Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

PSE-PrismaCloud PSE Palo Alto Networks System Engineer Professional - Prisma Cloud Questions and Answers

Questions 4

How can all alerts related to "Amazon RDS" be quickly identified within the Prisma Cloud dashboard?

Options:

A.

Generate a Center for Internet Security (CIS) compliance report and search for "Amazon RDS" policy violations.

B.

View the alert data on the "Asset Inventory" dashboard and filter on "Amazon RDS.

C.

Within the "Alerts" tab. filter on "Amazon RDS" as a service.

D.

Create a custom Resource Query Language (RQL) configuration report.

Buy Now
Questions 5

Which type of Prisma Cloud Enterprise alert supports autoremediation?

Options:

A.

network

B.

audit

C.

anomaly

D.

config

Buy Now
Questions 6

Which option is defined by the creation and change of public cloud services managed in a repeatable and predictable fashion?

Options:

A.

platform as a service

B.

infrastructure as a service

C.

software as code

D.

infrastructure as code

Buy Now
Questions 7

What are two benefits of Cloud Security Posture Management (CSPM) over other solutions? (Choose two.)

Options:

A.

guaranteed proof of concept (POC) extensions beyond 30 days

B.

native integration of network, endpoint, and cloud data to stop attacks

C.

elimination of blind spots

D.

proactive addressing of risks

Buy Now
Questions 8

How does Prisma Cloud Enterprise autoremediate unwanted violations to public cloud infrastructure?

Options:

A.

It inspects the application program interface (API) call made to public cloud and blocks the change if a policy violation is found.

B.

It makes changes after a policy violation has been identified in monitoring.

C.

It locks all changes to public cloud infrastructure and stops any configuration changes without prior approval.

D.

It uses machine learning (ML) to identify unusual changes to infrastructure.

Buy Now
Questions 9

Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)

Options:

A.

Excessive login failures

B.

Unusual user activity

C.

Denial-of-service activity

D.

Account hijacking attempts

E.

Suspicious file activity

Buy Now
Questions 10

Which RQL query should be used to quickly identify any events related to an organization's Google Cloud Platform Big Query database the last 24 hours?

Options:

A.

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'Google Bigtable Instance'

B.

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'cloudsql.googleapis.com'

C.

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'bigquery.googleapis.com'

D.

event from cloud.audit_logs where cloud.type = 'gcp' AND cloud.service = 'dataproc.googleapis.com'

Buy Now
Questions 11

Which Resource Query Language (RQL) query monitors all "delete" activities for the user "user1"?

Options:

A.

event where crud = 'delete’ AND subject = 'user1'

B.

event where crud = 'delete'

C.

event where crud = 'delete' AND subject = 'user1' AND cloud.type = 'aws'

D.

event where subject = 'user1'

Buy Now
Questions 12

Which Resource Query Language (RQL) query searches for all Relational Database Service (RDS) instances that have a public IP address?

Options:

A.

config from cloud.resource where api.name = 'aws-rds-describe-db-instances' AND json.rule = storageEncrypted is false

B.

event from cloud.audit_logs where api.name = 'aws-rds-describe-db-instances' AND json.rule = publiclyAccessible is true

C.

config from cloud.resource where api.name = 'aws-rds-describe-db-instances' AND json.rule = publiclyAccessible is true

D.

config from cloud.resource where api.name = 'aws-ec2-describe-instances' AND json.rule = publiclyAccessible is true

Buy Now
Questions 13

Which pillar of the Prisma Cloud platform provides support for both public and private clouds as well as flexible agentless scanning and agent-based protection?

Options:

A.

Cloud Network Security

B.

Cloud Security Posture Management

C.

Cloud Identity Security

D.

Cloud Workload Protection (CWP)

Buy Now
Questions 14

Which statement is specific for Prisma Cloud when integrating into cloud environments?

Options:

A.

An AutoFocus license is included in Prisma Cloud.

B.

For multi-cloud environment licenses are required for the number of Prisma Cloud instances.

C.

Can be natively integrated into Prisma Access.

D.

No agents or proxies are required.

Buy Now
Questions 15

What is Prisma Public Cloud licensing based on?

Options:

A.

number of alerts generated

B.

number of accounts onboarded

C.

number of monitored workloads

D.

volume of flow logs consumed

Buy Now
Questions 16

An administrator has deployed an AWS transit gateway and used multiple VPC spokes to segregate a multi-tier application. The administrator also created a security VPC with multiple VM-Series NGFWs in an active/active deployment model via ECMP using Amazon Web Services VPN-based attachments.

What must be configured on the firewall to avoid asymmetric routing?

Options:

A.

source address translation

B.

destination address translation

C.

port address translation

D.

source and destination address translation

Buy Now
Questions 17

Which statement reflects the default vulnerability management policy?

Options:

A.

Policy rule order has little impact on optimization.

B.

Prisma Cloud scans images in all containers immediately upon policy activation.

C.

The default vulnerability policy rule has an alert threshold to critical.

D.

Prisma Cloud ships all vulnerability policy with a default alert for containers, hosts, and serverless functions.

Buy Now
Questions 18

Under which operating systems (OSs) is twistcli supported?

Options:

A.

Linux, macOS, and Windows

B.

Windows only

C.

Linux and Windows

D.

Linux, macOS, PAN-OS, and Windows

Buy Now
Questions 19

What are two ways to enable interface swap when deploying a VM-Series NGFW in Google Cloud Platform? (Choose two.)

