Courseiva

Cloud-Security-Engineer · domain

Cloud Security Posture Management

Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Cloud Security Posture Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

58 questions19 easy19 medium20 hard

Focused practice

Practice Cloud Security Posture Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Security Posture Management

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security Posture Management exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Question index

All Cloud Security Posture Management questions (58)

Click any question to see the full explanation, or start a practice session above.

1

An administrator needs to quickly view the overall security posture and compliance status of multiple AWS accounts connected to Prisma Cloud. Which Prisma Cloud tab provides this aggregate high-level executive dashboard?

Easy
2

Which TWO methods can administrators use to search or filter assets in the Prisma Cloud Asset Inventory? (Choose two.)

Medium
3

An auditor needs to review historical configuration changes of an AWS security group that resulted in a compliance violation three weeks ago. Which Prisma Cloud feature should be used?

Hard
4

How does Prisma Cloud connect to enterprise cloud environments (AWS, Azure, GCP) for CSPM scanning?

Easy
5

What is the primary benefit of using Prisma Cloud's out-of-the-box (OOTB) policies?

Easy
6

An administrator needs to ensure that Prisma Cloud policy evaluations run against newly created cloud resources immediately upon deployment. How does Prisma Cloud handle real-time policy evaluation for cloud configurations?

Hard
7

An administrator in Prisma Cloud wants to identify and remediate overly permissive AWS IAM policies that allow full administrative access. Which Prisma Cloud CSPM feature should the administrator use to automatically generate a least-privilege policy based on actual cloud trail usage?

Medium
8

Your auditor requests a report showing historical compliance trends over the last 90 days for the ISO 27001 standard. Where can an administrator generate or schedule this report in Prisma Cloud?

Medium
9

Which THREE capabilities are provided by Prisma Cloud Resource Query Language (RQL)? (Choose three.)

Hard
10

Which THREE data sources can Prisma Cloud CSPM ingest and analyze to evaluate security posture and compliance? (Choose three)

Hard
11

When onboarding a new multi-account AWS environment into Prisma Cloud CSPM via CloudFormation, what is the primary purpose of deploying the StackSet template?

Easy
12

Which TWO actions can an administrator perform when configuring Alert Rules in Prisma Cloud? (Choose two.)

Easy
13

What role do Prisma Cloud Account Groups play in organizing security posture management?

Easy
14

When onboarding a new Google Cloud Platform (GCP) organization into Prisma Cloud, what is the primary prerequisite required to grant Prisma Cloud visibility across all projects?

Easy
15

Which Prisma Cloud feature allows security teams to group cloud resources based on business units, environments (e.g., Production vs. Development), or ownership for targeted policy enforcement?

Easy
16

Where in Prisma Cloud can an administrator create, modify, or disable OOTB (Out-of-The-Box) and custom security policies?

Easy
17

An organization requires that all compute instances across AWS and Azure be tagged with an 'Owner' and 'Environment' tag. How can Prisma Cloud enforce or report on missing tags?

Hard
18

An administrator needs to create a custom RQL policy that detects AWS IAM users who have console access enabled, have not enabled Multi-Factor Authentication (MFA), and have not logged in within the last 90 days. Which RQL query correctly combines these conditions?

Hard
19

An auditor identifies that an AWS IAM role in your environment has an overly permissive policy granting `*` action on `*` resource. You want to write an RQL query to find all IAM policies with full administrative privileges. What is the correct RQL syntax?

Hard
20

You are tasked with writing a Resource Query Language (RQL) statement in Prisma Cloud to find all AWS S3 buckets that do not have server-side encryption enabled. Which RQL query correctly achieves this?

Medium
21

Which THREE actions occur when a Prisma Cloud policy is flagged as a violation (generating an alert)? (Choose three.)

Hard
22

When creating a custom RQL query in Prisma Cloud, which THREE parameters or clauses are commonly utilized in a configuration resource query (`config from cloud.resource`)? (Choose three.)

Hard
23

An administrator wants to suppress low-priority Prisma Cloud CSPM alerts for specific development resources so they do not clutter the dashboard. What is the recommended best practice to achieve this?

Medium
24

When configuring an Alert Rule in Prisma Cloud CSPM, which THREE notification channels or integration types are natively supported out-of-the-box? (Choose three)

Medium
25

An organization wants to use Prisma Cloud to ensure that no Kubernetes clusters running in Google Kubernetes Engine (GKE) have legacy ABAC (Attribute-Based Access Control) enabled. Which RQL query accomplishes this?

Hard
26

Your security team needs to identify AWS EC2 instances that have been assigned public IP addresses and are accessible from the internet on any port. Which RQL query accurately detects this?

Medium
27

You need to detect if any Azure storage accounts have public blob access enabled across your enterprise subscription. Which RQL query accurately identifies this misconfiguration?

Hard
28

An administrator needs to restrict access to Prisma Cloud so that junior security analysts can only view alerts and assets belonging to the 'PCI-Scope' AWS account, and nothing else. How should this be achieved?

