Courseiva

Cloud-Security-Engineer · domain

Cloud Workload Protection

Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Cloud Workload Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

50 questions12 easy19 medium19 hard

Focused practice

Practice Cloud Workload Protection questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Workload Protection

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Workload Protection exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Question index

All Cloud Workload Protection questions (50)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO actions can a Prisma Cloud Host Defender perform when installed on a Linux virtual machine? Select the two correct answers.

Medium
2

An enterprise wants to enforce runtime protection for serverless functions in AWS Lambda without modifying function code layers. Which Prisma Cloud feature should be implemented?

Easy
3

Which TWO features are provided by Prisma Cloud Web Application and API Security (WAAS) for containerized applications? Select the two correct answers.

Medium
4

A security analyst notices that Prisma Cloud is generating numerous false-positive alerts for a custom internal binary flagged as malware during host scans. How can the analyst resolve this issue permanently across the environment?

Medium
5

Where in the Prisma Cloud Console can an administrator review compliance benchmark results (such as CIS benchmarks) for deployed container images and hosts?

Easy
6

During incident response, a security analyst notices that a Prisma Cloud Host Defender has generated an alert for an unknown binary execution, but the process was not blocked. What is the reason for this behavior?

Hard
7

A security team wants to ensure that any container attempting to access the cloud provider metadata service (e.g., 169.254.169.254) from within a compromised workload is blocked. Which Prisma Cloud feature provides this protection?

Medium
8

Which THREE types of assets can be protected by Prisma Cloud Compute Workload Protection? (Choose three)

Medium
9

An organization runs an Amazon ECS cluster with Fargate launch types. The security team needs to scan container images for vulnerabilities before tasks are instantiated. Which approach should be implemented?

Hard
10

A Linux host running a Prisma Cloud Defender experiences high CPU usage originating from the defender process during a scheduled container image scan. How can an administrator mitigate this impact on production workloads?

Hard
11

An application running in a Kubernetes pod is attempting to make unauthorized outbound connections to a known command-and-control IP address. The Prisma Cloud Container Defender is deployed in the cluster. Which runtime defense rule should be configured to prevent this behavior?

Hard
12

During a vulnerability scan of a container image in the Prisma Cloud Console, a custom Python package installed via pip shows as unpatched, but the CVE has a fixed version available. Why might Prisma Cloud still report the vulnerability as unresolved?

Hard
13

When configuring compliance policies in Prisma Cloud Compute for host operating systems and container images, which THREE types of checks are evaluated? Select the three correct answers.

Hard
14

An enterprise runs containerized microservices on AWS Elastic Kubernetes Service (EKS) and wants to enforce mutual TLS (mTLS) and network micro-segmentation managed via Prisma Cloud. Which feature should be configured?

Hard
15

An application running in an AWS Lambda function requires protection against serverless-specific attacks, such as injection and event payload manipulation. Which Prisma Cloud component should be integrated?

Medium
16

An administrator is troubleshooting why a Prisma Cloud Serverless Defender deployed on AWS Lambda is not reporting runtime telemetry. Which THREE factors must be verified? Select the three correct answers.

Hard
17

Which TWO actions can be performed by the Prisma Cloud Container Runtime Defense module when a security anomaly is detected? (Choose two)

Hard
18

Which THREE actions can Prisma Cloud take when a container runtime rule detects a high-severity security violation (such as a blocked process or forbidden network connection)? Select the three correct answers.

Hard
19

An administrator notices that Prisma Cloud Host Defenders deployed on AWS EC2 instances are failing to report back to the console. Security groups allow outbound traffic, but VPC Flow Logs show dropped packets on port 8084. What must the administrator verify?

Medium
20

A security engineer is troubleshooting a Web Application and API Security (WAAS) rule that is not inspecting HTTPS traffic flowing into a Kubernetes Ingress controller. What is the most likely cause?

Medium
21

A container running inside a Kubernetes cluster was compromised, and the attacker attempted to modify the host's kernel parameters using sysctl. Which Prisma Cloud feature detects and prevents this action?

Hard
22

Which TWO methods can be used to scan infrastructure-as-code (IaC) templates using Prisma Cloud before deployment? Select the two correct answers.

Medium
23

A cloud security engineer needs to deploy Prisma Cloud defenders on a Kubernetes cluster. Which method provides the most automated deployment mechanism managed via the Kubernetes control plane?

Easy
24

Which TWO steps are required to integrate Prisma Cloud Compute scanning into a GitLab CI/CD pipeline? Select the two correct answers.

Medium
25

A security team wants to block high-severity Common Vulnerabilities and Exposures (CVEs) from being deployed into production clusters via CI/CD pipelines. Where should this policy be enforced using Prisma Cloud?

