[2024年最新] 高合格率な最新PCCSE日本語テストノートとPCCSE日本語高合格率な試験ガイドを試そう
PCCSE日本語実際の問題アンサーPDFには100%カバーリアル試験問題
質問 # 111
アクセス キーとパスワードの両方を使用してコンソール アクセスを有効にしたユーザーを表示する出力を正しく生成する IAM RQL クエリはどれですか?
- A. api.name = 'aws-iam-get-credential-report' かつ json.rule = cert_1_active が true または cert_2_active が true で、password_enabled が「true」に等しいネットワークからの構成
- B. api.name = 'aws-iam-get-credential-report' かつ json.rule = access_key_1_active が false または access_key_2_active が true で、password_enabled が「*」に等しい、cloud.resource からの構成
- C. Cloud.resource からの構成。ここで、api.name = 'aws-iam-get-credential-report' かつ json.rule = access_key_1_active が true または access_key_2_active が true で、password_enabled が「true」に等しい
- D. api.name = 'aws-iam-get-credential-report' かつ json.rule= access_key_1_active が true または access_key_2_active が true で、password_enabled が「true」に等しい構成
正解:C
解説:
View users who enabled console access with both access keys and passwords: config from cloud.resource where api.name = 'aws-iam-get-credential-report' AND json.rule = access_key_1_active is true or access_key_2_active is true and password_enabled is true
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/config-query/co
質問 # 112
カスタム構成クエリの作成時にどのフィールドが必要ですか?
- A. 検索タイプ
- B. api.name
- C. クラウド.タイプ
- D. リソースのステータス
正解:B
解説:
During the creation of a custom config query in Prisma Cloud, the "api.name" field is required. This field specifies the API endpoint that the query will target, essentially defining the scope of the query within the cloud environment. The "api.name" serves as a critical identifier that allows the query to retrieve specific information or perform actions related to the chosen API endpoint. By specifying the "api.name," users can create tailored queries that address their specific security, compliance, or governance needs, enabling more precise and effective management of cloud resources and security posture.
質問 # 113
ネットワーク上のリソースの1つが、デフォルト構成ポリシーのアラートをトリガーしました。
次のリソースJSONスニペットがあるとします。
どのRQLが脆弱性を検出しましたか?
A)
B)
C)
D)
- A. オプションB
- B. オプションC
- C. オプションD
- D. オプションA
正解:A
質問 # 114
AWS のリソースに対する正味有効なアクセス許可の計算に使用されない要素は何ですか?
- A. IPTables ファイアウォール ルール
- B. AWS サービス コントロール ポリシー (SCP)
- C. 権限の境界
- D. AWS 1AM ポリシー
正解:A
解説:
In the context of calculating net effective permissions for a resource in AWS, IPTables firewall rule is not used. Net effective permissions in AWS are determined by evaluating various AWS-specific mechanisms such as IAM policies, permission boundaries, and service control policies (SCPs). IAM policies define what actions are allowed or denied for various AWS resources. Permission boundaries provide a way to delegate administration for IAM entities, setting the maximum permissions that an IAM entity can have. SCPs are part of AWS Organizations and allow for central control over the maximum available permissions for all accounts within an organization. IPTables, on the other hand, is a Linux-based application for setting up firewall rules on individual hosts and is not directly related to AWS resource permissions. Therefore, IPTables firewall rules are not considered when calculating net effective permissions in AWS, making option C the correct answer.
質問 # 115
アクセスキーの使用に関する正しい説明は次のうちどれですか? (2つ選択してください。)
- A. システム管理者はすべてのユーザーのアクセスキーを作成できます
- B. アクセスキーはAPI呼び出しに使用されます
- C. 最大2つのアクセスキーをいつでもアクティブにできます
- D. アクセスキーには有効期限が必要です
正解:A、C
質問 # 116
指定された操作ごとに正しいスキャンモードを一致させます。
(プルダウンリストから回答を選択します。回答は複数回使用される場合と、まったく使用されない場合があります。)
正解:
解説:
Explanation
Diagram Description automatically generated
質問 # 117
顧客には、サーバーレス機能の脆弱性をスキャンするという要件があります。
スキャンを構成する正しいオプションは何ですか?