Medium
29

What is the primary purpose of creating an Alert Rule in Prisma Cloud?

Easy
30

What is the function of Prisma Cloud's Trusted Advisor or cloud provider native recommendations integration within CSPM?

Easy
31

An organization wants to enforce an automated remediation workflow in Prisma Cloud for AWS Security Groups that allow unrestricted ingress on port 22 (SSH). How should the administrator configure this integration?

Hard
32

An administrator notices that a connected AWS account is showing a 'Data Collection Error' status in Prisma Cloud. What is the most likely cause of this issue?

Medium
33

An enterprise environment uses Prisma Cloud Data Security posture management to scan for sensitive data in cloud storage. Which capability does Prisma Cloud Data Security provide?

Hard
34

Your security team requires that any high-severity misconfiguration alert generated in Prisma Cloud must immediately notify the SecOps team via a Slack channel. Which feature should you configure?

Medium
35

An administrator needs to write an RQL query to identify AWS IAM users who have access keys that have been active and unchanged for over 365 days. Which RQL query correctly evaluates access key age?

Hard
36

An organization requires that any security alert generated by Prisma Cloud CSPM for production S3 buckets with public access must automatically trigger an AWS Lambda function to remediate the public ACLs. Which mechanism should be configured in Prisma Cloud?

Hard
37

What is the purpose of the Asset Inventory module in Prisma Cloud?

Easy
38

Which TWO of the following capabilities are native functions of Prisma Cloud CSPM? (Choose two)

Hard
39

Which TWO methods can an administrator use to view or export compliance posture data in Prisma Cloud? (Choose two.)

Easy
40

Which TWO types of reports can an administrator schedule or generate directly from the Prisma Cloud console? (Choose two.)

Easy
41

Your organization operates in a heavily regulated industry and requires that all Prisma Cloud audit logs and alert history be retained indefinitely and exported to an external SIEM. How should you configure log retention and forwarding?

Medium
42

Which TWO actions can be taken on an alert within the Prisma Cloud Alerts tab? (Choose two.)

Easy
43

An enterprise uses Prisma Cloud to monitor multi-cloud environments. A custom policy needs to identify Azure Virtual Machines that do not have disk encryption enabled. Which RQL syntax is accurate for Azure disks?

Hard
44

When configuring network flow RQL (`network from vpc.flow`), which THREE attributes or fields can be evaluated in the query? (Choose three.)

Hard
45

An administrator wishes to map custom security policies to the CIS AWS Foundations Benchmark inside Prisma Cloud. Where can compliance standards and mappings be customized or viewed?

Easy
46

An auditor asks for evidence of how long security alerts remain active before being resolved in your multi-cloud environment. Where can an administrator find metrics and trending data regarding alert lifecycles and resolution times?

Hard
47

When onboarding an AWS environment into Prisma Cloud for CSPM, which TWO components or permissions are typically required to establish the integration? (Choose two.)

Medium
48

Which Prisma Cloud feature allows developers to scan Infrastructure as Code (IaC) templates such as Terraform and CloudFormation before deployment?

Easy
49

When configuring an integration with a third-party ticketing system like Jira in Prisma Cloud, which THREE components must typically be provided or configured? (Choose three.)

Hard
50

An administrator wants to use Resource Graph RQL in Prisma Cloud to find all AWS EC2 instances that are not attached to any security group. Which RQL query structure achieves this?

Medium
51

Your compliance team requires proof that Prisma Cloud is actively scanning your cloud environments and generating alerts. Where can an administrator review audit trails of administrative actions taken inside the Prisma Cloud console itself?

Medium
52

Which TWO cloud security posture domains or features are core pillars of Prisma Cloud CSPM? (Choose two.)

Medium
53

Your company acquired another firm that uses a separate AWS account structure. You need to onboard their AWS Organization into your existing Prisma Cloud tenant while keeping their alerts segregated from your primary business unit. How should you structure this?

Medium
54

When creating a custom compliance standard in Prisma Cloud CSPM, what are the primary building blocks required to map your internal policies to the framework?

Easy
55

Which TWO platforms or cloud providers are natively supported for posture management and account onboarding within Prisma Cloud CSPM? (Choose two.)

Easy
56

Which TWO practices are recommended when establishing Role-Based Access Control (RBAC) in Prisma Cloud? (Choose two.)

Medium
57

An enterprise security architect wants to create a custom compliance standard in Prisma Cloud that combines controls from both CIS and NIST SP 800-53. How can this be accomplished?

Medium
58

Which TWO settings or features are configurable under Prisma Cloud Settings > Access Control? (Choose two.)

Medium

Frequently asked questions

What does the Cloud Security Posture Management domain cover on the Cloud-Security-Engineer exam?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How many questions are in this domain?
This page lists all 58 Cloud Security Posture Management questions in the Cloud-Security-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Security Posture Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cloudsec-engineer PANW-CLOUDSEC-ENGINEER cloud security posture management Practice Questions