Cloud-Security-Engineer · domain
Cloud Security Posture Management
Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Cloud Security Posture Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cloud Security Posture Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Security Posture Management
Watch out for
Common Cloud Security Posture Management exam traps
Question index
All Cloud Security Posture Management questions (58)
Click any question to see the full explanation, or start a practice session above.
An administrator needs to quickly view the overall security posture and compliance status of multiple AWS accounts connected to Prisma Cloud. Which Prisma Cloud tab provides this aggregate high-level executive dashboard?
Easy2Which TWO methods can administrators use to search or filter assets in the Prisma Cloud Asset Inventory? (Choose two.)
Medium3An auditor needs to review historical configuration changes of an AWS security group that resulted in a compliance violation three weeks ago. Which Prisma Cloud feature should be used?
Hard4How does Prisma Cloud connect to enterprise cloud environments (AWS, Azure, GCP) for CSPM scanning?
Easy5What is the primary benefit of using Prisma Cloud's out-of-the-box (OOTB) policies?
Easy6An administrator needs to ensure that Prisma Cloud policy evaluations run against newly created cloud resources immediately upon deployment. How does Prisma Cloud handle real-time policy evaluation for cloud configurations?
Hard7An administrator in Prisma Cloud wants to identify and remediate overly permissive AWS IAM policies that allow full administrative access. Which Prisma Cloud CSPM feature should the administrator use to automatically generate a least-privilege policy based on actual cloud trail usage?
Medium8Your auditor requests a report showing historical compliance trends over the last 90 days for the ISO 27001 standard. Where can an administrator generate or schedule this report in Prisma Cloud?
Medium9Which THREE capabilities are provided by Prisma Cloud Resource Query Language (RQL)? (Choose three.)
Hard10Which THREE data sources can Prisma Cloud CSPM ingest and analyze to evaluate security posture and compliance? (Choose three)
Hard11When onboarding a new multi-account AWS environment into Prisma Cloud CSPM via CloudFormation, what is the primary purpose of deploying the StackSet template?
Easy12Which TWO actions can an administrator perform when configuring Alert Rules in Prisma Cloud? (Choose two.)
Easy13What role do Prisma Cloud Account Groups play in organizing security posture management?
Easy14When onboarding a new Google Cloud Platform (GCP) organization into Prisma Cloud, what is the primary prerequisite required to grant Prisma Cloud visibility across all projects?
Easy15Which Prisma Cloud feature allows security teams to group cloud resources based on business units, environments (e.g., Production vs. Development), or ownership for targeted policy enforcement?
Easy16Where in Prisma Cloud can an administrator create, modify, or disable OOTB (Out-of-The-Box) and custom security policies?
Easy17An organization requires that all compute instances across AWS and Azure be tagged with an 'Owner' and 'Environment' tag. How can Prisma Cloud enforce or report on missing tags?
Hard18An administrator needs to create a custom RQL policy that detects AWS IAM users who have console access enabled, have not enabled Multi-Factor Authentication (MFA), and have not logged in within the last 90 days. Which RQL query correctly combines these conditions?
Hard19An auditor identifies that an AWS IAM role in your environment has an overly permissive policy granting `*` action on `*` resource. You want to write an RQL query to find all IAM policies with full administrative privileges. What is the correct RQL syntax?
Hard20You are tasked with writing a Resource Query Language (RQL) statement in Prisma Cloud to find all AWS S3 buckets that do not have server-side encryption enabled. Which RQL query correctly achieves this?
Medium21Which THREE actions occur when a Prisma Cloud policy is flagged as a violation (generating an alert)? (Choose three.)
Hard22When creating a custom RQL query in Prisma Cloud, which THREE parameters or clauses are commonly utilized in a configuration resource query (`config from cloud.resource`)? (Choose three.)
Hard23An administrator wants to suppress low-priority Prisma Cloud CSPM alerts for specific development resources so they do not clutter the dashboard. What is the recommended best practice to achieve this?
Medium24When configuring an Alert Rule in Prisma Cloud CSPM, which THREE notification channels or integration types are natively supported out-of-the-box? (Choose three)
Medium25An organization wants to use Prisma Cloud to ensure that no Kubernetes clusters running in Google Kubernetes Engine (GKE) have legacy ABAC (Attribute-Based Access Control) enabled. Which RQL query accomplishes this?
Hard26Your security team needs to identify AWS EC2 instances that have been assigned public IP addresses and are accessible from the internet on any port. Which RQL query accurately detects this?
Medium27You need to detect if any Azure storage accounts have public blob access enabled across your enterprise subscription. Which RQL query accurately identifies this misconfiguration?
Hard28An administrator needs to restrict access to Prisma Cloud so that junior security analysts can only view alerts and assets belonging to the 'PCI-Scope' AWS account, and nothing else. How should this be achieved?
