Cloud-Security-Engineer · domain
Prisma Cloud Architecture And Components
Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Prisma Cloud Architecture And Components practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Prisma Cloud Architecture And Components questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Prisma Cloud Architecture And Components
Watch out for
Common Prisma Cloud Architecture And Components exam traps
Question index
All Prisma Cloud Architecture And Components questions (50)
Click any question to see the full explanation, or start a practice session above.
Where in the Prisma Cloud console should an administrator navigate to generate a custom API Access Key for programmatic integration with CI/CD pipelines?
Easy2You are reviewing the Prisma Cloud administration settings and need to delegate read-only access to a new security analyst. Which role should you assign to the user?
Medium3You need to ensure that Prisma Cloud only scans specific Kubernetes namespaces in a large multi-tenant cluster while ignoring test and staging workloads. Where should you configure this namespace scoping?
Medium4Which THREE configuration elements can be defined within a Prisma Cloud Account Group?
Medium5Where can an administrator view the status and health of all Prisma Cloud connected cloud accounts and their respective data sync cycles?
Easy6What is the primary function of the Prisma Cloud Intelligence Stream?
Easy7Which TWO features are provided by the Prisma Cloud Compute module?
Medium8Which THREE actions can an administrator perform within the Prisma Cloud Settings menu?
Medium9Which TWO protocols or methods are supported by Prisma Cloud for sending alert notifications to external destinations?
Hard10An administrator wants to organize cloud accounts in Prisma Cloud based on business units (e.g., Finance, Engineering) to apply granular access control and policy scoping. Which Prisma Cloud feature should be used?
Easy11An administrator needs to restrict access to the Prisma Cloud administration console so that users can only log in from the corporate network IP range (192.0.2.0/24). Where is this restriction configured?
Medium12Which THREE prerequisites must be verified when troubleshooting a newly deployed Prisma Cloud Compute Defender that fails to connect to the Compute Console via WebSockets?
Hard13A security engineer is troubleshooting why Prisma Cloud Compute Defenders deployed on an ECS Fargate cluster are not reporting connection status back to the Prisma Cloud Console. Which architecture requirement for Fargate defenders is likely missing?
Hard14Which THREE core architectural components comprise the Prisma Cloud Enterprise Edition platform?
Hard15Which Prisma Cloud module provides visibility into cloud resource configurations, posture management, and compliance across multi-cloud environments?
Easy16An enterprise customer is onboarding Google Cloud (GCP) organization-level assets into Prisma Cloud. They choose the Terraform onboarding method. Which GCP service API must be enabled in the Terraform configuration script to allow Prisma Cloud to discover all projects within the organization hierarchy?
Hard17When onboarding a Microsoft Azure account into Prisma Cloud, what is the purpose of granting the application Reader permissions at the Management Group or Subscription level?
Easy18An organization requires strict tenant isolation where users in the APAC region must not be able to view cloud security postures of EMEA resources. Which Prisma Cloud construct should an administrator implement?
Easy19You are troubleshooting a Prisma Cloud Compute deployment where container vulnerability scans are failing because Defenders cannot download image layers from a private registry. The private registry requires token-based authentication. Where must the registry credentials be configured in Prisma Cloud Compute?
Hard20You are configuring agentless scanning for AWS within Prisma Cloud. The setup requires creating a cross-account IAM role. Which specific permission must be included in the IAM policy to allow Prisma Cloud to take EBS volume snapshots for vulnerability analysis without exposing encryption keys?
Hard21Which TWO actions are required when configuring agentless scanning for Azure in Prisma Cloud?
Hard22Which THREE best practices should be followed when administering Prisma Cloud API Access Keys?
Hard23You are configuring SSO for Prisma Cloud Enterprise Edition using SAML 2.0 with Okta as the Identity Provider. After completing the configuration, users attempting to log in receive an 'Invalid SAML Assertion' error. Which troubleshooting step should you perform first?
Medium24An administrator is setting up notification channels in Prisma Cloud to alert the security operations team when critical misconfigurations are detected. Which THREE notification integrations are natively supported out-of-the-box by Prisma Cloud?
Medium25An enterprise is deploying Prisma Cloud Compute across a hybrid environment consisting of AWS EC2 instances, Azure Kubernetes Service (AKS), and on-premises Linux servers. Which TWO deployment methods are supported for installing Prisma Cloud Defenders in this architecture?
Hard26A security engineer notices that Prisma Cloud Runtime Defense on a defender-protected Kubernetes cluster is generating excessive alerts for legitimate build processes running inside application pods. Which configuration change should be applied to suppress these alerts without reducing container security?
