Cybersecurity-Practitioner · domain
Cloud Security
Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) Cloud Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cloud Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Security
Watch out for
Common Cloud Security exam traps
Question index
All Cloud Security questions (37)
Click any question to see the full explanation, or start a practice session above.
An administrator is reviewing Prisma Cloud Data Security reports and identifies several high-risk findings related to AWS S3 buckets. Which THREE conditions or findings would trigger an alert in Prisma Cloud Data Security? (Choose three)
Hard2An administrator needs to configure Prisma Access to inspect traffic from remote workers using explicit proxy mode rather than the GlobalProtect tunnel. Which component or configuration is required for explicit proxy support in Prisma Access?
Hard3An enterprise is deploying Prisma Access to secure remote workers and branch offices. The security team needs to ensure that user identity from Microsoft Entra ID is correctly mapped to traffic logs without requiring users to authenticate through an explicit captive portal. Which component must be deployed?
Hard4An administrator is configuring Prisma Cloud Compute to protect serverless functions in AWS Lambda. Which THREE features are supported for serverless function protection? (Choose three)
Hard5Which Prisma Cloud feature continuously scans cloud resource configurations to detect compliance violations against frameworks such as CIS Benchmarks, HIPAA, and PCI-DSS?
Easy6An administrator is reviewing WildFire submissions in the Prisma Access monitoring dashboard and notices a custom PowerShell script was classified as malware. Where can the administrator view the detailed behavioral analysis report showing registry modifications and API calls made by the sample?
Medium7An administrator is investigating a security alert in Prisma Cloud where a container image in an Amazon ECR registry has a critical CVE. The engineering team wants to prevent CI/CD pipelines from building or pushing images that contain critical vulnerabilities. Which Prisma Cloud feature should be implemented?
Hard8An organization running Kubernetes clusters across multiple public clouds wants to enforce runtime protection that blocks unauthorized container process execution and file system writes. Which Prisma Cloud component performs this enforcement?
Hard9An administrator needs to protect serverless AWS Lambda functions using Prisma Cloud Compute. Which method should be used to instrument the Lambda functions for vulnerability and compliance scanning?
Medium10Which TWO metrics or features are provided by Prisma Autonomous DEM (ADEM) to troubleshoot remote user application performance issues? (Choose two)
Medium11An organization wants to secure a Kubernetes cluster using Prisma Cloud Compute. Which THREE capabilities can the Prisma Cloud Compute Defender provide for the cluster? (Choose three)
Hard12Which Palo Alto Networks product provides Cloud Infrastructure Entitlement Management (CIEM) to discover, analyze, and remediate excessive permissions and identities across multi-cloud environments?
Easy13Which TWO actions can an administrator perform within the Prisma Cloud Cloud Security Posture Management (CSPM) console to remediate misconfigured cloud resources? (Choose two)
Medium14When configuring Prisma Access to inspect traffic between different branch offices (Branch-to-Branch traffic), where is the inspection typically performed?
Easy15An organization uses Prisma Access for secure internet access. Users in a specific branch office report that a SaaS application is loading slowly. Which Prisma Access monitoring tool should the administrator use to analyze end-to-end path performance, latency, and packet loss between the branch office and the SaaS application?
Medium16An enterprise deploying VM-Series firewalls in Google Cloud Platform (GCP) requires centralized license management via Panorama. Which licensing mode should be configured so that firewalls automatically obtain their licenses from Panorama based on consumption or pre-purchased credits?
Hard17An administrator is deploying VM-Series firewalls in Microsoft Azure using an Azure Standard Load Balancer for inbound application traffic. Which component is required to handle asymmetry when routing return traffic from backend application VMs back through the firewall?
Medium18Which TWO deployment methods are officially supported for provisioning VM-Series firewalls in public cloud environments like AWS and Azure? (Choose two)
Medium19Which TWO methods can be used to authenticate remote users connecting to Prisma Access via GlobalProtect? (Choose two)
Medium20When setting up Prisma Access Mobile Users, what is the recommended client software installed on end-user laptops to establish secure connections to the cloud security processing nodes?
Easy21An organization is using Prisma Cloud to monitor AWS IAM policies. A custom policy check fails because an IAM role allows overly permissive actions on S3 buckets. Where in Prisma Cloud should the administrator navigate to view and remediate this specific cloud infrastructure misconfiguration?
Hard22An administrator needs to deploy VM-Series firewalls in an AWS environment using an AWS Gateway Load Balancer (GWLB). Which CloudFormation template or method should the administrator use to ensure traffic is transparently routed through the firewall without requiring destination NAT?
Hard23Which TWO benefits are achieved by integrating Prisma Cloud with cloud provider audit logs (such as AWS CloudTrail, Azure Activity Logs, and GCP Audit Logs)? (Choose two)
Medium24An organization wants to inspect east-west traffic between different microservices running inside an Amazon Elastic Kubernetes Service (EKS) cluster using VM-Series firewalls. Which architectural pattern is recommended?
Medium25What is the primary function of the Prisma Cloud Data Security module?
Easy26An administrator is configuring DNS Security on VM-Series firewalls protecting a multi-cloud environment. Which mechanism does DNS Security use to protect against newly registered domains and command-and-control (C2) domains that lack traditional signatures?
Medium27An enterprise is deploying VM-Series firewalls across AWS, Azure, and GCP. The security team wants a single pane of glass to manage firewall security policies, rule deployments, and software updates across all cloud and on-premises firewalls. Which tool should be used?
Medium28When configuring Prisma Access Remote Networks, which THREE core components or settings are mandatory to establish a secure IPsec tunnel from a branch office firewall to a Prisma Access mobile gateway? (Choose three)
Hard29Which Prisma Cloud module provides Cloud Workload Protection (CWP) capabilities, including runtime defense, vulnerability management, and compliance for containers, hosts, and serverless functions?
Easy30An engineer is configuring Prisma Cloud to scan AWS Infrastructure as Code (IaC) templates within a GitHub repository. Which scanning integration should be implemented to detect misconfigurations before deployment?
Medium31An administrator is configuring a secure IPsec VPN tunnel between an on-premises Palo Alto Networks firewall and a Prisma Access Remote Networks mobile gateway. During negotiation, Phase 2 fails. Where should the administrator check to view detailed IKE and IPsec negotiation error messages?
Hard32What is the primary purpose of bootstrapping a VM-Series firewall during deployment in a public cloud?
Easy33Which TWO log types are generated by VM-Series firewalls and can be forwarded to Panorama or external SIEM platforms for cloud security analysis? (Choose two)
Medium34An administrator is configuring Advanced URL Filtering on Prisma Access. Which feature allows the security policy to block newly observed malicious domains that have existed for only a few hours?
Medium35An organization wants to use Prisma Access to inspect all outbound internet traffic from Google Cloud Platform (GCP) VPCs. Which architecture provides the most scalable integration between GCP and Prisma Access?
Hard36Which feature in Prisma Cloud allows security teams to write custom security policies using a SQL-like query language to inspect cloud resource configurations and audit trails?
Easy37An administrator is configuring Prisma Access to secure remote networks and mobile users. Which TWO cloud-delivered security services can be natively integrated into Prisma Access security policies to inspect traffic? (Choose two)
HardOther domains
All Cybersecurity-Practitioner exam domains
Frequently asked questions
- What does the Cloud Security domain cover on the Cybersecurity-Practitioner exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 37 Cloud Security questions in the Cybersecurity-Practitioner question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.