Medium29What is the primary purpose of creating an Alert Rule in Prisma Cloud?
Easy30What is the function of Prisma Cloud's Trusted Advisor or cloud provider native recommendations integration within CSPM?
Easy31An organization wants to enforce an automated remediation workflow in Prisma Cloud for AWS Security Groups that allow unrestricted ingress on port 22 (SSH). How should the administrator configure this integration?
Hard32An administrator notices that a connected AWS account is showing a 'Data Collection Error' status in Prisma Cloud. What is the most likely cause of this issue?
Medium33An enterprise environment uses Prisma Cloud Data Security posture management to scan for sensitive data in cloud storage. Which capability does Prisma Cloud Data Security provide?
Hard34Your security team requires that any high-severity misconfiguration alert generated in Prisma Cloud must immediately notify the SecOps team via a Slack channel. Which feature should you configure?
Medium35An administrator needs to write an RQL query to identify AWS IAM users who have access keys that have been active and unchanged for over 365 days. Which RQL query correctly evaluates access key age?
Hard36An organization requires that any security alert generated by Prisma Cloud CSPM for production S3 buckets with public access must automatically trigger an AWS Lambda function to remediate the public ACLs. Which mechanism should be configured in Prisma Cloud?
Hard37What is the purpose of the Asset Inventory module in Prisma Cloud?
Easy38Which TWO of the following capabilities are native functions of Prisma Cloud CSPM? (Choose two)
Hard39Which TWO methods can an administrator use to view or export compliance posture data in Prisma Cloud? (Choose two.)
Easy40Which TWO types of reports can an administrator schedule or generate directly from the Prisma Cloud console? (Choose two.)
Easy41Your organization operates in a heavily regulated industry and requires that all Prisma Cloud audit logs and alert history be retained indefinitely and exported to an external SIEM. How should you configure log retention and forwarding?
Medium42Which TWO actions can be taken on an alert within the Prisma Cloud Alerts tab? (Choose two.)
Easy43An enterprise uses Prisma Cloud to monitor multi-cloud environments. A custom policy needs to identify Azure Virtual Machines that do not have disk encryption enabled. Which RQL syntax is accurate for Azure disks?
Hard44When configuring network flow RQL (`network from vpc.flow`), which THREE attributes or fields can be evaluated in the query? (Choose three.)
Hard45An administrator wishes to map custom security policies to the CIS AWS Foundations Benchmark inside Prisma Cloud. Where can compliance standards and mappings be customized or viewed?
Easy46An auditor asks for evidence of how long security alerts remain active before being resolved in your multi-cloud environment. Where can an administrator find metrics and trending data regarding alert lifecycles and resolution times?
Hard47When onboarding an AWS environment into Prisma Cloud for CSPM, which TWO components or permissions are typically required to establish the integration? (Choose two.)
Medium48Which Prisma Cloud feature allows developers to scan Infrastructure as Code (IaC) templates such as Terraform and CloudFormation before deployment?
Easy49When configuring an integration with a third-party ticketing system like Jira in Prisma Cloud, which THREE components must typically be provided or configured? (Choose three.)
Hard50An administrator wants to use Resource Graph RQL in Prisma Cloud to find all AWS EC2 instances that are not attached to any security group. Which RQL query structure achieves this?
Medium51Your compliance team requires proof that Prisma Cloud is actively scanning your cloud environments and generating alerts. Where can an administrator review audit trails of administrative actions taken inside the Prisma Cloud console itself?
Medium52Which TWO cloud security posture domains or features are core pillars of Prisma Cloud CSPM? (Choose two.)
Medium53Your company acquired another firm that uses a separate AWS account structure. You need to onboard their AWS Organization into your existing Prisma Cloud tenant while keeping their alerts segregated from your primary business unit. How should you structure this?
Medium54When creating a custom compliance standard in Prisma Cloud CSPM, what are the primary building blocks required to map your internal policies to the framework?
Easy55Which TWO platforms or cloud providers are natively supported for posture management and account onboarding within Prisma Cloud CSPM? (Choose two.)
Easy56Which TWO practices are recommended when establishing Role-Based Access Control (RBAC) in Prisma Cloud? (Choose two.)
Medium57An enterprise security architect wants to create a custom compliance standard in Prisma Cloud that combines controls from both CIS and NIST SP 800-53. How can this be accomplished?
Medium58Which TWO settings or features are configurable under Prisma Cloud Settings > Access Control? (Choose two.)
MediumOther domains
All Cloud-Security-Engineer exam domains
Frequently asked questions
- What does the Cloud Security Posture Management domain cover on the Cloud-Security-Engineer exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 58 Cloud Security Posture Management questions in the Cloud-Security-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Security Posture Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.