Hard27An engineer needs to write a Resource Query Language (RQL) query to identify all AWS S3 buckets that currently have public read access enabled. Which combination of RQL collections and fields should be used?
Medium28An enterprise has strict compliance policies mandating that all Prisma Cloud SaaS console administrator activity must be auditable in near real-time. Which feature should be enabled to capture and stream administrative actions such as policy modifications and user logins?
Hard29An organization requires that cloud resource configurations discovered by Prisma Cloud are ingested in near-real-time to trigger automated remediation via Webhooks. Which Prisma Cloud feature should be configured to meet this requirement?
Medium30An organization has strict compliance requirements requiring all Prisma Cloud audit logs and user activity events to be forwarded to their internal Splunk SIEM in real-time. Which feature should the administrator configure?
Medium31An administrator needs to deploy a Prisma Cloud Compute Defender on a host that operates in a restricted environment with no outbound internet access to the public Prisma Cloud Console. How should communication be established?
Hard32Which THREE methods are supported for deploying Prisma Cloud Compute Defenders on host operating systems (such as standalone Linux VMs)?
Hard33An administrator needs to deploy the Prisma Cloud Defender to monitor hosts in a Kubernetes cluster running on Amazon EKS. Which deployment method uses a DaemonSet to automatically deploy a Defender to every node in the cluster?
Medium34Which THREE criteria can be used to filter or scope alerts in Prisma Cloud Alert Rules?
Medium35Which THREE components are part of the Prisma Cloud Compute architecture?
Medium36An enterprise security architect wants to integrate Prisma Cloud compliance alerts into an existing SIEM using Amazon SQS and AWS Lambda. Which mechanism should be configured on Prisma Cloud to push alerts asynchronously to an SQS queue?
Hard37You are configuring a new AWS cloud account onboarding into Prisma Cloud via CloudFormation. The security team mandates that CloudTrail monitoring must use an existing centralized S3 bucket located in a separate logging account. Which prerequisite configuration must be completed before executing the CFT?
Hard38An administrator wants to configure Prisma Cloud to automatically send notifications to an enterprise Slack channel whenever a high-severity policy violation occurs. Which sequence of configuration steps is correct?
Medium39An administrator needs to deploy Prisma Cloud Compute Defenders across a fleet of Google Cloud Compute Engine (GCE) instances using a startup script. Which parameter must be correctly supplied to the installer script to ensure the Defender successfully registers with the correct Compute Console?
Hard40An administrator is onboarding an AWS organization into Prisma Cloud via CloudFormation StackSets. During deployment, the StackSet execution fails across several member accounts with permission errors. Which action should the administrator take to resolve this issue?
Medium41An administrator needs to restrict access to Prisma Cloud so that the local security operations team can only view alerts and reports without having permissions to modify compliance policies or cloud accounts. Which role should be assigned to this team?
Easy42You are deploying Prisma Cloud Compute Defenders across a heterogeneous environment containing Linux VMs, Windows VMs, and Kubernetes clusters. Which component acts as the central orchestrator and data aggregator for all deployed Compute Defenders?
Hard43Which THREE data sources are ingested and analyzed by Prisma Cloud Posture Management (CSPM) to evaluate security posture?
Hard44An administrator has configured a webhook integration in Prisma Cloud to send alerts to a custom incident management system. However, test alerts are failing with an HTTP 403 Forbidden error. What is the most likely cause?
Hard45Your company has multiple business units sharing a single Prisma Cloud Enterprise tenant. You need to ensure that compliance reports generated by the Finance business unit only include AWS accounts owned by Finance. What feature must you configure?
Medium46What is the primary function of the Prisma Cloud Resource Graph?
Easy47You are troubleshooting a newly onboarded Azure subscription where Prisma Cloud is failing to ingest asset inventory. Upon checking the Azure Activity Log, you notice that API throttling limits are frequently reached. Which mechanism does Prisma Cloud use to manage Azure API rate limits?
Medium48Which TWO methods can be used to onboard an AWS account into Prisma Cloud Enterprise Edition?
Medium49An auditor requests evidence that Prisma Cloud is actively monitoring all cloud accounts in the enterprise. Which built-in Prisma Cloud report should you generate to provide a summary of onboarded cloud accounts and their current monitoring status?
Medium50What is the primary purpose of creating custom compliance standards in Prisma Cloud?
EasyOther domains
All Cloud-Security-Engineer exam domains
Frequently asked questions
- What does the Prisma Cloud Architecture And Components domain cover on the Cloud-Security-Engineer exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 50 Prisma Cloud Architecture And Components questions in the Cloud-Security-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Prisma Cloud Architecture And Components questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.