PSE-PRISMA Sample Questions

PSE-PRISMA Sample Questions & Answers

Checks your knowledge of configuration and compliance posture management tied with workload protection for containers, serverless and hosts, plus Prisma Cloud's architecture basics, network visibility and segmentation, and data security and threat detection.

Launch the full PSE-PRISMA simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    SOC Fundamentals · Explain the role of threat intelligence in incident response and incident management

    A SOC analyst is investigating a Prisma Cloud alert indicating that an EC2 instance is communicating with a known malicious IP address. To understand the context of this event, the analyst needs to determine what other internal and external systems the compromised instance has communicated with over the past 7 days. Which feature in Prisma Cloud provides this network-level visibility?

    Show answer & explanation

    Correct answer: C

    The Investigate tab allows for ad-hoc querying of cloud data using RQL. A Network RQL query can filter on the specific EC2 instance and time range to visualize all ingress and egress network traffic flows, showing exactly which internal and external entities it communicated with. This is a primary tool for network forensics and incident investigation.

  2. Question 2Advanced

    Cloud Posture Security · Explain the role of Posture Security Management Modules

    Case Study

    A large e-commerce company, GlobalRetail, has fully migrated to a multi-cloud environment, using both AWS and Azure for their main application platform. The platform is built on Kubernetes (EKS in AWS, AKS in Azure) and uses various PaaS services like RDS, S3, and Azure Blob Storage. The CISO has mandated a unified security strategy that provides consistent visibility, compliance enforcement, and runtime protection across both clouds from a single console.

    The key requirements are:

    1. Enforce PCI DSS 4.0 compliance across all cloud resources.
    2. Scan all container images for critical vulnerabilities in their CI/CD pipeline before they are pushed to the registry.
    3. Protect the production Kubernetes applications against zero-day exploits and anomalous network connections.
    4. Discover and classify any credit card numbers accidentally stored in S3 or Blob storage.

    Which combination of Prisma Cloud modules offers the most comprehensive solution to meet all of GlobalRetail's requirements?

    Show answer & explanation

    Correct answer: A

    This option correctly maps each requirement to the specific Prisma Cloud module designed to address it: CSPM for compliance standards like PCI DSS (Req 1), CWP for both shift-left image scanning and runtime protection (Req 2 & 3), and Data Security for discovering and classifying sensitive data in cloud storage (Req 4). This represents a complete, integrated solution.

  3. Question 3Advanced

    Cloud Posture Security · Identify and explain the use of key cloud posture security elements

    A security team needs to create a Prisma Cloud RQL query to find all publicly accessible virtual machines in their GCP project that are also tagged with 'Project: Phoenix'. Which RQL query correctly implements this logic?

    Show answer & explanation

    Correct answer: D

    This RQL query correctly identifies the resource type via the API name (gcloud-compute-instances-list). It then uses json.rule to filter for instances with a public IP (type equals ONE_TO_ONE_NAT). Finally, it uses the AND operator to combine this with a filter for the specific label (labels.Project equals Phoenix), ensuring both conditions must be met.

  4. Question 4Beginner

    Application Security · Explain the features and functionality of application security

    The command twistcli hosts scan --address --user --password is used to scan what type of asset for vulnerabilities?

    Show answer & explanation

    Correct answer: B

    The twistcli hosts scan command is specifically designed to perform a vulnerability and compliance scan of the host operating system (Linux or Windows) on which the twistcli binary is executed. The results are then sent to the specified Prisma Cloud Console.

  5. Question 5Intermediate

    Cortex Fundamentals · Demonstrate understanding of data source ingestion

    A cloud administrator is configuring data source ingestion for their Prisma Cloud tenant. They want to ingest AWS CloudTrail logs to enable threat detection and anomaly policies. What is the recommended and most secure method for Prisma Cloud to gain the necessary access to these logs?

    Show answer & explanation

    Correct answer: B

    Using a cross-account IAM role with an external ID is the AWS-recommended best practice for granting third-party services like Prisma Cloud access to your resources. It avoids the use of long-lived credentials (access keys) and mitigates the 'confused deputy' problem by ensuring that only Prisma Cloud can assume the role.

  6. Question 6Intermediate

    Cloud Runtime Security · Explain cloud detection and response (CDR)

    During a runtime security audit, an analyst is reviewing a container model for a production web server. The model, generated by Prisma Cloud's machine learning, shows that the container process 'nginx' is expected to listen on port 443. An alert is triggered because the 'nginx' process attempted to bind to port 22. What is this type of runtime protection mechanism called?

    Show answer & explanation

    Correct answer: B

    The Cloud Native Application Firewall (CNAF) is Prisma Cloud's mechanism for learning the expected behavior of a containerized application, including processes, file system access, and network activity. It creates a model of this normal behavior. When a deviation occurs, such as a process attempting to bind to an unexpected port, CNAF triggers an alert or blocks the action, effectively providing runtime protection against anomalous behavior.

  7. Question 7IntermediateSelect 2

    Cloud Posture Security · Identify and explain the use of key cloud posture security elements

    What are two primary functions of the Prisma Cloud Kubernetes Security Posture Management (KSPM) feature? (Select TWO).

    Show answer & explanation

    Correct answers: B, D

    KSPM integrates with the Kubernetes API server to continuously assess the configuration of cluster components (like the API server, etcd, scheduler) against industry best practices, including the CIS Kubernetes Benchmark.

    KSPM analyzes the YAML manifests of deployed workloads to find security misconfigurations, such as running containers as root, using host networking, or having excessive permissions via RBAC roles.

  8. Question 8Beginner

    Application Security · Explain the features and functionality of application security

    A developer has written a Terraform script to deploy a new web application in Azure. To prevent security misconfigurations from being deployed, the organization requires all Infrastructure as Code (IaC) to be scanned. Where in the development lifecycle is the MOST effective place to integrate Prisma Cloud's IaC scanning?

    Show answer & explanation

    Correct answer: B

    Integrating IaC scanning as a pre-commit hook is the earliest possible point in the development lifecycle. This 'shift-left' approach provides immediate feedback to the developer before the misconfigured code is even committed to the central repository, preventing the issue from propagating through the pipeline and reducing remediation costs.

  9. Question 9Intermediate

    Cloud Posture Security · Identify and explain the use of key cloud posture security elements

    A security team has configured Prisma Cloud with read-only access to their cloud environments. An alert is generated for a publicly exposed security group. The team wants to enable auto-remediation for this specific type of alert. Which additional permission is required in the cloud provider's IAM role for Prisma Cloud to perform this action?

    Show answer & explanation

    Correct answer: B

    To enable auto-remediation, Prisma Cloud needs permissions to modify the misconfigured resource. Following the principle of least privilege, you should grant specific write permissions only for the service in question (e.g., ec2:RevokeSecurityGroupIngress in AWS or Microsoft.Network/networkSecurityGroups/write in Azure), rather than broad administrative access.

  10. Question 10Beginner

    Cloud Posture Security · Identify and explain the use of key cloud posture security elements

    True or False: The Prisma Cloud Agentless Scanning feature requires deploying a Defender on a dedicated scanner host within the customer's VPC to inspect workload snapshots.

    Show answer & explanation

    Correct answer: A

    True. Prisma Cloud's agentless scanning works by taking snapshots of VM disks. It then mounts these snapshots to a temporary scanner VM, which has a Defender installed, within the customer's environment. The Defender on this scanner host performs the vulnerability and compliance analysis on the snapshot data.

Ready for the real thing?

The full PSE-PRISMA simulator has every exam-style question, timed mode, and instant scoring.