[Jan-2023] Exam PCCSE: New Brain Dump Professional - CramPDF
Free PCCSE Exam Dumps to Improve Exam Score
How much does Palo-Alto-Networks PCCSE: Prisma Certified Cloud Security Engineer Exam Cost
The price of PCCSE exam is $160 USD.
For more info visit:
Palo Alto Networks PCCSE Exam Reference
Exam Information and Practice Material
NEW QUESTION 11
What are the two ways to scope a CI policy for image scanning? (Choose two.)
- A. container name
- B. image labels
- C. hostname
- D. image name
Answer: B,D
NEW QUESTION 12
A Prisma Cloud administrator is tasked with pulling a report via API The Prisma Cloud tenant is located on app2.pnsmacfoudjo. What is the correct API endpoint?
- A. https://api2eu-prismacioud.io
- B. https //api2-prismacloud io
- C. https://api pnsmacloud.cn
- D. https://api.prismactoud.io
Answer: A
NEW QUESTION 13
An administrator wants to install the Defenders to a Kubernetes cluster. This cluster is running the console on the default service endpoint and will be exporting to YAML Console Address SCONSOLE_ADDRESS Websocket Address SWEBSOCKHT_ADDRESS User: SADMIN USER Which command generates the YAML file for Defender install?
A)
B)
C)
D)
- A. Option B
- B. Option C
- C. Option A
- D. Option D
Answer: C
NEW QUESTION 14
Which order of steps map a policy to a custom compliance standard?
(Drag the steps into the correct order of occurrence, from the first step to the last.)
Answer:
Explanation:
Explanation
1. click on compliance standard.
2. add custom compliance standard.
3. edit policies.
4. add compliance standard from drop-down menu
https://docs.prismacloudcompute.com/docs/enterprise_edition/compliance/custom_compliance_checks.html#cre
NEW QUESTION 15
Which port should a security team use to pull data from Console's API?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 16
An S3 bucket within AWS has generated an alert by violating the Prisma Cloud Default policy "AWS S3 buckets are accessible to public". The policy definition follows:
config where cloud.type = 'aws' AND api.name='aws-s3api-get-bucket-acl' AND json.rule="((((acl.grants[? (@.grantee=='AllUsers')] size > 0) or policyStatus.isPublic is true) and publicAccessBlockConfiguration does not exist) or ((acl.grants[?(@.grantee=='AllUsers')] size > 0) and publicAccessBlockConfiguration.ignorePublicAcis is false) or (policyStatus.isPublic is true and publicAccessBlockConfiguration.restrictPublicBuckets is false)) and websiteConfiguration does not exist" Why did this alert get generated?
- A. configuration of the S3 bucket
- B. network traffic to the S3 bucket
- C. anomalous behaviors
- D. an event within the cloud account
Answer: A
NEW QUESTION 17
A customer wants to be notified about port scanning network activities in their environment Which policy type detects this behavior?
- A. Anomaly
- B. Port Scan
- C. Network
- D. Config
Answer: A
NEW QUESTION 18
A security team has a requirement to ensure the environment is scanned for vulnerabilities. What are three options for configuring vulnerability policies? (Choose three.)
- A. apply policy only when vendor fix is available
- B. output verbosity for blocked requests
- C. individual grace periods for each severity level
- D. customize message on blocked requests
- E. individual actions based on package type
Answer: A,B,C
NEW QUESTION 19
How often do Defenders share logs with Console?
- A. Every 1 hour
- B. Real time
- C. Every 30 minutes
- D. Every 10 minutes
Answer: A
NEW QUESTION 20
An administrator wants to install the Defenders to a Kubernetes cluster. This cluster is running the console on the default service endpoint and will be exporting to YAML.
Console Address: $CONSOLE_ADDRESS Websocket Address: $WEBSOCKET_ADDRESS User: $ADMIN_USER Which command generates the YAML file for Defender install?