- A. サーバーレス Defender を関数に埋め込みます。
- B. [防御] > [脆弱性] > [機能] ページから機能スキャン ポリシーを構成します。
- C. [防御] > [コンプライアンス] > [クラウド プラットフォーム] ページからサーバーレス レーダーを構成します。
- D. Lambda レイヤーを使用して、Defender を関数にデプロイします。
正解:B
解説:
In Prisma Cloud, the capability to scan serverless functions, such as AWS Lambda functions, for vulnerabilities is an integral part of ensuring cloud security posture management (CSPM) and compliance. Specifically, option C is correct because Prisma Cloud provides a dedicated section for defining policies related to serverless function vulnerabilities under the "Defend > Vulnerabilities > Functions" page. This feature allows administrators to create and manage policies that automatically scan serverless functions for known vulnerabilities, ensuring that the functions comply with the organization's security standards before they are deployed. This approach aligns with Prisma Cloud's comprehensive security model that covers various aspects of cloud security, including serverless functions, as outlined in the "Guide to Cloud Security Posture Management Tools" document
質問 # 118
コンプライアンスチームは、PrismaCloudポリシーをコンプライアンスフレームワークに関連付ける必要があります。このタスクを実行するには、チームはどのオプションを選択する必要がありますか?
- A. コンプライアンス
- B. アラートルール
- C. カスタムコンプライアンス
- D. ポリシー
正解:D
質問 # 119
Defender がアドミッション コントローラーとして機能するように構成されている Kubernetes オブジェクトの "種類" はどれですか?
- A. ValidatingWebhookConfiguration
- B. MutatingWebhookConfiguration
- C. DestinationRules
- D. PodSecurityPolicies
正解:A
質問 # 120
ユーザーがアカウント乗っ取りの試みによる未知のブラウザーと OS、不可能なタイムトラベル、またはその両方についてレポートしたい場合に、異常設定で低重大度アラートと高重大度アラートを生成するには、どのアラート登録重大度を選択する必要がありますか?
- A. 高
- B. アグレッシブ
- C. 保守的
- D. 中程度
正解:A
解説:
In the Anomaly settings of a cloud security platform, choosing a High alert disposition severity is crucial when the objective is to generate alerts for both low and high severity incidents, especially in scenarios such as reporting unknown browsers and OS, impossible time travel, or account hijacking attempts. Setting the alert severity to High ensures that the security team is promptly notified of both overt and subtle anomalies, enabling quick response to potential security threats that may indicate unauthorized access or suspicious activities within the cloud environment.
質問 # 121
Prisma Cloud は監査イベント レコードの送信をサポートしています。どの 3 つのターゲットへ送信しますか? (3つお選びください。)
- A. SNMP トラップ
- B. プロメテウス
- C. 標準出力
- D. Syslog
- E. ネットフロー
正解:B、C、D
質問 # 122
お客様は、すべてのディフェンダーを一度にアップグレードせずにコンソールをアップグレードする必要がある大規模な環境を持っています。
ディフェンダーのローリングアップグレードを実行する前の2つの前提条件は何ですか? (2つ選択してください。)
- A. ローリングアップグレードの実行前に読み取り専用モードに設定されたすべてのディフェンダー
- B. ローリングアップグレードを実行するには、追加のワークロードライセンスが必要です
- C. ローリングアップグレード前の最新のtwistcliツールの手動インストール
- D. バージョンn-1の既存のコンソール
- E. コンソールをインストールできる2番目の場所
正解:A、D
質問 # 123
AWS の root ユーザーによって実行される特定の高リスクアクティビティを検出するために使用される ROL クエリはどれですか?
