
Palo Alto NetworksCertified Cloud Security Engineer
Domain 5Objective 2
5.2 Explain Rule and Policy Deployment and Management CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)
Part of the Application Security domain, which accounts for 16% of the CLOUD-SECURITY-ENGINEER exam.
27questions here
6free pages
6concepts
16%of the exam
Questions 11–15
- 11
A company has multiple development teams using different CI/CD pipelines. They want to enforce a common security policy that all code must pass a security scan before deployment. However, some teams use Jenkins, while others use GitLab CI. The security team wants to manage the policy centrally. What is the most effective approach?
Select an answer first - 12
A development team uses a CI/CD pipeline to deploy a containerized web application. During a recent security review, the team discovered that a known critical vulnerability in a third-party library was present in the production image. The vulnerability had been flagged by a scanner but did not block the deployment because the pipeline only ran the scanner on the source code, not on the final container image. The team wants to prevent this from happening again. Which action should be taken?
Select an answer first - 13
A company wants to enforce a policy that all code deployed to production must pass a security scan. They have multiple teams using different CI/CD tools. What is the most effective way to enforce this policy consistently?
Select an answer first - 14
An organization's security team uses an AI-based tool that monitors application behavior and suggests security guardrails. The tool recommends a guardrail that would block all outbound traffic to a specific geographic region. The team is concerned about the impact on legitimate business operations. What is the best way to proceed?
Select an answer first - 15
A company has a policy that all code must pass a security scan before being deployed to production. They use a CI/CD pipeline that includes a security scanning step. A developer needs to deploy a hotfix for a critical bug, but the security scan is failing due to a low-severity vulnerability that is not related to the hotfix. What should the developer do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.