Practice Cybersecurity-Practitioner Cloud Security questions with full explanations on every answer.
Start practicing
Cloud Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When configuring Prisma Access to inspect traffic between different branch offices (Branch-to-Branch traffic), where is the inspection typically performed?
2An enterprise is deploying Prisma Access to secure remote workers and branch offices. The security team needs to ensure that user identity from Microsoft Entra ID is correctly mapped to traffic logs without requiring users to authenticate through an explicit captive portal. Which component must be deployed?
3An organization is using Prisma Cloud to monitor AWS IAM policies. A custom policy check fails because an IAM role allows overly permissive actions on S3 buckets. Where in Prisma Cloud should the administrator navigate to view and remediate this specific cloud infrastructure misconfiguration?
4An engineer is configuring Prisma Cloud to scan AWS Infrastructure as Code (IaC) templates within a GitHub repository. Which scanning integration should be implemented to detect misconfigurations before deployment?
5An administrator needs to protect serverless AWS Lambda functions using Prisma Cloud Compute. Which method should be used to instrument the Lambda functions for vulnerability and compliance scanning?
6An administrator is deploying VM-Series firewalls in Microsoft Azure using an Azure Standard Load Balancer for inbound application traffic. Which component is required to handle asymmetry when routing return traffic from backend application VMs back through the firewall?
7An administrator needs to deploy VM-Series firewalls in an AWS environment using an AWS Gateway Load Balancer (GWLB). Which CloudFormation template or method should the administrator use to ensure traffic is transparently routed through the firewall without requiring destination NAT?
8An organization wants to use Prisma Access to inspect all outbound internet traffic from Google Cloud Platform (GCP) VPCs. Which architecture provides the most scalable integration between GCP and Prisma Access?
9An administrator is reviewing WildFire submissions in the Prisma Access monitoring dashboard and notices a custom PowerShell script was classified as malware. Where can the administrator view the detailed behavioral analysis report showing registry modifications and API calls made by the sample?
10What is the primary function of the Prisma Cloud Data Security module?
11An organization running Kubernetes clusters across multiple public clouds wants to enforce runtime protection that blocks unauthorized container process execution and file system writes. Which Prisma Cloud component performs this enforcement?
12Which Prisma Cloud module provides Cloud Workload Protection (CWP) capabilities, including runtime defense, vulnerability management, and compliance for containers, hosts, and serverless functions?
13When setting up Prisma Access Mobile Users, what is the recommended client software installed on end-user laptops to establish secure connections to the cloud security processing nodes?
14An administrator is configuring DNS Security on VM-Series firewalls protecting a multi-cloud environment. Which mechanism does DNS Security use to protect against newly registered domains and command-and-control (C2) domains that lack traditional signatures?
15An organization wants to inspect east-west traffic between different microservices running inside an Amazon Elastic Kubernetes Service (EKS) cluster using VM-Series firewalls. Which architectural pattern is recommended?
16Which Prisma Cloud feature continuously scans cloud resource configurations to detect compliance violations against frameworks such as CIS Benchmarks, HIPAA, and PCI-DSS?
17An administrator is configuring Advanced URL Filtering on Prisma Access. Which feature allows the security policy to block newly observed malicious domains that have existed for only a few hours?
18An enterprise deploying VM-Series firewalls in Google Cloud Platform (GCP) requires centralized license management via Panorama. Which licensing mode should be configured so that firewalls automatically obtain their licenses from Panorama based on consumption or pre-purchased credits?
19What is the primary purpose of bootstrapping a VM-Series firewall during deployment in a public cloud?
20An administrator is investigating a security alert in Prisma Cloud where a container image in an Amazon ECR registry has a critical CVE. The engineering team wants to prevent CI/CD pipelines from building or pushing images that contain critical vulnerabilities. Which Prisma Cloud feature should be implemented?
21An organization uses Prisma Access for secure internet access. Users in a specific branch office report that a SaaS application is loading slowly. Which Prisma Access monitoring tool should the administrator use to analyze end-to-end path performance, latency, and packet loss between the branch office and the SaaS application?
22Which Palo Alto Networks product provides Cloud Infrastructure Entitlement Management (CIEM) to discover, analyze, and remediate excessive permissions and identities across multi-cloud environments?
23An enterprise is deploying VM-Series firewalls across AWS, Azure, and GCP. The security team wants a single pane of glass to manage firewall security policies, rule deployments, and software updates across all cloud and on-premises firewalls. Which tool should be used?
24Which feature in Prisma Cloud allows security teams to write custom security policies using a SQL-like query language to inspect cloud resource configurations and audit trails?
25An organization wants to secure a Kubernetes cluster using Prisma Cloud Compute. Which THREE capabilities can the Prisma Cloud Compute Defender provide for the cluster? (Choose three)
26An administrator needs to configure Prisma Access to inspect traffic from remote workers using explicit proxy mode rather than the GlobalProtect tunnel. Which component or configuration is required for explicit proxy support in Prisma Access?
27An administrator is configuring Prisma Access to secure remote networks and mobile users. Which TWO cloud-delivered security services can be natively integrated into Prisma Access security policies to inspect traffic? (Choose two)
28Which TWO deployment methods are officially supported for provisioning VM-Series firewalls in public cloud environments like AWS and Azure? (Choose two)
29An administrator is configuring a secure IPsec VPN tunnel between an on-premises Palo Alto Networks firewall and a Prisma Access Remote Networks mobile gateway. During negotiation, Phase 2 fails. Where should the administrator check to view detailed IKE and IPsec negotiation error messages?
30Which TWO actions can an administrator perform within the Prisma Cloud Cloud Security Posture Management (CSPM) console to remediate misconfigured cloud resources? (Choose two)
31Which TWO log types are generated by VM-Series firewalls and can be forwarded to Panorama or external SIEM platforms for cloud security analysis? (Choose two)
32When configuring Prisma Access Remote Networks, which THREE core components or settings are mandatory to establish a secure IPsec tunnel from a branch office firewall to a Prisma Access mobile gateway? (Choose three)
33An administrator is configuring Prisma Cloud Compute to protect serverless functions in AWS Lambda. Which THREE features are supported for serverless function protection? (Choose three)
34An administrator is reviewing Prisma Cloud Data Security reports and identifies several high-risk findings related to AWS S3 buckets. Which THREE conditions or findings would trigger an alert in Prisma Cloud Data Security? (Choose three)
35Which TWO metrics or features are provided by Prisma Autonomous DEM (ADEM) to troubleshoot remote user application performance issues? (Choose two)
36Which TWO methods can be used to authenticate remote users connecting to Prisma Access via GlobalProtect? (Choose two)
37Which TWO benefits are achieved by integrating Prisma Cloud with cloud provider audit logs (such as AWS CloudTrail, Azure Activity Logs, and GCP Audit Logs)? (Choose two)
The Cloud Security domain covers the key concepts tested in this area of the Cybersecurity-Practitioner exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all Cybersecurity-Practitioner domains — no account required.
The Courseiva Cybersecurity-Practitioner question bank contains 37 questions in the Cloud Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cloud Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included