues, provided that a defender is installed or the host is covered by an agentless scan. Among these, the following compliance issues are covered.

-Host configuration

-Docker daemon configuration

https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/compliance/host_scanning

Prisma Cloud Compute's compliance enforcement capabilities for hosts include ensuring proper configurations of Docker daemons and host operating systems, as well as managing hosts that do not have Defender agents installed. These measures are critical for hardening environments against misconfigurations which could lead to security vulnerabilities.

Creation of a new custom compliance standard that is based on other individual custom compliance standards needs to be automated.

Assuming the necessary data from other standards has been collected, which API order should be used for this new compliance standard?

A.
1) https://api.prismacloud.io/compliance/add 2) https://api.prismacloud.io/compliance/requirementld/section 3) https://api.prismacloud.io/compliance/complianceld/requirement
A.
1) https://api.prismacloud.io/compliance/add 2) https://api.prismacloud.io/compliance/requirementld/section 3) https://api.prismacloud.io/compliance/complianceld/requirement
Answers
B.
1) https://api.prismacloud.io/compliance 2) https://api.prismacloud.io/compliance/complianceld/requirement 3) https://api.prismacloud.io/compliance/requirementld/section
B.
1) https://api.prismacloud.io/compliance 2) https://api.prismacloud.io/compliance/complianceld/requirement 3) https://api.prismacloud.io/compliance/requirementld/section
Answers
C.
1) https://api.prismacloud.io/compliance/add 2) https://api.prismacloud.io/compliance/complianceld/requirement 3) https://api.prismacloud.io/compliance/requirementld/section
C.
1) https://api.prismacloud.io/compliance/add 2) https://api.prismacloud.io/compliance/complianceld/requirement 3) https://api.prismacloud.io/compliance/requirementld/section
Answers
D.
1) https://api.prismacloud.io/compliance 2) https://api.prismacloud.io/compliance/requirementld/section 3) https://api.prismacloud.io/compliance/complianceld/requirement
D.
1) https://api.prismacloud.io/compliance 2) https://api.prismacloud.io/compliance/requirementld/section 3) https://api.prismacloud.io/compliance/complianceld/requirement
Answers
Suggested answer: B

Explanation:

https://api.prismacloud.io/compliance Add Compliance Standard https://api.prismacloud.io/compliance/complianceld/requirement Add Compliance Requirement https://api.prismacloud.io/compliance/requirementld/section Add Compliance Requirement Section https://pan.dev/prisma-cloud/api/cspm/get-all-standards/

Which report includes an executive summary and a list of policy violations, including a page with details for each policy?

A.
Compliance Standard
A.
Compliance Standard
Answers
B.
Business Unit
B.
Business Unit
Answers
C.
Cloud Security Assessment
C.
Cloud Security Assessment
Answers
D.
Detailed
D.
Detailed
Answers
Suggested answer: C

Explanation:

The Cloud Security Assessment report is a PDF report that summarizes the risks from open alerts in the monitored cloud accounts for a specific cloud type. The report includes an executive summary and a list of policy violations, including a page with details for each policy that includes the description and the compliance standards that are associated with it, the number of resources that passed and failed the check within the specified time period. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-alerts/generate-reports-on-prisma-cloud-alerts

The report that includes an executive summary along with a list of policy violations and detailed pages for each policy is the 'Cloud Security Assessment' report. This type of report is designed to provide organizations with a comprehensive overview of their cloud security posture, highlighting both compliance with security policies and areas needing attention.

A customer's Security Operations Center (SOC) team wants to receive alerts from Prisma Cloud via email once a day about all policies that have a violation, rather than receiving an alert every time a new violation occurs.

Which alert rule configuration meets this requirement?

A.
Configure an alert rule with all the defaults except selecting email within the 'Alert Notifications' tab and specifying recipient.
A.
Configure an alert rule with all the defaults except selecting email within the 'Alert Notifications' tab and specifying recipient.
Answers
B.
Configure an alert rule. Under the 'Policies' tab, select 'High Risk Severity Policies.' In the 'Set Alert Notifications' tab, select 'Email > Recurring,' set to repeat every 1 day, and enable 'Email.'
B.
Configure an alert rule. Under the 'Policies' tab, select 'High Risk Severity Policies.' In the 'Set Alert Notifications' tab, select 'Email > Recurring,' set to repeat every 1 day, and enable 'Email.'
Answers
C.
Set up email integrations under the 'Integrations' tab in 'Settings' and create a notification template.
C.
Set up email integrations under the 'Integrations' tab in 'Settings' and create a notification template.
Answers
D.
Configure an alert rule. Under the 'Policies' tab, select 'All Policies.' In the 'Set Alert Notifications' tab, select 'Email > Recurring,' set to repeat every 1 day, and then enable 'Email.'
D.
Configure an alert rule. Under the 'Policies' tab, select 'All Policies.' In the 'Set Alert Notifications' tab, select 'Email > Recurring,' set to repeat every 1 day, and then enable 'Email.'
Answers
Suggested answer: D

Explanation:

To receive daily email alerts for all policy violations, the SOC team should configure an alert rule that encompasses all policies and sets the notification frequency to once per day. This can be achieved by:

Navigating to the ''Policies'' tab within the alert rule configuration and selecting ''All Policies'' to ensure that the rule applies to every policy.