- A. event from cloud.audit logs where operation IN ( 'ChangePassword', 'ConsoleLogin', DeactivateMFADevice', 'DeleteAccessKey' , 'DeleteAlarms' ) AND user = 'root'
- B. event from cloud.audit_logs where Risk.Level = 'high1 AND user = 'root'
- C. event from cloud.security_logs where operation IN ( 'ChangePassword', 'ConsoleLogin', 'DeactivateMFADevice1, 'DeleteAccessKey' , 'DeleteAlarms' ) AND user = 'root'
- D. config from cloud.audit_logs where operation IN ( 'ChangePassword', 'ConsoleLogin', 1DeactivateMFADevice', 'DeleteAccessKey' , 'DeleteAlarms' ) AND user = 'root1
正解:A
解説:
The correct Resource Query Language (RQL) query to detect high-risk activities executed by a root user in AWS is the one that specifies cloud audit logs as the data source and filters events based on operations that are indicative of high-risk activities. The query should include operations like 'ChangePassword', 'ConsoleLogin', 'DeactivateMFADevice', 'DeleteAccessKey', and 'DeleteAlarms', which are typically sensitive and should be monitored closely when performed by a root user, due to the elevated privileges associated with this account. The query filters for events where the user is 'root', ensuring that only activities executed by this highly privileged user are returned in the results.
質問 # 124
ビルドおよび実行サブタイプを使用してカスタムポリシーを作成したいとします。各例のクエリタイプを一致させます。
(プルダウンリストから回答を選択します。回答は複数回使用される場合と、まったく使用されない場合があります。)
正解:
解説:
Reference:
https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/create-a- policy.html
質問 # 125
ビルドおよび実行サブタイプを使用してカスタムポリシーを作成したいとします。各例のクエリタイプを一致させます。
(プルダウンリストから回答を選択します。回答は複数回使用される場合と、まったく使用されない場合があります。)
正解:
解説:

質問 # 126
マルウェアから保護できる Prisma Cloud のポリシー タイプは?
- A. 構成
- B. イベント
- C. ネットワーク
- D. データ
正解:D
質問 # 127
AWS 内の S3 バケットが、「AWS S3 バケットはパブリックにアクセス可能」という Prisma Cloud Default ポリシーに違反してアラートを生成しました。ポリシー定義は次のとおりです。
config where cloud.type = 'aws' AND api.name='aws-s3api-get-bucket-acl' AND json.rule="(((acl.grants[? (@.grantee=='AllUsers') ] size > 0) または、policyStatus.isPublic が true) かつ publicAccessBlockConfiguration が存在しない) または ((acl.grants[?(@.grantee=='AllUsers')] size > 0) かつ publicAccessBlockConfiguration.ignorePublicAcis が false) または ( 「policyStatus.isPublic が true で、publicAccessBlockConfiguration.restrictPublicBuckets が false))、websiteConfiguration が存在しません」 このアラートはなぜ生成されましたか?
- A. クラウド アカウント内のイベント
- B. S3 バケットの構成
- C. S3 バケットへのネットワーク トラフィック
- D. 異常な動作
正解:B
解説:
The alert "AWS S3 buckets are accessible to public" is generated due to the configuration of the S3 bucket, which has been set in a way that allows public access. The policy definition provided checks for various conditions that would make an S3 bucket publicly accessible, such as grants to 'AllUsers', the absence of a 'publicAccessBlockConfiguration', or specific configurations that do not restrict public access. Therefore, the alert is triggered by the configuration settings of the S3 bucket that violate the policy's criteria for public accessibility.
質問 # 128
ネットワーク上のリソースの 1 つが、デフォルト構成ポリシーのアラートをトリガーしました。
次のリソース JSON スニペットがあるとします。
どの RQL が脆弱性を検出しましたか?
- A.

- B.

- C.

- D.

正解:C
質問 # 129
展開中の攻撃を特定するために、ファイアウォールとランタイム センサーによって生成される、自動的に関連付けられた個々のイベントのセットは何ですか?
- A. インシデント
- B. 異常
- C. ポリシー
- D. 監査
正解:A
質問 # 130
Prisma Cloud 管理者は、API を介してレポートを取得する任務を負っています。Prisma Cloud テナントは app2.prismacloud.io にあります。
正しい API エンドポイントは何ですか?
