Cloud-Security-Engineer Prisma Cloud Architecture And Components Practice Question
An administrator needs to restrict access to the Prisma Cloud administration console so that users can only log in from the corporate network IP range (192.0.2.0/24). Where is this restriction configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Settings > Trusted IP Addresses
Network access controls and IP whitelisting for the Prisma Cloud console are managed under Settings > Trusted IP Addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Administration > SSO > Network Policies
Why it's wrong here
SSO settings handle identity provider federation, but trusted IP ranges are configured under Settings > Trusted IP Addresses.
- ✓
Settings > Trusted IP Addresses
Why this is correct
Trusted IP settings restrict console access to specified CIDR blocks.
- ✗
Risks > Policies > Network Rules
Why it's wrong here
Policies are used for compliance and cloud security rules, not console authentication enforcement.
- ✗
Compute > Defend > Access Control
Why it's wrong here
This restricts access to container workloads and registries, not the Prisma Cloud web console.
About these practice questions
One of 216 original Cloud-Security-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cloud-Security-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cloud-Security-Engineer exam.