Courseiva

Cloud-Security-Engineer · topic practice

Cloud Workload Protection practice questions

Practise Certified Cloud Security Engineer (Cloud-Security-Engineer) Cloud Workload Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Cloud Workload Protection

What the exam tests

What to know about Cloud Workload Protection

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Workload Protection exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Practice set

Cloud Workload Protection questions

20 questions · select your answer, then reveal the explanation

An enterprise wants to enforce runtime protection for serverless functions in AWS Lambda without modifying function code layers. Which Prisma Cloud feature should be implemented?

During a vulnerability scan of a container image in the Prisma Cloud Console, a custom Python package installed via pip shows as unpatched, but the CVE has a fixed version available. Why might Prisma Cloud still report the vulnerability as unresolved?

An application running in a Kubernetes pod is attempting to make unauthorized outbound connections to a known command-and-control IP address. The Prisma Cloud Container Defender is deployed in the cluster. Which runtime defense rule should be configured to prevent this behavior?

An administrator needs to scan container images stored in an Azure Container Registry (ACR) without deploying them to a running cluster. Which Prisma Cloud feature accomplishes this?

A security engineer is troubleshooting a Web Application and API Security (WAAS) rule that is not inspecting HTTPS traffic flowing into a Kubernetes Ingress controller. What is the most likely cause?

An administrator notices that Prisma Cloud Host Defenders deployed on AWS EC2 instances are failing to report back to the console. Security groups allow outbound traffic, but VPC Flow Logs show dropped packets on port 8084. What must the administrator verify?

A security team wants to block high-severity Common Vulnerabilities and Exposures (CVEs) from being deployed into production clusters via CI/CD pipelines. Where should this policy be enforced using Prisma Cloud?

A cloud security engineer needs to deploy Prisma Cloud defenders on a Kubernetes cluster. Which method provides the most automated deployment mechanism managed via the Kubernetes control plane?

A container running inside a Kubernetes cluster was compromised, and the attacker attempted to modify the host's kernel parameters using sysctl. Which Prisma Cloud feature detects and prevents this action?

Where in the Prisma Cloud Console can an administrator review compliance benchmark results (such as CIS benchmarks) for deployed container images and hosts?

An administrator needs to install a Prisma Cloud Defender on a standalone Linux virtual machine that does not run Kubernetes or Docker. Which defender type should be selected?

An organization runs sensitive workloads on Google Cloud Run. They need to protect these serverless container services against known vulnerabilities and runtime attacks. Which Prisma Cloud Defender architecture supports Cloud Run?

An organization wants to ensure that no containers run with root privileges in their Amazon ECS clusters. Which Prisma Cloud policy type should be used to enforce this at runtime?

A developer pushes a container image to a private registry, but Prisma Cloud fails to scan it. The registry uses self-signed SSL certificates. What action must the administrator take in the Prisma Cloud Console?

A Linux host running a Prisma Cloud Defender experiences high CPU usage originating from the defender process during a scheduled container image scan. How can an administrator mitigate this impact on production workloads?

An auditor requests a report showing all open vulnerabilities across all active container registries connected to Prisma Cloud. Where can this report be generated?

A security engineer is reviewing container image scan results in Prisma Cloud and notices that a base image vulnerability is marked as 'Not Applicable'. What does this status indicate?

A security team wants to ensure that any container attempting to access the cloud provider metadata service (e.g., 169.254.169.254) from within a compromised workload is blocked. Which Prisma Cloud feature provides this protection?

An enterprise runs containerized microservices on AWS Elastic Kubernetes Service (EKS) and wants to enforce mutual TLS (mTLS) and network micro-segmentation managed via Prisma Cloud. Which feature should be configured?

An administrator wants to view a visual map of all container services, hosts, and incoming network connections across their cloud environment in real time. Which Prisma Cloud Compute view provides this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Workload Protection sessions

Start a Cloud Workload Protection only practice session

Every question in these sessions is drawn from the Cloud Workload Protection domain — nothing else.

Related practice questions

Related Cloud-Security-Engineer topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Cloud-Security-Engineer exam test about Cloud Workload Protection?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Workload Protection questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Workload Protection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Cloud-Security-Engineer topics?
Use the topic links above to move to related areas, or go back to the Cloud-Security-Engineer question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Cloud-Security-Engineer exam covers. They are not copied from any real exam or dump site.