Practice Cloud-Security-Engineer Cloud Workload Protection questions with full explanations on every answer.
Start practicing
Cloud Workload Protection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise wants to enforce runtime protection for serverless functions in AWS Lambda without modifying function code layers. Which Prisma Cloud feature should be implemented?
2During a vulnerability scan of a container image in the Prisma Cloud Console, a custom Python package installed via pip shows as unpatched, but the CVE has a fixed version available. Why might Prisma Cloud still report the vulnerability as unresolved?
3An application running in a Kubernetes pod is attempting to make unauthorized outbound connections to a known command-and-control IP address. The Prisma Cloud Container Defender is deployed in the cluster. Which runtime defense rule should be configured to prevent this behavior?
4An administrator needs to scan container images stored in an Azure Container Registry (ACR) without deploying them to a running cluster. Which Prisma Cloud feature accomplishes this?
5A security engineer is troubleshooting a Web Application and API Security (WAAS) rule that is not inspecting HTTPS traffic flowing into a Kubernetes Ingress controller. What is the most likely cause?
6An administrator notices that Prisma Cloud Host Defenders deployed on AWS EC2 instances are failing to report back to the console. Security groups allow outbound traffic, but VPC Flow Logs show dropped packets on port 8084. What must the administrator verify?
7A security team wants to block high-severity Common Vulnerabilities and Exposures (CVEs) from being deployed into production clusters via CI/CD pipelines. Where should this policy be enforced using Prisma Cloud?
8A cloud security engineer needs to deploy Prisma Cloud defenders on a Kubernetes cluster. Which method provides the most automated deployment mechanism managed via the Kubernetes control plane?
9A container running inside a Kubernetes cluster was compromised, and the attacker attempted to modify the host's kernel parameters using sysctl. Which Prisma Cloud feature detects and prevents this action?
10Where in the Prisma Cloud Console can an administrator review compliance benchmark results (such as CIS benchmarks) for deployed container images and hosts?
11An administrator needs to install a Prisma Cloud Defender on a standalone Linux virtual machine that does not run Kubernetes or Docker. Which defender type should be selected?
12An organization runs sensitive workloads on Google Cloud Run. They need to protect these serverless container services against known vulnerabilities and runtime attacks. Which Prisma Cloud Defender architecture supports Cloud Run?
13An organization wants to ensure that no containers run with root privileges in their Amazon ECS clusters. Which Prisma Cloud policy type should be used to enforce this at runtime?
14A developer pushes a container image to a private registry, but Prisma Cloud fails to scan it. The registry uses self-signed SSL certificates. What action must the administrator take in the Prisma Cloud Console?
15A Linux host running a Prisma Cloud Defender experiences high CPU usage originating from the defender process during a scheduled container image scan. How can an administrator mitigate this impact on production workloads?
16An auditor requests a report showing all open vulnerabilities across all active container registries connected to Prisma Cloud. Where can this report be generated?
17A security engineer is reviewing container image scan results in Prisma Cloud and notices that a base image vulnerability is marked as 'Not Applicable'. What does this status indicate?
18A security team wants to ensure that any container attempting to access the cloud provider metadata service (e.g., 169.254.169.254) from within a compromised workload is blocked. Which Prisma Cloud feature provides this protection?
19An enterprise runs containerized microservices on AWS Elastic Kubernetes Service (EKS) and wants to enforce mutual TLS (mTLS) and network micro-segmentation managed via Prisma Cloud. Which feature should be configured?
20An administrator wants to view a visual map of all container services, hosts, and incoming network connections across their cloud environment in real time. Which Prisma Cloud Compute view provides this?
21An administrator needs to automatically scan container images as soon as they are built in a Jenkins CI/CD pipeline before pushing them to a registry. What tool should be integrated into Jenkins?
22A security analyst notices that Prisma Cloud is generating numerous false-positive alerts for a custom internal binary flagged as malware during host scans. How can the analyst resolve this issue permanently across the environment?
23During incident response, a security analyst notices that a Prisma Cloud Host Defender has generated an alert for an unknown binary execution, but the process was not blocked. What is the reason for this behavior?
24An application team is deploying serverless functions on Azure Functions. They need to protect the functions against injection attacks and runtime tampering using Prisma Cloud. Which deployment step is required?