Medium
26

An engineer needs to prevent unauthorized processes from executing inside a protected Kubernetes cluster namespace. Which Prisma Cloud feature should be configured?

Easy
27

An administrator needs to automatically scan container images as soon as they are built in a Jenkins CI/CD pipeline before pushing them to a registry. What tool should be integrated into Jenkins?

Easy
28

A security engineer notices that a Prisma Cloud Host Defender running on an Ubuntu virtual machine is reporting container runtime events, but host-level file integrity monitoring (FIM) alerts are not generating. Where should the engineer check to enable FIM?

Medium
29

A Kubernetes administrator notices that a Prisma Cloud Defender deployed as a DaemonSet is reporting high resource utilization on worker nodes. Which configuration setting in the Prisma Cloud Console can the administrator adjust to optimize resource consumption?

Hard
30

An organization runs sensitive workloads on Google Cloud Run. They need to protect these serverless container services against known vulnerabilities and runtime attacks. Which Prisma Cloud Defender architecture supports Cloud Run?

Hard
31

A container running a legacy web application is subjected to a distributed denial-of-service (DDoS) attack and application-layer vulnerability exploitation. The security team wants to block Layer 7 attacks while allowing legitimate HTTP traffic. Which Prisma Cloud feature should be deployed?

Medium
32

An enterprise uses Prisma Cloud Compute to scan Infrastructure as Code (IaC) templates in a GitHub repository before deployment. A Terraform script containing an insecure container security configuration is flagged. What tool and workflow were used?

Hard
33

A developer pushes a container image to a private registry, but Prisma Cloud fails to scan it. The registry uses self-signed SSL certificates. What action must the administrator take in the Prisma Cloud Console?

Medium
34

An administrator wants to configure alerting so that security team members receive an email whenever a critical container vulnerability is discovered during a registry scan. Where is this configured?

Easy
35

An administrator is configuring Prisma Cloud Container Registry Scanning. Which THREE registry types are natively supported for automated scanning by Prisma Cloud? Select the three correct answers.

Hard
36

An administrator needs to scan container images stored in an Azure Container Registry (ACR) without deploying them to a running cluster. Which Prisma Cloud feature accomplishes this?

Easy
37

Which TWO metrics or details are displayed within the Prisma Cloud Radar interface for container workloads? Select the two correct answers.

Medium
38

When deploying Prisma Cloud Defenders in a secure Kubernetes cluster, which THREE configuration best practices should an administrator follow? Select the three correct answers.

Hard
39

An administrator needs to deploy the Prisma Cloud Defender on a Linux virtual machine hosted in AWS EC2 to protect the host against runtime threats. Which method should the administrator use to automatically install the Defender?

Easy
40

When configuring vulnerability management policies in Prisma Cloud Compute for container images, which THREE criteria can be used to define vulnerability thresholds and rules? (Choose three)

Hard
41

An auditor requests a report showing all open vulnerabilities across all active container registries connected to Prisma Cloud. Where can this report be generated?

Easy
42

Which TWO mechanisms are used by Prisma Cloud to identify vulnerabilities in container images? Select the two correct answers.

Medium
43

An administrator wants to view a visual map of all container services, hosts, and incoming network connections across their cloud environment in real time. Which Prisma Cloud Compute view provides this?

Easy
44

An enterprise wants to scan container images stored in a private JFrog Artifactory registry automatically on a schedule using Prisma Cloud Compute. Where should this integration be configured?

Medium
45

An administrator needs to install a Prisma Cloud Defender on a standalone Linux virtual machine that does not run Kubernetes or Docker. Which defender type should be selected?

Easy
46

An administrator needs to check the health status and connectivity of all deployed Prisma Cloud Defenders across multiple cloud environments. Where should they look in the console?

Easy
47

An administrator wants to secure container runtimes against zero-day exploits and unauthorized file modifications. Which THREE runtime defense capabilities should be enabled in Prisma Cloud? Select the three correct answers.

Hard
48

An application team is deploying serverless functions on Azure Functions. They need to protect the functions against injection attacks and runtime tampering using Prisma Cloud. Which deployment step is required?

Hard
49

A security engineer is reviewing container image scan results in Prisma Cloud and notices that a base image vulnerability is marked as 'Not Applicable'. What does this status indicate?

Medium
50

An organization wants to ensure that no containers run with root privileges in their Amazon ECS clusters. Which Prisma Cloud policy type should be used to enforce this at runtime?

Medium

Frequently asked questions

What does the Cloud Workload Protection domain cover on the Cloud-Security-Engineer exam?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How many questions are in this domain?
This page lists all 50 Cloud Workload Protection questions in the Cloud-Security-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Workload Protection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cloudsec-engineer PANW-CLOUDSEC-ENGINEER cloud workload protection Practice Questions