Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Cloud Security Engineer

Domain 6Objective 1

6.1 Identify and Describe Troubleshooting Issues Related to Insufficient Cloud Service Provider (CSP) IAM Permissions, CloudFormation / Terraform Stack Failures, and Organization-Level Onboarding Related Errors, Including Ingestion CLOUD-SECURITY-ENGINEER Practice Questions (Page 3)

Part of the Troubleshooting domain, which accounts for 16% of the CLOUD-SECURITY-ENGINEER exam.

21questions here
5free pages
5concepts
16%of the exam

Questions 11–15

  1. 11foundation · easy

    An organization-level onboarding fails because the member account cannot be associated with the organization. The error message indicates that the account is already a member of another organization. What is the most likely cause?

    Select an answer first
  2. 12application · medium

    A Terraform configuration is used to deploy a Palo Alto Networks firewall. The `terraform apply` fails with the error: 'Error: Error creating network interface: InvalidParameterValue: The security group 'sg-12345' does not exist.' The engineer confirms the security group exists in the AWS account. What is the most likely cause?

    Select an answer first
  3. 13expert · hard

    A security engineer is troubleshooting why CloudTrail logs are not being ingested into Prisma Cloud for a specific AWS account. The IAM role has the required permissions, and the S3 bucket policy allows access. The engineer notices that the CloudTrail trail is configured to deliver logs to an S3 bucket in a different account. What is the most likely cause of the ingestion failure?

    Select an answer first
  4. 14foundation · easy

    During a CloudFormation stack update, the stack rolls back and the status changes to UPDATE_ROLLBACK_COMPLETE. What is the most common reason for this rollback?

    Select an answer first
  5. 15application · medium

    A Terraform configuration is used to deploy a Palo Alto Networks VM-Series firewall. The `terraform plan` command fails with the error: 'Error: Failed to query available provider packages. Could not retrieve the list of available versions for provider hashicorp/aws: 403 Forbidden.' The engineer has network access to the internet. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.