
Palo Alto NetworksCertified Cloud Security Engineer
Domain 2Objective 5
2.5 Explain the Integration Process for Third-Party Static Application Security Testing (SAST) / Software Composition Analysis (SCA) Tools (e.g., Semgrep, Veracode, Generic SARIF) CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)
Part of the Integration domain, which accounts for 16% of the CLOUD-SECURITY-ENGINEER exam.
21questions here
5free pages
7concepts
16%of the exam
Questions 11–15
- 11
A team is using Veracode for SCA scanning. They have configured Veracode to export results in SARIF format. When they upload the SARIF file to Prisma Cloud, the dependency vulnerabilities are not showing up in the 'Vulnerabilities' tab; they only appear in the 'Code Security' tab. What is the most likely reason?
Select an answer first - 12
What is the primary purpose of using Prisma Cloud's API to retrieve scan results from a third-party SAST tool?
Select an answer first - 13
Which CI/CD pipeline stage is most appropriate for running a SAST tool integrated with Prisma Cloud?
Select an answer first - 14
A security team wants to use webhooks to automate the flow of scan results from their SAST tool to Prisma Cloud. The SAST tool supports webhooks to notify external systems when a scan completes. Which approach should the team take?
Select an answer first - 15
Which output format must a generic SAST tool be configured to produce so that Prisma Cloud can import its results?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.