25An enterprise uses Prisma Cloud Compute to scan Infrastructure as Code (IaC) templates in a GitHub repository before deployment. A Terraform script containing an insecure container security configuration is flagged. What tool and workflow were used?
26An administrator needs to check the health status and connectivity of all deployed Prisma Cloud Defenders across multiple cloud environments. Where should they look in the console?
27A container running a legacy web application is subjected to a distributed denial-of-service (DDoS) attack and application-layer vulnerability exploitation. The security team wants to block Layer 7 attacks while allowing legitimate HTTP traffic. Which Prisma Cloud feature should be deployed?
28An administrator wants to configure alerting so that security team members receive an email whenever a critical container vulnerability is discovered during a registry scan. Where is this configured?
29Which TWO actions can a Prisma Cloud Host Defender perform when installed on a Linux virtual machine? Select the two correct answers.
30An administrator is configuring Prisma Cloud Container Registry Scanning. Which THREE registry types are natively supported for automated scanning by Prisma Cloud? Select the three correct answers.
31Which TWO features are provided by Prisma Cloud Web Application and API Security (WAAS) for containerized applications? Select the two correct answers.
32When deploying Prisma Cloud Defenders in a secure Kubernetes cluster, which THREE configuration best practices should an administrator follow? Select the three correct answers.
33Which TWO methods can be used to scan infrastructure-as-code (IaC) templates using Prisma Cloud before deployment? Select the two correct answers.
34Which TWO metrics or details are displayed within the Prisma Cloud Radar interface for container workloads? Select the two correct answers.
35Which THREE actions can Prisma Cloud take when a container runtime rule detects a high-severity security violation (such as a blocked process or forbidden network connection)? Select the three correct answers.
36Which TWO mechanisms are used by Prisma Cloud to identify vulnerabilities in container images? Select the two correct answers.
37An administrator is troubleshooting why a Prisma Cloud Serverless Defender deployed on AWS Lambda is not reporting runtime telemetry. Which THREE factors must be verified? Select the three correct answers.
38When configuring compliance policies in Prisma Cloud Compute for host operating systems and container images, which THREE types of checks are evaluated? Select the three correct answers.
39A security engineer notices that a Prisma Cloud Host Defender running on an Ubuntu virtual machine is reporting container runtime events, but host-level file integrity monitoring (FIM) alerts are not generating. Where should the engineer check to enable FIM?
40An administrator wants to secure container runtimes against zero-day exploits and unauthorized file modifications. Which THREE runtime defense capabilities should be enabled in Prisma Cloud? Select the three correct answers.
41An administrator needs to deploy the Prisma Cloud Defender on a Linux virtual machine hosted in AWS EC2 to protect the host against runtime threats. Which method should the administrator use to automatically install the Defender?
42Which TWO steps are required to integrate Prisma Cloud Compute scanning into a GitLab CI/CD pipeline? Select the two correct answers.
43An organization runs an Amazon ECS cluster with Fargate launch types. The security team needs to scan container images for vulnerabilities before tasks are instantiated. Which approach should be implemented?
44An engineer needs to prevent unauthorized processes from executing inside a protected Kubernetes cluster namespace. Which Prisma Cloud feature should be configured?
45An application running in an AWS Lambda function requires protection against serverless-specific attacks, such as injection and event payload manipulation. Which Prisma Cloud component should be integrated?
46A Kubernetes administrator notices that a Prisma Cloud Defender deployed as a DaemonSet is reporting high resource utilization on worker nodes. Which configuration setting in the Prisma Cloud Console can the administrator adjust to optimize resource consumption?
47An enterprise wants to scan container images stored in a private JFrog Artifactory registry automatically on a schedule using Prisma Cloud Compute. Where should this integration be configured?
48Which THREE types of assets can be protected by Prisma Cloud Compute Workload Protection? (Choose three)
49Which TWO actions can be performed by the Prisma Cloud Container Runtime Defense module when a security anomaly is detected? (Choose two)
50When configuring vulnerability management policies in Prisma Cloud Compute for container images, which THREE criteria can be used to define vulnerability thresholds and rules? (Choose three)
The Cloud Workload Protection domain covers the key concepts tested in this area of the Cloud-Security-Engineer exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all Cloud-Security-Engineer domains — no account required.
The Courseiva Cloud-Security-Engineer question bank contains 50 questions in the Cloud Workload Protection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cloud Workload Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included