c2 Flashcards
(115 cards)
Which configuration needs to be done to perform user entity behavior analysis with Prisma Public Cloud?
A. Create alert rules.
B. Whitelist IP addresses.
C. Configure User-ID.
D. Define enterprise settings.
D. Define enterprise settings.
Which two cloud providers support Load Balancers as next hop configurations for outbound connections? (Choose two.)
A. Google Cloud Platform
B. Microsoft Azure
C. Oracle Cloud
D. Amazon Web Services
A. Google Cloud Platform
D. Amazon Web Services
- find instances that are accessible over the internet using insecure ports.
- detect risky changes executed by a root user.
- view all s3 buckets that are open to the public via bucket policy.
match:
config where
event where
network where
- network where
- event where
- config where
Which RQL string returns a list of all Azure virtual machines that are not currently running?
A. config where api.name = ‘azure-vm-list’ AND json.rule = powerState = “off’
B. config where api.name = ‘azure-vm-list’ AND json.rule = powerState does not contain “running”
C. config where api.name = ‘azure-vm-list’ AND json.rule = powerState = “running”
D. config where api.name = ‘azure-vm-list’ AND json.rule = powerState contains “running”
B. config where api.name = ‘azure-vm-list’ AND json.rule = powerState does not contain “running”
Palo Alto Networks recommends which two options for outbound HA design in Amazon Web Services using VM-Series NGFW? (Choose two.)
A. iLB-as-next-hop
B. transit gateway and security VPC with VM-Series
C. traditional active/standby HA on VM-Series
D. transit VPC and security VPC with VM-Series
B. transit gateway and security VPC with VM-Series
C. traditional active/standby HA on VM-Series
Which three anomaly policies are predefined in Prisma Public Cloud? (Choose three.)
A. Excessive login failures
B. Unusual user activity
C. Denial-of-service activity
D. Account hijacking attempts
E. Suspicious file activity
A. Excessive login failures
B. Unusual user activity
D. Account hijacking attempts
An administrator deploys a VM-Series firewall into Amazon Web Services. Which attribute must be disabled on the data-plane elastic network interface for the instance to handle traffic that is not destined to its own IP address?
A. security group
B. tags
C. elastic ip address
D. source/destination checking
D. source/destination checking
Which Google Cloud Platform project shares its VPC networks with other projects?
A. Service project
B. Host project
C. Admin project
D. Subscribing project
B. Host project
An administrator has deployed an AWS transit gateway and used multiple VPC spokes to segregate a
multi-tier application. The administrator also created a security VPC with multiple VM-Series NGFWs
in an active/active deployment model via ECMP using Amazon Web Services VPN-based
attachments.
What must be configured on the firewall to avoid asymmetric routing?
A. source address translation
B. destination address translation
C. port address translation
D. source and destination address translation
A. source address translation
Which two items are required when a VM-100 BYOL instance is upgraded to a VM-300 BYOL
instance? (Choose two.)
A. UUID
B. new Auth Code
C. CPU ID
D. API Key
B. new Auth Code
D. API Key
can you create a custom compliance standard in Prisma Public Cloud?
A. Generate a new Compliance Report.
B. Create compliance framework in a spreadsheet then import into Prisma Public Cloud.
C. From Compliance tab, clone a default framework and customize.
D. From Compliance tab > Compliance Standards, click “Add New.”
D. From Compliance tab > Compliance Standards, click “Add New.”
Which three types of security checks can Prisma Public Cloud perform? (Choose three.)
A. compliance where
B. network where
C. user where
D. config where
E. event where
B. network where
D. config where
E. event where
Prisma Public Cloud enables compliance monitoring and reporting by mapping which configurations
to compliance standards?
A. RQL queries
B. alert rules
C. notification templates
D. policies
D. policies
What configuration on AWS is required in order for VM-Series to forward traffic between its network interfaces?
A. Both Source and Destination Checks are disabled
B. Both Source and Destination Checks are enabled
C. Source Check is disabled and Destination Check is enabled
D. Source Check is enabled and Destination Check is disabled
A. Both Source and Destination Checks are disabled
In which two ways does Palo Alto Networks VM orchestration help service providers automatically
provision security instances and policies? (Choose two.)
A. fully instrumented API
B. Aperture Orchestration Engine
C. VM Orchestration Policy Editor
D. support for Dynamic Address Groups
A. fully instrumented API
D. support for Dynamic Address Groups
Which change represents a VM-Series NGFW license transfer?
A. VM-100 BYOL on Microsoft Azure to VM-100 BYOL on Amazon Web Services
B. VM-300 BYOL on Microsoft Azure to VM-300 PAY6 on Amazon Web Services
C. VM-100 BYOL on Microsoft Azure to VM-300 BYOL on Microsoft Azure
D. VM-100 BYOL on Microsoft Azure to VM-300 PAYG on Amazon Web Services
C. VM-100 BYOL on Microsoft Azure to VM-300 BYOL on Microsoft Azure
The VM-Series integration with Amazon GuardDuty feeds malicious IP addresses to the VM-Series
NGFW using XML API to populate a Dynamic Address Group within a Security policy that blocks
traffic.
How does Amazon Web Services achieve this integration?
A. SNS
B. SQS
C. CodeDeploy
D. Lambda
D. Lambda
What are two examples of Amazon Web Services logging services? (Choose two.)
A. CloudLog
B. CloudEvent
C. CloudWatch
D. CIoudTrail
C. CloudWatch
D. CIoudTrail
What are two ways to initially deploy a VM-Series NGFW in Microsoft Azure? (Choose two.)
A. through ARM Templates in the GitHub Repository
B. through Solution Templates in the Azure Marketplace
C. through Expedition in the Customer Success Portal
D. through Iron Skillets in the GitHub Repository
A. through ARM Templates in the GitHub Repository
B. through Solution Templates in the Azure Marketplace
What is required for an EC2 instance to access the internet directly from an AWS VPC?
A. Internet Gateway
B. Transit Gateway
C. Virtual Private Gateway
D. Customer Gateway
A. Internet Gateway
What is a permanent public IP called on Amazon Web Services?
A. Reserved IP
B. PIP
C. EIP
D. Floating IP
C. EIP
What are the two options to dynamically register tags used by Dynamic Address Groups that are
referenced in policy? (Choose two.)
A. VM Monitoring
B. External Dynamic List
C. CFT Template
D. XML API
A. VM Monitoring
D. XML API
The Microsoft Azure virtual network gateway supports which two site-to-site connectivity options?
(Choose two.)
A. Direct Connect
B. Fast Connect
C. IPsecVPN
D. ExpressRoute
C. IPsecVPN
D. ExpressRoute
Which Prisma Public Cloud policy alerts administrators to unusual user activity?
A. Anomaly
B. Audit Event
C. Network
D. Configuration
A. Anomaly