- A. <PLATFORM>/twistcli defender \
--address $CONSOLE_ADDRESS \
--user $ADMIN_USER \
--cluster-address $CONSOLE_ADDRESS - B. <PLATFORM>/twistcli defender export kubernetes \
--address $WEBSOCKET_ADDRESS \
--user $ADMIN_USER \
--cluster-address $CONSOLE_ADDRESS - C. <PLATFORM>/twistcli defender export kubernetes \
--address $CONSOLE_ADDRESS \
--user $ADMIN_USER \
--cluster-address $WEBSOCKET_ADDRESS - D. <PLATFORM>/twistcli defender YAML kubernetes \
--address $CONSOLE_ADDRESS \
--user $ADMIN_USER \
--cluster-address $WEBSOCKET_ADDRESS
Answer: C
NEW QUESTION 21
You wish to create a custom policy with build and run subtypes. Match the query types for each example.
(Select your answer from the pull-down list. Answers may be used more than once or not at all.)
Answer:
Explanation:
Reference:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/create-a- policy.html
NEW QUESTION 22
The security team wants to target a CNAF policy for specific running Containers. How should the administrator scope the policy to target the Containers?
- A. scope the policy to Defender names.
- B. scope the policy to namespaces.
- C. scope the policy to Host names.
- D. scope the policy to Image names.
Answer: B
NEW QUESTION 23
A security team notices a number of anomalies under Monitor > Events The incident response team works with the developers to determine that these anomalies are false positives.
What will be the effect if the security team chooses to Relearn on this image?
- A. The model is retained, and any new behavior observed during the new learning period will be added to the existing model
- B. The model is deleted, and Defender will releam for 24 hours.
- C. The model is deleted and returns to the initial learning state
- D. The anomalies detected will automatically be added to the model.
Answer: B
NEW QUESTION 24
A DevOps lead reviewed some system logs and notices some odd behavior that could be a data exfiltration attempt The DevOps lead only has access to vulnerability data in Prisma Cloud Compute, so the DevOps lead passes this information to SecOps Which pages in Prisma Cloud Compute can the SecOps lead use to investigate the runtime aspects of this attack?
- A. The SecOps lead should use the Incident Explorer page and Monitor > Events > Container Audits
- B. The SecOps lead should investigate the attack using Vulnerability Explorer and Runtime Radar
- C. The SecOps lead should review the vulnerability scans in the CI/CD process to determine blame
- D. The SecOps lead should use Incident Explorer and Compliance Explorer.
Answer: D
NEW QUESTION 25
What is an example of an outbound notification within Prisma Cloud?
- A. PagerDuty
- B. Tenable
- C. AWS Inspector
- D. Qualys
Answer: A
NEW QUESTION 26
Which two roles have access to view the Prisma Cloud policies? (Choose two.)
- A. Dev SecOps
- B. Auditor
- C. Build AND Deploy Security
- D. Defender Manager
Answer: B,D
NEW QUESTION 27
Given the following audit event activity snippet:
Which RQL will be triggered by the audit event?
A)
B)
C)
D)
- A. Option A
- B. Option C
- C. Option D
- D. Option B
Answer: D
NEW QUESTION 28
Which alert deposition severity must be chosen to generate low and high severity alerts in the Anomaly settings when user wants to report on an unknown browser and OS, impossible time travel, or both due to account hijacking attempts?
- A. Moderate
- B. Conservative
- C. High
- D. Aggressive
Answer: A
NEW QUESTION 29
The security team wants to protect a web application container from an SQLi attack? Which type of policy should the administrator create to protect the container?
- A. CNNF
- B. CNAF
- C. Runtime
- D. Compliance
Answer: A
NEW QUESTION 30
......
Powerful PCCSE PDF Dumps for PCCSE Questions: https://www.crampdf.com/PCCSE-exam-prep-dumps.html
2023 Realistic PCCSE Dumps Exam Tips Test Pdf Exam Material: https://drive.google.com/open?id=1V0Il0jKY9hUD1iHyksVWmM156PuBHGp0