PCCSE Sample Questions

PCCSE Sample Questions & Answers

Digs into cloud security posture management, the single biggest weight, plus protecting container, host and serverless workloads, deploying Prisma Cloud and onboarding accounts, data security posture management, cloud network security, and incident response automation.

Launch the full PCCSE simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Prisma Cloud Administration · Defender deployment strategies in Kubernetes.

    True or False: When a Prisma Cloud Container Defender is deployed using a DaemonSet in a Kubernetes cluster, it automatically scales and protects new nodes as they are added to the cluster without manual intervention.

    Show answer & explanation

    Correct answer: A

    This is the primary function of a Kubernetes DaemonSet. It ensures that all (or a subset of) nodes run a copy of a pod. When a new node is added to the cluster, the DaemonSet controller automatically schedules a Defender pod on that node, ensuring continuous security coverage as the cluster scales.

  2. Question 2Intermediate

    Data Security and Compliance · Configuring custom data patterns for Data Security Posture Management (DSPM).

    A healthcare organization is using Prisma Cloud's Data Security module to discover and classify sensitive patient data in their AWS S3 buckets. After an initial scan, they find that many objects containing Protected Health Information (PHI) have been misclassified. They need to create a new, highly accurate data pattern for identifying National Provider Identifier (NPI) numbers, which are 10-digit numbers that may or may not have a checksum. What is the most effective way to improve classification accuracy for this specific data type?

    Show answer & explanation

    Correct answer: B

    Prisma Cloud's Data Security module allows for the creation of custom data patterns to identify proprietary or specific data formats. Using a precise RegEx (e.g., \b\d{10}\b) to match the 10-digit structure, combined with proximity keywords, provides a highly accurate method for the classification engine to identify NPI numbers within files, significantly reducing false positives compared to generic patterns.

  3. Question 3Advanced

    Network Security · Implementing microsegmentation using Cloud Network Security (CNS).

    A cloud security engineer needs to establish a network baseline for an application and then enforce a strict microsegmentation policy. The application consists of three tiers: a web front-end, an application logic tier, and a database tier, all running as separate services in a Kubernetes namespace. What is the correct sequence of steps using Prisma Cloud's Cloud Network Security (CNS) capabilities?

    Show answer & explanation

    Correct answer: B

    This sequence follows the recommended best practice for implementing microsegmentation. First, Defenders must be deployed to collect network data. Second, the system observes actual traffic to understand legitimate communication patterns, which are visualized in the Radar. Third, Prisma Cloud can automatically generate policy recommendations based on this observed traffic. Finally, the engineer must review these recommendations, fine-tune them as needed (e.g., removing unnecessary connections), and then enforce them to lock down communication.

  4. Question 4Intermediate

    Prisma Cloud Administration · Role-Based Access Control (RBAC) based on cloud account groups.

    A company has onboarded its AWS Organization to Prisma Cloud. A junior cloud engineer, who is part of a team that only manages the 'Staging' OU, needs access to view compliance findings for accounts within that OU. However, they must be prevented from seeing findings for the 'Production' OU. Which Prisma Cloud feature should be used to enforce this granular access control?

    Show answer & explanation

    Correct answer: C

    Prisma Cloud's RBAC model allows administrators to create Account Groups, which can be defined based on criteria like AWS OUs, tags, or individual account IDs. By creating an Account Group for the 'Staging' OU and another for 'Production', a custom role can be created that grants permissions (e.g., 'Cloud Security Viewer') only on the 'Staging' Account Group. This effectively segments visibility and control within the platform.

  5. Question 5IntermediateSelect 2

    SecOps and Incident Response · Investigating user behavior and anomaly alerts.

    A security analyst is reviewing a high-priority alert in Prisma Cloud titled 'Anomalous Compute Provisioning Activity'. The alert indicates that an unusually high number of VMs were launched in a short period by an IAM user. The analyst needs to quickly assess the potential impact and gather more context. Which TWO actions within the alert details would be most effective for this initial investigation? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

  6. Question 6Advanced

    Cloud Security Posture Management (CSPM) · Writing RQL to inspect IAM policy documents for specific permissions.

