[Dec-2025] PSE-PrismaCloud Pre-Exam Practice Tests | Exam Questions and Answers for PSE-Prisma Cloud Professional Study Guide
PSE Palo Alto Networks System Engineer Professional - Prisma Cloud Certification Sample Questions
NEW QUESTION # 15
Which two template formats are supported by the Prisma Cloud infrastructure as code (laC) scan service?
(Choose two.)
- A. JSON
- B. ARM
- C. XML
- D. YAML
Answer: B,D
NEW QUESTION # 16
A customer has deployed a VM-Series NGFW on Amazon Web Services using a PAYG license. What is the sequence required by the customer to switch to a BYOL license?
Answer:
Explanation:
NEW QUESTION # 17
Based on the diagram, prioritize the order in which the Virtual Gateway evaluates the best route based on the deterministic B6P Path selection process.

Answer:
Explanation:
NEW QUESTION # 18
What resource is required to receive inbound traffic from the internet to VM-Series NGFW deployed as a gateway for Azure Stack workloads?
- A. Border Customer Network
- B. Public IP for the VM-Series NGFW
- C. Azure Stack Edge Router
- D. NAT appliance
Answer: C
NEW QUESTION # 19
A Prisma Cloud Administrator has been asked to create a custom policy which notifies the InfoSec team each time a configuration mange is made to a Security group.
Which type of Resource Query Language (RQL) query would be used in this policy?
- A. network from
- B. config from
- C. event from
- D. audit from
Answer: D
NEW QUESTION # 20
Which Google Cloud Platform project shares its VPC networks with other projects?
- A. Service project
- B. Subscribing project
- C. Host project
- D. Admin project
Answer: C
Explanation:
Create a shared VPC using the Trust VPC created when you deployed the firewall template.
Set up a shared VPC for the host (firewall) project:
gcloud compute shared-vpc enable HOST_PROJECT_ID
https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series-firewall-on- google-cloud-platform/autoscaling-on-google-cloud-platform/deploy-autoscaling-on-google-cloud.html
NEW QUESTION # 21
Where can rules be configured and viewed to configure trusted images?
- A. Defend > Compliance > Trusted Images
- B. Monitor > Compliance > Trusted Images
- C. Monitor > Compliance > Images
- D. Defend > Compliance > Images
Answer: A
NEW QUESTION # 22
Which two deployment methods are supported for Prisma Cloud Compute (PCC) container Defenders? (Choose two.)
- A. Oracle Functions service
- B. Azure SQL database instances
- C. Google Kubernetes Engine
- D. Kubernetes DaemonSet
Answer: C,D
NEW QUESTION # 23
How can you use Prisma Public Cloud to identify Amazon EC2 instances that have been tagged as "Private?
- A. Generate a CIS compliance report and review the "Asset Summary."
- B. Open the Asset Dashboard, filter on tags: and choose "Private."
- C. Create an RQL network query to identify traffic from resources tagged "Private."
- D. Create an RQL config query to identify resources with the tag "Private."
Answer: C
NEW QUESTION # 24
An administrator deploys a VM-Series firewall into Amazon Web Services. Which attribute must be disabled on the data-plane elastic network interface for the instance to handle traffic that is not destined to its own IP address?
- A. source/destination checking
- B. security group
- C. elastic ip address
- D. tags
Answer: A
Explanation:
Explanation
https://docs.paloaltonetworks.com/vm-series/8-1/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/de
NEW QUESTION # 25
Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?
- A. Create alert rules.
- B. Whitelist IP addresses.
- C. Define enterprise settings.
- D. Configure User-ID.
Answer: C
Explanation:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly- policies.html
NEW QUESTION # 26
Which type of Prisma Cloud Enterprise alert supports autoremediation?
- A. config
- B. network
- C. anomaly
- D. audit
Answer: A
NEW QUESTION # 27
Which three features are not supported by VM-Series NGFWs on Azure Stack? (Choose three.)
- A. Resource Group
- B. ARM Template
- C. Azure Security Center
- D. Bootstrapping
- E. Azure Application Insight
Answer: B,D,E
NEW QUESTION # 28
Which Prisma Public Cloud policy alerts administrators to unusual user activity?
- A. Audit Event
- B. Anomaly
- C. Network
- D. Configuration
Answer: B
Explanation:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly- policies.html
NEW QUESTION # 29
Which three requirements are needed to register a PAYG VM-Series NGFW at the Palo Alto Networks Customer Support website? (Choose three.)
- A. Auth Code
- B. CPU ID
- C. License Key
- D. Serial Number
- E. UUID
Answer: A,B,D
NEW QUESTION # 30
The customer has an Amazon Web Services Elastic Computing Cloud that provides a service to the internet directly and needs to secure that cloud with a VM-Series NGFW.
