
Palo Alto NetworksCertified Cloud Security Engineer
Domain 4Objective 4
4.4 Explain the Creation and Configuration Process for Cloud Detection and Response (CDR) and Threat Management CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)
Part of the Runtime Security domain, which accounts for 18% of the CLOUD-SECURITY-ENGINEER exam.
32questions here
7free pages
9concepts
18%of the exam
Questions 11–15
- 11
A security engineer is creating an automation playbook that should run when a detection rule fires. The playbook needs to perform a series of steps, including gathering additional context from a threat intelligence platform and then blocking the affected user. What must the engineer configure in the playbook?
Select an answer first - 12
What are the key components of an automation playbook in CDR?
Select an answer first - 13
A security analyst is creating a BIOC rule to detect a new malware that exhibits a specific behavior: it creates a scheduled task and then modifies a registry key. The analyst wants to ensure the rule only triggers when both behaviors occur in sequence within a short time. What should the analyst configure in the BIOC rule?
Select an answer first - 14
A security analyst wants to detect a user who is creating multiple admin accounts in a short period, which is a common precursor to privilege escalation. The analyst wants to alert on this behavior pattern, not on a specific account name or IP. Which type of rule should they create?
Select an answer first - 15
A security analyst wants to detect a new ransomware strain that has no known file hashes or C2 domains, but it exhibits a distinct behavior: it encrypts files in rapid succession and then attempts to delete shadow copies. The analyst needs to create a rule that alerts on this behavior pattern. Which type of rule should they create?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.