Moving to the ''Set Alert Notifications'' tab and choosing the ''Email'' notification method.

Setting the notification to ''Recurring'' with a frequency of every 1 day.

Enabling the email notification by specifying the recipient's email address.

This configuration ensures that the SOC team will receive a consolidated email once a day that includes information on all policies that have been violated, rather than receiving multiple alerts throughout the day as new violations occur. It allows the team to review the compliance status efficiently and prioritize their response accordingly.

Where can a user submit an external new feature request?

A.
Aha
A.
Aha
Answers
B.
Help Center
B.
Help Center
Answers
C.
Support Portal
C.
Support Portal
Answers
D.
Feature Request
D.
Feature Request
Answers
Suggested answer: A

Explanation:

https://prismacloud.ideas.aha.io/ideas

To submit an external new feature request for Prisma Cloud, users can utilize theAhaplatform. By accessing the Palo Alto Networks Aha portal, users can submit their feature requests, suggest enhancements, and contribute to shaping the future of Prisma Cloud. Aha provides a structured way to collect and prioritize customer feedback, ensuring that valuable insights reach the product development teams.

For those seeking to propose new features or improvements, visiting the Aha portal and submitting their ideas is the recommended approach.It allows users to participate in the ongoing evolution of Prisma Cloud by sharing their requirements and vision for the platform

Which of the following is a reason for alert dismissal?

A.
SNOOZED_AUTO_CLOSE
A.
SNOOZED_AUTO_CLOSE
Answers
B.
ALERT_RULE_ADDED
B.
ALERT_RULE_ADDED
Answers
C.
POLICY_UPDATED
C.
POLICY_UPDATED
Answers
D.
USER_DELETED
D.
USER_DELETED
Answers
Suggested answer: C

Explanation:

https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-alerts/prisma-cloud-alert-resolution-reasons

In Prisma Cloud,POLICY_UPDATEDis a valid reason for the dismissal of an alert. This reason indicates that an alert can be dismissed if the policy that triggered the alert has been updated. When a policy is updated to no longer apply to certain resources or conditions, any open alerts that were generated based on the previous version of the policy may be dismissed as they are no longer relevant.

The other options, such as SNOOZED_AUTO_CLOSE, ALERT_RULE_ADDED, and USER_DELETED, are not standard reasons for the dismissal of an alert in Prisma Cloud. SNOOZED_AUTO_CLOSE refers to the temporary suspension of an alert, ALERT_RULE_ADDED is related to the creation of a new alert rule, and USER_DELETED would pertain to the removal of a user account, not directly to alert dismissal.

Which two statements explain differences between build and run config policies? (Choose two.)

A.
Run and Network policies belong to the configuration policy set.
A.
Run and Network policies belong to the configuration policy set.
Answers
B.
Build policies allow checking for security misconfigurations in the IaC templates and ensure these issues do not get into production.
B.
Build policies allow checking for security misconfigurations in the IaC templates and ensure these issues do not get into production.
Answers
C.
Run policies monitor network activities in the environment and check for potential issues during runtime.
C.
Run policies monitor network activities in the environment and check for potential issues during runtime.
Answers
D.
Run policies monitor resources and check for potential issues after these cloud resources are deployed.
D.
Run policies monitor resources and check for potential issues after these cloud resources are deployed.
Answers
Suggested answer: B, D

Explanation:

The Run policies monitor resources and check for potential issues once these cloud resources are deployed Build policies enable you to check for security misconfigurations in the IaC templates and ensure that these issues do not make their way into production. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/create-a-policy

B . Build policies: These are designed to identify insecure configurations in your Infrastructure as Code (IaC) templates, such as AWS CloudFormation, HashiCorp Terraform, and Kubernetes App manifests. The goal of build policies is to detect security issues early in the development process, before the actual resources are deployed in runtime environments.This helps ensure that security issues are identified and remediated before they can affect production1.

D . Run policies: These policies are focused on monitoring the deployed cloud resources and checking for potential issues during their operation.Run policies are essential for ongoing security and compliance in the production environment, as they provide visibility into the actual state of resources and their activities1.

Run and Network policies (A) are indeed part of the configuration policy set, but they do not highlight the difference between build and run policies. Similarly, while Run policies do monitor network activities , this statement does not contrast them with Build policies.

DRAG DROP

Order the steps involved in onboarding an AWS Account for use with Data Security feature.


Question 238
Correct answer: Question 238

DRAG DROP

An administrator has been tasked with creating a custom service that will download any existing compliance report from a Prisma Cloud Enterprise tenant.

In which order will the APIs be executed for this service?

(Drag the steps into the correct order of occurrence, from the first step to the last.)


Question 239
Correct answer: Question 239

DRAG DROP

Which order of steps map a policy to a custom compliance standard?

(Drag the steps into the correct order of occurrence, from the first step to the last.)


Question 240
Correct answer: Question 240
Total 260 questions
Go to page: of 26