Cloud-Security-Engineer · domain
Cloud Workload Protection
Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Cloud Workload Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cloud Workload Protection questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Workload Protection
Watch out for
Common Cloud Workload Protection exam traps
Question index
All Cloud Workload Protection questions (50)
Click any question to see the full explanation, or start a practice session above.
Which TWO actions can a Prisma Cloud Host Defender perform when installed on a Linux virtual machine? Select the two correct answers.
Medium2An enterprise wants to enforce runtime protection for serverless functions in AWS Lambda without modifying function code layers. Which Prisma Cloud feature should be implemented?
Easy3Which TWO features are provided by Prisma Cloud Web Application and API Security (WAAS) for containerized applications? Select the two correct answers.
Medium4A security analyst notices that Prisma Cloud is generating numerous false-positive alerts for a custom internal binary flagged as malware during host scans. How can the analyst resolve this issue permanently across the environment?
Medium5Where in the Prisma Cloud Console can an administrator review compliance benchmark results (such as CIS benchmarks) for deployed container images and hosts?
Easy6During incident response, a security analyst notices that a Prisma Cloud Host Defender has generated an alert for an unknown binary execution, but the process was not blocked. What is the reason for this behavior?
Hard7A security team wants to ensure that any container attempting to access the cloud provider metadata service (e.g., 169.254.169.254) from within a compromised workload is blocked. Which Prisma Cloud feature provides this protection?
Medium8Which THREE types of assets can be protected by Prisma Cloud Compute Workload Protection? (Choose three)
Medium9An organization runs an Amazon ECS cluster with Fargate launch types. The security team needs to scan container images for vulnerabilities before tasks are instantiated. Which approach should be implemented?
Hard10A Linux host running a Prisma Cloud Defender experiences high CPU usage originating from the defender process during a scheduled container image scan. How can an administrator mitigate this impact on production workloads?
Hard11An application running in a Kubernetes pod is attempting to make unauthorized outbound connections to a known command-and-control IP address. The Prisma Cloud Container Defender is deployed in the cluster. Which runtime defense rule should be configured to prevent this behavior?
Hard12During a vulnerability scan of a container image in the Prisma Cloud Console, a custom Python package installed via pip shows as unpatched, but the CVE has a fixed version available. Why might Prisma Cloud still report the vulnerability as unresolved?
Hard13When configuring compliance policies in Prisma Cloud Compute for host operating systems and container images, which THREE types of checks are evaluated? Select the three correct answers.
Hard14An enterprise runs containerized microservices on AWS Elastic Kubernetes Service (EKS) and wants to enforce mutual TLS (mTLS) and network micro-segmentation managed via Prisma Cloud. Which feature should be configured?
Hard15An application running in an AWS Lambda function requires protection against serverless-specific attacks, such as injection and event payload manipulation. Which Prisma Cloud component should be integrated?
Medium16An administrator is troubleshooting why a Prisma Cloud Serverless Defender deployed on AWS Lambda is not reporting runtime telemetry. Which THREE factors must be verified? Select the three correct answers.
Hard17Which TWO actions can be performed by the Prisma Cloud Container Runtime Defense module when a security anomaly is detected? (Choose two)
Hard18Which THREE actions can Prisma Cloud take when a container runtime rule detects a high-severity security violation (such as a blocked process or forbidden network connection)? Select the three correct answers.
Hard19An administrator notices that Prisma Cloud Host Defenders deployed on AWS EC2 instances are failing to report back to the console. Security groups allow outbound traffic, but VPC Flow Logs show dropped packets on port 8084. What must the administrator verify?
Medium20A security engineer is troubleshooting a Web Application and API Security (WAAS) rule that is not inspecting HTTPS traffic flowing into a Kubernetes Ingress controller. What is the most likely cause?
Medium21A container running inside a Kubernetes cluster was compromised, and the attacker attempted to modify the host's kernel parameters using sysctl. Which Prisma Cloud feature detects and prevents this action?
Hard22Which TWO methods can be used to scan infrastructure-as-code (IaC) templates using Prisma Cloud before deployment? Select the two correct answers.
Medium23A cloud security engineer needs to deploy Prisma Cloud defenders on a Kubernetes cluster. Which method provides the most automated deployment mechanism managed via the Kubernetes control plane?
Easy24Which TWO steps are required to integrate Prisma Cloud Compute scanning into a GitLab CI/CD pipeline? Select the two correct answers.
Medium25A security team wants to block high-severity Common Vulnerabilities and Exposures (CVEs) from being deployed into production clusters via CI/CD pipelines. Where should this policy be enforced using Prisma Cloud?
