CloudSec-Pro Sample Questions & Answers
Free Palo Alto Networks Cloud Security Professional (CloudSec-Pro) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full CloudSec-Pro simulator →Showing 6 of 12 free samples.
- Question 1Beginner
Application Security · Infrastructure as Code (IaC) security
A DevOps team is implementing a 'Shift Left' strategy. They want to ensure that no Infrastructure as Code (IaC) templates (Terraform, Kubernetes manifests) containing misconfigurations—such as open security groups or unencrypted databases—are deployed to the cloud. Which component of Application Security is BEST suited to integrate into their CI/CD pipeline to achieve this?
Show answer & explanation
Correct answer: A
IaC Scanning analyzes infrastructure templates (like Terraform, ARM, CloudFormation) early in the development lifecycle (IDE, git, CI/CD) to detect misconfigurations before resources are actually provisioned.
- Question 2IntermediateSelect 2
Cloud Posture Security · Cloud security posture management (CSPM)
Which TWO of the following are primary functions of the Cloud Security Posture Management (CSPM) module within the Cortex Cloud platform? (Select TWO)
Show answer & explanation
Correct answers: B, D
CSPM's core role is comparing cloud configurations against security policies and compliance frameworks.
CSPM provides visibility into compliance status across multiple clouds (AWS, Azure, GCP) continuously.
- Question 3Beginner
Cloud Posture Security · Data security posture management (DSPM)
True or False: Data Security Posture Management (DSPM) relies primarily on network traffic analysis to identify sensitive data exfiltration attempts.
Show answer & explanation
Correct answer: B
False. DSPM focuses on discovering, classifying, and assessing the posture of data at rest (e.g., in S3 buckets, databases) to ensure proper access controls and encryption. Network traffic analysis is the domain of NDR or CDR.
- Question 4Advanced
Cloud Runtime Security · Cloud workload protection (CWP)
An organization is deploying a microservices architecture on Kubernetes. They require strict network segmentation between services (East-West traffic) to prevent lateral movement. The native security groups are insufficient. Which Cloud Runtime Security capability should be implemented to achieve Layer 7 visibility and enforcement between pods?
Show answer & explanation
Correct answer: D
Cloud Native Network Segmentation (often part of CWP/Runtime Security) provides identity-based enforcement at Layer 7, allowing granular control over traffic between pods based on application identity rather than just IP addresses.
- Question 5Intermediate
Cloud Posture Security · Identity security
A SOC analyst is investigating an incident where an attacker allegedly used a valid set of access keys to download sensitive data. The keys belong to a role that should only have 'read' access to a specific bucket, but the logs show 'write' actions were also attempted. Which Cortex Cloud module is BEST suited to investigate the permissions associated with this identity and determine if it is over-privileged?
Show answer & explanation
Correct answer: C
CIEM (Cloud Identity Entitlement Management) specializes in analyzing IAM roles, permissions, and effective access. It creates a graph of permissions to identify over-privileged identities and suggest least-privilege policies.
- Question 6Advanced
Application Security · Application security posture management (ASPM)
Review the diagram below illustrating a Kubernetes deployment flow. At which point in this pipeline would Application Security Posture Management (ASPM) provide the MOST value in correlating code-level risks with runtime context?
flowchart LR A[Developer Commit] --> B[CI Build] B --> C[Image Registry] C --> D[K8s Cluster] D --> E[Runtime Monitoring]Show answer & explanation
Correct answer: C
ASPM is designed to provide holistic visibility by correlating insights from Code (A), Build (B), and Runtime (E). It connects the dots between a runtime vulnerability and the specific code repository/developer that introduced it, covering the entire lifecycle.
Ready for the real thing?
The full CloudSec-Pro simulator has every exam-style question, timed mode, and instant scoring.