Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Cloud Security Engineer

Domain 3Objective 3

3.3 Explain the Creation and Configuration of Cloud Security Rules and Policies (e.g., Attack Path, Configuration, Data, Identity, Network Exposure, AI) CLOUD-SECURITY-ENGINEER Practice Questions (Page 4)

Part of the Posture Security domain, which accounts for 22% of the CLOUD-SECURITY-ENGINEER exam.

20questions here
4free pages
7concepts
22%of the exam

Questions 16–20

  1. 16foundation · easy

    Which of the following is an example of a network exposure rule?

    Select an answer first
  2. 17application · medium

    A machine learning team is deploying a model that processes sensitive customer data. The security team needs to create a policy that ensures the model's training data is not publicly accessible and that the model endpoint is only accessible from a specific virtual network. Which policy configuration should be used?

    Select an answer first
  3. 18application · medium

    A data security policy must be created to protect sensitive customer data stored in an object storage service. The policy should ensure that data is encrypted at rest and that only a specific set of service principals can access the data. Which combination of policy elements should be configured?

    Select an answer first
  4. 19expert · hard

    A data security policy must be created to protect a database that contains personally identifiable information (PII). The policy must ensure that only a specific set of applications can access the database, and that all data is encrypted in transit. The security team is considering using a combination of identity-based and data classification rules. Which configuration best meets the requirements?

    Select an answer first
  5. 20application · medium

    A security analyst is configuring attack path rules for a web application. The analyst has identified a path where a compromised web application can access a database via a service principal, and the database has a public endpoint. The analyst needs to create a rule that alerts on this specific path. Which rule configuration should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.