- A. https://api2.prismacloud.io
- B. httsp://api.prismacloud.cn
- C. https://api2.eu.prismacloud.io
- D. https://api.prismacloud.io
正解:A
解説:
https://prisma.pan.dev/api/cloud/api-urls/
質問 # 131
コンソールは Kubernetes クラスター内で実行されており、Defender はこのクラスター内のノードにデプロイする必要があります。
デフォルトのコンソール サービス名を使用して Kubernetes の Defender をデプロイするにはどうすればよいですか?
- A. コンソールのデプロイメント ページから、コンソール識別子として「ポッド名」を選択し、DaemonSet ファイルを生成し、DaemonSet をツイストロック名前空間に適用します。
- B. デプロイメント ページから、コンソールでクラウド認証情報を構成し、クラウド検出による Kubernetes ノードの自動保護を許可します。
- C. コンソールのデプロイメント ページから、コンソール識別子として「twistlock-console」を選択し、マスター Kubernetes ノードで「curl | bash」スクリプトを実行します。
- D. コンソールのデプロイメント ページから、コンソール識別子として「twistlock-console」を選択し、DaemonSet ファイルを生成し、DaemonSet をツイストロック名前空間に適用します。
正解:D
解説:
In Kubernetes environments, deploying Defenders to protect nodes involves leveraging DaemonSets, which ensure that every node in the cluster runs a copy of a specific pod. When the Console is running within a Kubernetes cluster, it's essential to correctly reference the Console service to ensure seamless communication between Defenders and the Console. Option A is the most straightforward and Kubernetes-native method for deploying Defenders. By choosing "twistlock-console" as the Console identifier on the deployment page within the Console, users can generate a DaemonSet configuration file tailored for the Twistlock namespace. This approach ensures that the Defenders are correctly configured to communicate with the Console, providing comprehensive security coverage across the Kubernetes nodes. This method aligns with best practices for deploying security agents in Kubernetes and is supported by Prisma Cloud (formerly Twistlock) documentation, which provides step-by-step instructions for deploying Defenders using DaemonSets.
質問 # 132
管理者は、コンテナーに対して実行時監査が生成されたことを確認します。
監査メッセージは次のとおりです。
「/bin/ls が起動され、ランタイム ルールで明示的にブロックされています。完全なコマンド: ls -latr」 ランタイム ルールのどの保護によってこの監査が発生しますか?
- A. プロセス
- B. ネットワーキング
- C. コンテナ
- D. ファイル システム
正解:A
解説:
The protection in the runtime rule that would cause the audit message indicating "/bin/ls launched and is explicitly blocked in the runtime rule" is related to "Processes". In container security, a runtime rule set to monitor and restrict processes can block specific executables or commands from running within a container. If the rule is triggered, it indicates that a process that is explicitly denied by the policy attempted to execute, which in this case is the 'ls' command.
https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-12/prisma-cloud-compute-edition-admin/runtime_def
質問 # 133
Prisma Cloud for Azure の正味有効アクセス許可の計算では、次の Azure アクセス許可レベルがサポートされている 3 つのアクセス許可はどれですか? (3 つ選択してください)。
- A. テナント
- B. 管理グループ
- C. サブスクリプション
- D. リソースグループ
- E. リソース
正解:B、C、D
解説:
In Azure, permissions can be assigned at various levels, including the subscription, resource group, and management group levels. Prisma Cloud's Net Effective Permissions Calculation would typically support these levels to effectively calculate and assess permissions across the Azure environment. Therefore, the correct answers would be A: Resource groups, B: Subscription, and C: Management Group. The option marked as "Tenant" is not a selectable answer in the provided format and "Resources" is too generic as it does not specify the permission level.
質問 # 134
......
PCCSE日本語試験問題とアンサー:https://www.passtest.jp/Palo-Alto-Networks/PCCSE-JPN-shiken.html