Courseiva
Cloud Workload ProtectionmediumMultiple ChoiceObjective-mapped

Cloud-Security-Engineer Cloud Workload Protection Practice Question

A container running a legacy web application is subjected to a distributed denial-of-service (DDoS) attack and application-layer vulnerability exploitation. The security team wants to block Layer 7 attacks while allowing legitimate HTTP traffic. Which Prisma Cloud feature should be deployed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy a Prisma Cloud WAAS rule configured to inspect HTTP/HTTPS traffic and protect against web attacks.

Prisma Cloud Web Application and API Security (WAAS) protects web applications and APIs against Layer 7 attacks, including OWASP Top 10, zero-days, and volumetric bot attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable AWS Shield Standard on the application load balancer.

    Why it's wrong here

    AWS Shield Standard protects against infrastructure DDoS, but Prisma Cloud WAAS handles application-layer inspection.

  • Configure a Prisma Cloud Container Network Firewall rule to drop all incoming TCP SYN packets on port 443.

    Why it's wrong here

    Dropping all SYN packets on port 443 would block legitimate HTTPS traffic along with the attack.

  • Deploy a Prisma Cloud WAAS rule configured to inspect HTTP/HTTPS traffic and protect against web attacks.

    Why this is correct

    WAAS is specifically designed to inspect Layer 7 traffic and block application attacks.

  • Implement a Host Defender compliance check for HTTP listening ports.

    Why it's wrong here

    Compliance checks audit configurations, they do not inspect or block active Layer 7 attacks.

About these practice questions

One of 216 original Cloud-Security-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.