Options:

A.

run the PAN-OS CLI command: set system mgmt-interface-swap enable yes

B.

run the PAN-OS CLI command: set system mgmt-interface-swap setting enable yes

C.

create a bootstrap file that includes the mgmt-interface-swap command

D.

in the Google Cloud Console Metadata Field, enter a key-value pair where mgmt-interface-swap is the key and enable is the value

Buy Now
Questions 20

Which option is true about VM-Series NGFW templates available from the Palo Alto Networks GitHub repository?

Options:

A.

Palo Alto Networks provides full support if a valid support license is in place.

B.

Support for the templates is available through Professional Services from Palo Alto Networks.

C.

Unless otherwise noted, these templates are released under an as-is. best effort support policy.

D.

The author of the template provides full support as long as the PAN-OS version specific to the template is supported.

Buy Now
Questions 21

In which two ways can Prisma Cloud Compute (PCC) edition be installed? (Choose two.)

Options:

A.

self-managed in a customer's own container platform

B.

self-contained hardware appliance

C.

as a stand-alone Windows application

D.

Cloud-hosted as part of a Prisma Cloud Enterprise tenant from Palo Alto Networks

Buy Now
Questions 22

What are the asset severity levels within Prisma Cloud asset inventory?

Options:

A.

Low, Medium, and High

B.

Low, Medium, High, and Critical

C.

Informational, Low, Medium, and High

D.

Low, Medium, High, Severe, and Critical

Buy Now
Questions 23

What are two valid image identifiers to designate trust? (Choose two.)

Options:

A.

repo

B.

trusted publisher

C.

registry

D.

base layer

Buy Now
Questions 24

Which two templates are supported by Cloud Code Security scan service? (Choose two.)

Options:

A.

Azure Resource Manager (ARM)

B.

Hyper Text Markup Language (HTML)

C.

GitHub

D.

Terraform

Buy Now
Questions 25

Which two resource types are included in the Prisma Cloud Enterprise licensing count? (Choose two.)

Options:

A.

Elastic Compute Cloud (EC2) instances

B.

Network Address Translation (NAT) gateways

C.

CloudFront distributions

D.

Security groups

Buy Now
Questions 26

Which two cloud providers support Load Balancers as next hop configurations for outbound connections? (Choose two.)

Options:

A.

Google Cloud Platform

B.

Microsoft Azure

C.

Oracle Cloud

D.

Amazon Web Services

Buy Now
Questions 27

The Microsoft Azure virtual network gateway supports which two site-to-site connectivity options? (Choose two.)

Options:

A.

Direct Connect

B.

Fast Connect

C.

IPsecVPN

D.

ExpressRoute

Buy Now
Questions 28

Which statement applies to vulnerability management policies?

Options:

A.

Host and serverless rules support blocking, whereas container rules do not.

B.

Rules explain the necessary actions when vulnerabilities are found in the resources of a customer environment.

C.

Policies for containers, hosts, and serverless functions are not separate.

D.

Rules are evaluated in an undefined order.

Buy Now
Questions 29

An Azure VNet has the IP network 10.0.0.0/16 with two subnets, 10.0.1.0/24 (used for web servers) and 10.0.2.0/24 (used for database servers). Which is a valid IP address to manage the VM-Series NGFW?

Options:

A.

10.0.1.254

B.

10.0.2.1

C.

10.0.3.255

D.

10.0.3.1

Buy Now
Questions 30

can you create a custom compliance standard in Prisma Public Cloud?

Options:

A.

Generate a new Compliance Report.

B.

Create compliance framework in a spreadsheet then import into Prisma Public Cloud.

C.

From Compliance tab, clone a default framework and customize.

D.

From Compliance tab > Compliance Standards, click "Add New."

Buy Now
Questions 31

What are three examples of outbound traffic flow? (Choose three.)

Options:

A.

issue yum update command on an instance inside Amazon Web Services

B.

Microsoft Windows inside Azure requesting a security patch

C.

web server inside Amazon Web Services receiving web requests from internet

D.

issue apt-get install command on an instance inside Amazon Web Services

E.

outgoing Prisma Public Cloud API calls

Buy Now
Questions 32

Which Resource Query Language (RQL) query returns a list of all TERMINATED Google Compute Engine (GCE) instances?

Options:

A.

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = status == TERMINATED

B.

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = TERMINATED

C.

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = status contains TERMINATED

D.

Config from.cloud.resource where api.name = „gcloud-compute-instance-list" and json.rule = is TERMINATED

Buy Now
Questions 33

Which two actions are appropriate when configuring Prisma Cloud to scan a registry? (Choose two.)

Options:

A.

Allow Prisma Cloud to automatically optimize registry scans with version pattern matching.

B.

Allow Prisma Cloud to automatically distribute the scan job across a pool of available Defenders.

C.

Explicitly specify the Defender to do the job.

D.

Explicitly specify the predefined version pattern-matching algorithm.

Buy Now
Questions 34

In which two ways does Palo Alto Networks VM orchestration help service providers automatically provision security instances and policies? (Choose two.)

Options:

A.

fully instrumented API

B.

Aperture Orchestration Engine

C.

VM Orchestration Policy Editor

D.

support for Dynamic Address Groups

Buy Now
Exam Code: PSE-PrismaCloud
Exam Name: PSE Palo Alto Networks System Engineer Professional - Prisma Cloud
Last Update: May 26, 2026
Questions: 115

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11