Medium26An engineer needs to prevent unauthorized processes from executing inside a protected Kubernetes cluster namespace. Which Prisma Cloud feature should be configured?
Easy27An administrator needs to automatically scan container images as soon as they are built in a Jenkins CI/CD pipeline before pushing them to a registry. What tool should be integrated into Jenkins?
Easy28A security engineer notices that a Prisma Cloud Host Defender running on an Ubuntu virtual machine is reporting container runtime events, but host-level file integrity monitoring (FIM) alerts are not generating. Where should the engineer check to enable FIM?
Medium29A Kubernetes administrator notices that a Prisma Cloud Defender deployed as a DaemonSet is reporting high resource utilization on worker nodes. Which configuration setting in the Prisma Cloud Console can the administrator adjust to optimize resource consumption?
Hard30An organization runs sensitive workloads on Google Cloud Run. They need to protect these serverless container services against known vulnerabilities and runtime attacks. Which Prisma Cloud Defender architecture supports Cloud Run?
Hard31A container running a legacy web application is subjected to a distributed denial-of-service (DDoS) attack and application-layer vulnerability exploitation. The security team wants to block Layer 7 attacks while allowing legitimate HTTP traffic. Which Prisma Cloud feature should be deployed?
Medium32An enterprise uses Prisma Cloud Compute to scan Infrastructure as Code (IaC) templates in a GitHub repository before deployment. A Terraform script containing an insecure container security configuration is flagged. What tool and workflow were used?
Hard33A developer pushes a container image to a private registry, but Prisma Cloud fails to scan it. The registry uses self-signed SSL certificates. What action must the administrator take in the Prisma Cloud Console?
Medium34An administrator wants to configure alerting so that security team members receive an email whenever a critical container vulnerability is discovered during a registry scan. Where is this configured?
Easy35An administrator is configuring Prisma Cloud Container Registry Scanning. Which THREE registry types are natively supported for automated scanning by Prisma Cloud? Select the three correct answers.
Hard36An administrator needs to scan container images stored in an Azure Container Registry (ACR) without deploying them to a running cluster. Which Prisma Cloud feature accomplishes this?
Easy37Which TWO metrics or details are displayed within the Prisma Cloud Radar interface for container workloads? Select the two correct answers.
Medium38When deploying Prisma Cloud Defenders in a secure Kubernetes cluster, which THREE configuration best practices should an administrator follow? Select the three correct answers.
Hard39An administrator needs to deploy the Prisma Cloud Defender on a Linux virtual machine hosted in AWS EC2 to protect the host against runtime threats. Which method should the administrator use to automatically install the Defender?
Easy40When configuring vulnerability management policies in Prisma Cloud Compute for container images, which THREE criteria can be used to define vulnerability thresholds and rules? (Choose three)
Hard41An auditor requests a report showing all open vulnerabilities across all active container registries connected to Prisma Cloud. Where can this report be generated?
Easy42Which TWO mechanisms are used by Prisma Cloud to identify vulnerabilities in container images? Select the two correct answers.
Medium43An administrator wants to view a visual map of all container services, hosts, and incoming network connections across their cloud environment in real time. Which Prisma Cloud Compute view provides this?
Easy44An enterprise wants to scan container images stored in a private JFrog Artifactory registry automatically on a schedule using Prisma Cloud Compute. Where should this integration be configured?
Medium45An administrator needs to install a Prisma Cloud Defender on a standalone Linux virtual machine that does not run Kubernetes or Docker. Which defender type should be selected?
Easy46An administrator needs to check the health status and connectivity of all deployed Prisma Cloud Defenders across multiple cloud environments. Where should they look in the console?
Easy47An administrator wants to secure container runtimes against zero-day exploits and unauthorized file modifications. Which THREE runtime defense capabilities should be enabled in Prisma Cloud? Select the three correct answers.
Hard48An application team is deploying serverless functions on Azure Functions. They need to protect the functions against injection attacks and runtime tampering using Prisma Cloud. Which deployment step is required?
Hard49A security engineer is reviewing container image scan results in Prisma Cloud and notices that a base image vulnerability is marked as 'Not Applicable'. What does this status indicate?
Medium50An organization wants to ensure that no containers run with root privileges in their Amazon ECS clusters. Which Prisma Cloud policy type should be used to enforce this at runtime?
MediumOther domains
All Cloud-Security-Engineer exam domains
Frequently asked questions
- What does the Cloud Workload Protection domain cover on the Cloud-Security-Engineer exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 50 Cloud Workload Protection questions in the Cloud-Security-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Workload Protection questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.