Practice Cloud-Security-Engineer Prisma Cloud Architecture And Components questions with full explanations on every answer.
Start practicing
Prisma Cloud Architecture And Components — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your company has multiple business units sharing a single Prisma Cloud Enterprise tenant. You need to ensure that compliance reports generated by the Finance business unit only include AWS accounts owned by Finance. What feature must you configure?
2An organization requires strict tenant isolation where users in the APAC region must not be able to view cloud security postures of EMEA resources. Which Prisma Cloud construct should an administrator implement?
3You are configuring a new AWS cloud account onboarding into Prisma Cloud via CloudFormation. The security team mandates that CloudTrail monitoring must use an existing centralized S3 bucket located in a separate logging account. Which prerequisite configuration must be completed before executing the CFT?
4An enterprise customer is onboarding Google Cloud (GCP) organization-level assets into Prisma Cloud. They choose the Terraform onboarding method. Which GCP service API must be enabled in the Terraform configuration script to allow Prisma Cloud to discover all projects within the organization hierarchy?
5You are troubleshooting a newly onboarded Azure subscription where Prisma Cloud is failing to ingest asset inventory. Upon checking the Azure Activity Log, you notice that API throttling limits are frequently reached. Which mechanism does Prisma Cloud use to manage Azure API rate limits?
6An administrator needs to deploy a Prisma Cloud Compute Defender on a host that operates in a restricted environment with no outbound internet access to the public Prisma Cloud Console. How should communication be established?
7An administrator needs to deploy the Prisma Cloud Defender to monitor hosts in a Kubernetes cluster running on Amazon EKS. Which deployment method uses a DaemonSet to automatically deploy a Defender to every node in the cluster?
8Where in the Prisma Cloud console should an administrator navigate to generate a custom API Access Key for programmatic integration with CI/CD pipelines?
9An administrator wants to configure Prisma Cloud to automatically send notifications to an enterprise Slack channel whenever a high-severity policy violation occurs. Which sequence of configuration steps is correct?
10What is the primary function of the Prisma Cloud Intelligence Stream?
11An organization has strict compliance requirements requiring all Prisma Cloud audit logs and user activity events to be forwarded to their internal Splunk SIEM in real-time. Which feature should the administrator configure?
12You are deploying Prisma Cloud Compute Defenders across a heterogeneous environment containing Linux VMs, Windows VMs, and Kubernetes clusters. Which component acts as the central orchestrator and data aggregator for all deployed Compute Defenders?
13You are configuring agentless scanning for AWS within Prisma Cloud. The setup requires creating a cross-account IAM role. Which specific permission must be included in the IAM policy to allow Prisma Cloud to take EBS volume snapshots for vulnerability analysis without exposing encryption keys?
14When onboarding a Microsoft Azure account into Prisma Cloud, what is the purpose of granting the application Reader permissions at the Management Group or Subscription level?
15An administrator needs to restrict access to the Prisma Cloud administration console so that users can only log in from the corporate network IP range (192.0.2.0/24). Where is this restriction configured?
16You are troubleshooting a Prisma Cloud Compute deployment where container vulnerability scans are failing because Defenders cannot download image layers from a private registry. The private registry requires token-based authentication. Where must the registry credentials be configured in Prisma Cloud Compute?
17An auditor requests evidence that Prisma Cloud is actively monitoring all cloud accounts in the enterprise. Which built-in Prisma Cloud report should you generate to provide a summary of onboarded cloud accounts and their current monitoring status?
18What is the primary purpose of creating custom compliance standards in Prisma Cloud?
19An administrator has configured a webhook integration in Prisma Cloud to send alerts to a custom incident management system. However, test alerts are failing with an HTTP 403 Forbidden error. What is the most likely cause?
20Which Prisma Cloud module provides visibility into cloud resource configurations, posture management, and compliance across multi-cloud environments?
21You need to ensure that Prisma Cloud only scans specific Kubernetes namespaces in a large multi-tenant cluster while ignoring test and staging workloads. Where should you configure this namespace scoping?
22An enterprise security architect wants to integrate Prisma Cloud compliance alerts into an existing SIEM using Amazon SQS and AWS Lambda. Which mechanism should be configured on Prisma Cloud to push alerts asynchronously to an SQS queue?
23What is the primary function of the Prisma Cloud Resource Graph?
