Courseiva

Cloud-Security-Engineer · topic practice

Cloud Security Posture Management practice questions

Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Cloud Security Posture Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Cloud Security Posture Management

What the exam tests

What to know about Cloud Security Posture Management

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security Posture Management exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Practice set

Cloud Security Posture Management questions

20 questions · select your answer, then reveal the explanation

Your security team wants to run an RQL query to investigate network traffic anomalies where outbound traffic is flowing to known malicious IP addresses. Which RQL query type should be used?

An organization wants to enforce an automated remediation workflow in Prisma Cloud for AWS Security Groups that allow unrestricted ingress on port 22 (SSH). How should the administrator configure this integration?

Your auditor requests a report showing historical compliance trends over the last 90 days for the ISO 27001 standard. Where can an administrator generate or schedule this report in Prisma Cloud?

You are tasked with writing a Resource Query Language (RQL) statement in Prisma Cloud to find all AWS S3 buckets that do not have server-side encryption enabled. Which RQL query correctly achieves this?

An enterprise uses Prisma Cloud to monitor multi-cloud environments. A custom policy needs to identify Azure Virtual Machines that do not have disk encryption enabled. Which RQL syntax is accurate for Azure disks?

When onboarding a new Google Cloud Platform (GCP) organization into Prisma Cloud, what is the primary prerequisite required to grant Prisma Cloud visibility across all projects?

An administrator wishes to map custom security policies to the CIS AWS Foundations Benchmark inside Prisma Cloud. Where can compliance standards and mappings be customized or viewed?

An administrator needs to quickly view the overall security posture and compliance status of multiple AWS accounts connected to Prisma Cloud. Which Prisma Cloud tab provides this aggregate high-level executive dashboard?

Your security team requires that any high-severity misconfiguration alert generated in Prisma Cloud must immediately notify the SecOps team via a Slack channel. Which feature should you configure?

Which Prisma Cloud feature allows security teams to group cloud resources based on business units, environments (e.g., Production vs. Development), or ownership for targeted policy enforcement?

An administrator needs to create a custom RQL policy that detects AWS IAM users who have console access enabled, have not enabled Multi-Factor Authentication (MFA), and have not logged in within the last 90 days. Which RQL query correctly combines these conditions?

An administrator needs to restrict access to Prisma Cloud so that junior security analysts can only view alerts and assets belonging to the 'PCI-Scope' AWS account, and nothing else. How should this be achieved?

What is the function of Prisma Cloud's Trusted Advisor or cloud provider native recommendations integration within CSPM?

An auditor identifies that an AWS IAM role in your environment has an overly permissive policy granting `*` action on `*` resource. You want to write an RQL query to find all IAM policies with full administrative privileges. What is the correct RQL syntax?

Your organization operates in a heavily regulated industry and requires that all Prisma Cloud audit logs and alert history be retained indefinitely and exported to an external SIEM. How should you configure log retention and forwarding?

You need to detect if any Azure storage accounts have public blob access enabled across your enterprise subscription. Which RQL query accurately identifies this misconfiguration?

Where in Prisma Cloud can an administrator create, modify, or disable OOTB (Out-of-The-Box) and custom security policies?

An organization wants to use Prisma Cloud to ensure that no Kubernetes clusters running in Google Kubernetes Engine (GKE) have legacy ABAC (Attribute-Based Access Control) enabled. Which RQL query accomplishes this?

Your compliance team requires proof that Prisma Cloud is actively scanning your cloud environments and generating alerts. Where can an administrator review audit trails of administrative actions taken inside the Prisma Cloud console itself?

What is the primary purpose of creating an Alert Rule in Prisma Cloud?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Security Posture Management sessions

Start a Cloud Security Posture Management only practice session

Every question in these sessions is drawn from the Cloud Security Posture Management domain — nothing else.

Related practice questions

Related Cloud-Security-Engineer topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Cloud-Security-Engineer exam test about Cloud Security Posture Management?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Security Posture Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Security Posture Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Cloud-Security-Engineer topics?
Use the topic links above to move to related areas, or go back to the Cloud-Security-Engineer question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Cloud-Security-Engineer exam covers. They are not copied from any real exam or dump site.