
Palo Alto NetworksCertified Cloud Security Engineer
Domain 1Objective 2
1.2 Determine Cortex Cloud Deployment and License Requirements, Data Source Ingestion and Retention Targets, Scanning Models (e.g., Cloud Scan Versus Outpost), and Cloud Provider Identity and Access Management (IAM) Requirements (e.g., Least-Privilege) CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)
Part of the Planning and Installation domain, which accounts for 12% of the CLOUD-SECURITY-ENGINEER exam.
25questions here
5free pages
8concepts
12%of the exam
Questions 11–15
- 11
A security team is integrating Cortex Cloud with a new AWS account. They want to ensure the integration role has the minimum permissions needed. What is the best practice for creating this role?
Select an answer first - 12
Which cloud provider IAM component is typically used to grant Cortex Cloud access to AWS resources?
Select an answer first - 13
When designing an IAM policy for Cortex Cloud, which action should you take to follow least-privilege?
Select an answer first - 14
In the cloud scan model, how is scanning performed?
Select an answer first - 15
A software company wants to scan container images in a private registry for vulnerabilities. They have no existing on-premises infrastructure and want the simplest setup. Which scanning model should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.