Which component handles address translation?
- A. The servers and VM-Series NGFW have publicly accessible IP addresses for management purposes.
- B. The server VMs have private use only (RFC 1918) IPs. The VM-Series NGFW translates those addresses to publicly accessible IP addresses.
- C. The server VMs have private use only (RFC 1918) IPs. Amazon's cloud infrastructure translates those addresses to publicly accessible IP addresses. The VM-Series NGFW has publicly accessible IP addresses.
- D. The server VMs and the VM-Series NGFW have private use only (RFC 1918) IPs. Amazons cloud infrastructure translates those addresses to publicly accessible IP addresses
Answer: D
NEW QUESTION # 31
How can you use Prisma Public Cloud to identify Amazon EC2 instances that have been tagged as "Private?
- A. Generate a CIS compliance report and review the "Asset Summary."
- B. Open the Asset Dashboard, filter on tags: and choose "Private."
- C. Create an RQL config query to identify resources with the tag "Private."
- D. Create an RQL network query to identify traffic from resources tagged "Private."
Answer: B
NEW QUESTION # 32
An administrator has deployed an AWS transit gateway and used multiple VPC spokes to segregate a multi-tier application. The administrator also created a security VPC with multiple VM-Series NGFWs in an active/active deployment model via ECMP using Amazon Web Services VPN-based attachments.
What must be configured on the firewall to avoid asymmetric routing?
- A. port address translation
- B. source and destination address translation
- C. destination address translation
- D. source address translation
Answer: A
NEW QUESTION # 33
Which two items are required when a VM-100 BYOL instance is upgraded to a VM-300 BYOL instance? (Choose two.)
- A. API Key
- B. new Auth Code
- C. UUID
- D. CPU ID
Answer: A,B
Explanation:
In a public cloud deployment, if your firewall is licensed with the BYOL option, you must Deactivate VM before you change the instance type or VM type and apply the license again on the firewall after you complete the model or instance upgrade. When you change the instance type, because the firewall has a new UUID and CPU ID, the existing license will no longer be valid.
https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/about-the-vm-series-firewall/upgrade-the-vm-series-firewall/upgrade-the-vm-series-model
NEW QUESTION # 34
Which RQL query should be used to quickly identify any events related to an organization's Google Cloud Platform Big Query database the last 24 hours?
- A. Event from cloud.autid_logs where cloud.type = "gcp" AND cloud.service = "bigquery.googleapis.com"
- B. Event from cloud.audit_logs where cloud.type = "gcp"
- C. Event from cloud.audit_logs where cloud.service = "Google Bisquery Dataset"
- D. Event from cloud.audit_logs where cloud.type = "grep" AND cloud.service = "Google Bigtable Instance"
Answer: A
NEW QUESTION # 35
What are two examples of Amazon Web Services logging services? (Choose two.)
- A. CloudLog
- B. CIoudTrail
- C. CloudWatch
- D. CloudEvent
Answer: B,C
NEW QUESTION # 36
Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)
- A. Denial-of-service activity
- B. Account hijacking attempts
- C. Excessive login failures
- D. Unusual user activity
- E. Suspicious file activity
Answer: B,C,D
Explanation:
Account hijacking attempts
-Detect potential account hijacking attempts discovered by identifying unusual login activities. These can happen if there are concurrent login attempts made in short duration from two different geographic locations, which is impossible time travel
, or login from a previously unknown browser, operating system, or location.
Excessive login failures
-Detect potential account hijacking attempts discovered by identifying brute force login attempts. Excessive login failure attempts are evaluated dynamically based on the models observed with continuous learning.
Unusual user activity
-Discover insider threat and an account compromise using advanced data science. The Prisma Cloud machine learning algorithm profiles a user's activities on the console, as well as the usage of access keys based on the location and the type of cloud resources.
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly- policies.html
NEW QUESTION # 37
How can all alerts related to "Amazon RDS" be quickly identified within the Prisma Cloud dashboard?
- A. Generate a Center for Internet Security (CIS) compliance report and search for "Amazon RDS" policy violations.
- B. Create a custom Resource Query Language (RQL) configuration report.
- C. View the alert data on the "Asset Inventory" dashboard and filter on "Amazon RDS.
- D. Within the "Alerts" tab. filter on "Amazon RDS" as a service.
Answer: D
NEW QUESTION # 38
......
Palo Alto Networks Exam Practice Test To Gain Brilliante Result: https://www.passsureexam.com/PSE-PrismaCloud-pass4sure-exam-dumps.html
Tested Material Used To PSE-PrismaCloud: https://drive.google.com/open?id=15YcTuHbvP296sgFk2xzWKooa8KPi9eMw