
Palo Alto NetworksCertified Cloud Security Professional
Domain 4Objective 1
4.1 Explain Cloud Runtime Security Concepts and Capabilities CLOUD-SECURITY-PROFESSIONAL Practice Questions (Page 4)
Part of the Cloud Runtime Security domain, which accounts for 26% of the CLOUD-SECURITY-PROFESSIONAL exam.
29questions here
6free pages
8concepts
26%of the exam
Questions 16–20
- 16
Which activity is part of the 'scanning' phase in cloud vulnerability management?
Select an answer first - 17
A company has a web application that is protected by a WAAS solution. The security team has noticed that the WAAS is blocking legitimate traffic from a specific user group. They suspect that the WAAS is misidentifying the traffic as malicious. The team wants to ensure that legitimate users are not affected while maintaining protection against OWASP Top 10 threats. Which action should they take?
Select an answer first - 18
A company has a web application that is deployed across multiple cloud regions. The application uses a content delivery network (CDN) to serve static content, and the origin server is behind a load balancer. The security team wants to protect the application from OWASP Top 10 threats without introducing additional latency for users. Which WAAS deployment mode should they choose?
Select an answer first - 19
A company is migrating a legacy application to AWS. The application runs on EC2 instances that are managed by an autoscaling group, and the security team needs continuous visibility into workload vulnerabilities and compliance. The team wants to avoid installing agents on every instance because the AMI is tightly controlled and changes require a lengthy approval process. Which approach should the security team take?
Select an answer first - 20
A security operations center (SOC) uses a SIEM platform to monitor on-premises infrastructure. The company is moving to the cloud and wants to extend visibility into cloud workloads and identities. They want to automate response actions, such as isolating a compromised instance, but they also want to keep the existing SIEM as the central console. Which integration should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-PROFESSIONAL” is a trademark of its owner, used for identification only.