24You are configuring SSO for Prisma Cloud Enterprise Edition using SAML 2.0 with Okta as the Identity Provider. After completing the configuration, users attempting to log in receive an 'Invalid SAML Assertion' error. Which troubleshooting step should you perform first?
25An administrator needs to deploy Prisma Cloud Compute Defenders across a fleet of Google Cloud Compute Engine (GCE) instances using a startup script. Which parameter must be correctly supplied to the installer script to ensure the Defender successfully registers with the correct Compute Console?
26Where can an administrator view the status and health of all Prisma Cloud connected cloud accounts and their respective data sync cycles?
27You are reviewing the Prisma Cloud administration settings and need to delegate read-only access to a new security analyst. Which role should you assign to the user?
28Which TWO features are provided by the Prisma Cloud Compute module?
29An enterprise has strict compliance policies mandating that all Prisma Cloud SaaS console administrator activity must be auditable in near real-time. Which feature should be enabled to capture and stream administrative actions such as policy modifications and user logins?
30Which TWO methods can be used to onboard an AWS account into Prisma Cloud Enterprise Edition?
31Which TWO actions are required when configuring agentless scanning for Azure in Prisma Cloud?
32Which TWO protocols or methods are supported by Prisma Cloud for sending alert notifications to external destinations?
33Which THREE configuration elements can be defined within a Prisma Cloud Account Group?
34Which THREE data sources are ingested and analyzed by Prisma Cloud Posture Management (CSPM) to evaluate security posture?
35Which THREE components are part of the Prisma Cloud Compute architecture?
36Which THREE best practices should be followed when administering Prisma Cloud API Access Keys?
37Which THREE criteria can be used to filter or scope alerts in Prisma Cloud Alert Rules?
38Which THREE actions can an administrator perform within the Prisma Cloud Settings menu?
39Which THREE prerequisites must be verified when troubleshooting a newly deployed Prisma Cloud Compute Defender that fails to connect to the Compute Console via WebSockets?
40Which THREE methods are supported for deploying Prisma Cloud Compute Defenders on host operating systems (such as standalone Linux VMs)?
41A security engineer notices that Prisma Cloud Runtime Defense on a defender-protected Kubernetes cluster is generating excessive alerts for legitimate build processes running inside application pods. Which configuration change should be applied to suppress these alerts without reducing container security?
42An administrator is onboarding an AWS organization into Prisma Cloud via CloudFormation StackSets. During deployment, the StackSet execution fails across several member accounts with permission errors. Which action should the administrator take to resolve this issue?
43An organization requires that cloud resource configurations discovered by Prisma Cloud are ingested in near-real-time to trigger automated remediation via Webhooks. Which Prisma Cloud feature should be configured to meet this requirement?
44A security engineer is troubleshooting why Prisma Cloud Compute Defenders deployed on an ECS Fargate cluster are not reporting connection status back to the Prisma Cloud Console. Which architecture requirement for Fargate defenders is likely missing?
45An administrator wants to organize cloud accounts in Prisma Cloud based on business units (e.g., Finance, Engineering) to apply granular access control and policy scoping. Which Prisma Cloud feature should be used?
46An enterprise is deploying Prisma Cloud Compute across a hybrid environment consisting of AWS EC2 instances, Azure Kubernetes Service (AKS), and on-premises Linux servers. Which TWO deployment methods are supported for installing Prisma Cloud Defenders in this architecture?
47An engineer needs to write a Resource Query Language (RQL) query to identify all AWS S3 buckets that currently have public read access enabled. Which combination of RQL collections and fields should be used?
48An administrator needs to restrict access to Prisma Cloud so that the local security operations team can only view alerts and reports without having permissions to modify compliance policies or cloud accounts. Which role should be assigned to this team?
49Which THREE core architectural components comprise the Prisma Cloud Enterprise Edition platform?
50An administrator is setting up notification channels in Prisma Cloud to alert the security operations team when critical misconfigurations are detected. Which THREE notification integrations are natively supported out-of-the-box by Prisma Cloud?
The Prisma Cloud Architecture And Components domain covers the key concepts tested in this area of the Cloud-Security-Engineer exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all Cloud-Security-Engineer domains — no account required.
The Courseiva Cloud-Security-Engineer question bank contains 50 questions in the Prisma Cloud Architecture And Components domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Prisma Cloud Architecture And Components domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included