    An organization is migrating to a serverless architecture using AWS Lambda. The security team wants to ensure that no Lambda functions are deployed with overly permissive IAM roles, specifically checking for roles that grant iam:PassRole permissions on all resources ('*'). An engineer is tasked with creating a custom policy in Prisma Cloud to detect this misconfiguration. What is the key component in the RQL query to identify this specific condition?

    Show answer & explanation

    Correct answer: B

    This query correctly targets IAM roles and inspects the attached policy documents. The json.rule uses dot notation to traverse the JSON structure of the IAM policy. The condition policy.statement.action equals iam:PassRole finds policies with the PassRole permission, and policy.statement.resource equals * specifically filters for those that are dangerously permissive by applying to all resources.

  7. Question 7Intermediate

    Cloud Workload Protection (CWP) · Configuring File Integrity Monitoring (FIM) using Host Defenders.

    A financial technology company is required to meet PCI DSS compliance. A key requirement is to implement File Integrity Monitoring (FIM) on all servers processing cardholder data. These servers are running as EC2 instances on AWS. The company is using Prisma Cloud Host Defenders. How should the security engineer configure Prisma Cloud to meet the FIM requirement?

    Show answer & explanation

    Correct answer: B

    File Integrity Monitoring is configured centrally within the Prisma Cloud Console. The correct procedure is to create or edit a Host Runtime Policy, navigate to the 'File Integrity' section, and add the specific files and directories that PCI DSS requires to be monitored. The 'effect' for this rule should be set to 'Alert' or 'Prevent' to log and optionally block unauthorized changes.

  8. Question 8Intermediate

    Prisma Cloud Administration · Upgrading Prisma Cloud Compute in an air-gapped environment.

    During an audit, an administrator discovers that the Prisma Cloud Compute Console is running a version with a known critical vulnerability. The Console is deployed in an air-gapped environment with no direct internet access. What is the correct procedure for upgrading the Console in this scenario?

    Show answer & explanation

    Correct answer: C

    For air-gapped environments, the standard upgrade procedure involves downloading the entire software release package (tarball) from a machine with internet access. This package is then securely transferred into the isolated network. From there, the new container images are loaded into the local image management system (like a private registry or directly onto the host's Docker daemon), and the provided upgrade script (prisma_cloud_upgrade.sh) is executed to perform the upgrade.

  9. Question 9Intermediate

    SecOps and Incident Response · Integrating Prisma Cloud with third-party tools like SOAR.

    A security team needs to integrate Prisma Cloud alerts with their Security Orchestration, Automation, and Response (SOAR) platform. The integration requires sending detailed alert data in JSON format over HTTPS to a specific API endpoint. The team wants to ensure that only alerts with a status of 'Open' and a severity of 'High' or 'Critical' are forwarded. Which Prisma Cloud integration method should be used?

    Show answer & explanation

    Correct answer: C

    The generic Webhook integration is designed for this type of custom integration. It allows you to specify a target URL (the SOAR API endpoint) and provides a customizable JSON payload. Most importantly, it can be configured within an Alert Rule, which allows for precise filtering based on criteria like alert status ('Open') and severity ('High', 'Critical'), ensuring that only relevant alerts are sent to the SOAR platform.

  10. Question 10Beginner

    Cloud Security Posture Management (CSPM) · Using the Compliance Dashboard for multi-cloud environments.

    A large enterprise has a multi-cloud strategy using both AWS and Azure. The CISO wants a single, unified view of the organization's compliance posture against the CIS Benchmarks for both cloud providers. Which feature in Prisma Cloud directly addresses this requirement?

    Show answer & explanation

    Correct answer: B

    The Compliance Dashboard is specifically designed to provide a centralized view of compliance against various standards and frameworks. It automatically aggregates data from all onboarded cloud accounts (AWS, Azure, GCP, etc.) and presents a unified report for standards like CIS Benchmarks, allowing the CISO to assess the overall posture without needing to look at separate reports for each cloud.

Ready for the real thing?

The full PCCSE simulator has every exam-style question, timed mode, and instant scoring.

Go to the PCCSE simulator →