Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Cloud Security Engineer

Domain 1Objective 2

1.2 Determine Cortex Cloud Deployment and License Requirements, Data Source Ingestion and Retention Targets, Scanning Models (e.g., Cloud Scan Versus Outpost), and Cloud Provider Identity and Access Management (IAM) Requirements (e.g., Least-Privilege) CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)

Part of the Planning and Installation domain, which accounts for 12% of the CLOUD-SECURITY-ENGINEER exam.

25questions here
5free pages
8concepts
12%of the exam

Questions 11–15

  1. 11expert · hard

    A security team is integrating Cortex Cloud with a new AWS account. They want to ensure the integration role has the minimum permissions needed. What is the best practice for creating this role?

    Select an answer first
  2. 12foundation · easy

    Which cloud provider IAM component is typically used to grant Cortex Cloud access to AWS resources?

    Select an answer first
  3. 13foundation · easy

    When designing an IAM policy for Cortex Cloud, which action should you take to follow least-privilege?

    Select an answer first
  4. 14foundation · easy

    In the cloud scan model, how is scanning performed?

    Select an answer first
  5. 15application · medium

    A software company wants to scan container images in a private registry for vulnerabilities. They have no existing on-premises infrastructure and want the simplest setup. Which scanning model should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.