[2024年08月]更新のPalo Alto Networks PCCSE日本語問題集合格率を上げるならPCCSE日本語試験問題集 [Q100-Q116]

Share

[2024年08月]更新のPalo Alto Networks PCCSE日本語問題集合格率を上げるならPCCSE日本語試験問題集

あなたのゴールを成し遂げるための問題集!あなたのPrisma Certified Cloud Security Engineer (PCCSE日本語版)の試験準備を合格するために実際のPalo Alto Networks PCCSE日本語問題集をおすすめします

質問 # 100
異常なプロトコルアクティビティ(内部)ネットワークの異常により、生成されるアラートが多すぎます。管理者は、完全に無効にすることなく、生成されるイベントの数が最小になるオプションに調整するように求められました。
管理者はこの目標を達成するためにどの戦略を使用する必要がありますか?

  • A. アラート処理を保守的に設定します
  • B. トレーニングしきい値を低に変更します
  • C. ポリシーを無効にする
  • D. アラート処理をアグレッシブに設定します

正解:B


質問 # 101
お客様は、構成ミスから環境を強化したいと考えています。
ホストに対する Prisma Cloud Compute Compliance の適用が対象となる 3 つのオプションはどれですか? (3つ選んでください。)

  • A. ホスト構成
  • B. Docker デーモン構成ファイル
  • C. Defender エージェントのないホスト
  • D. Docker デーモン構成
  • E. ホスト クラウド プロバイダーのタグ

正解:A、D、E


質問 # 102
顧客が Defender を Fargate 環境にデプロイしています。展開しているイメージの脆弱性を理解したいと考えています。
Fargate にデプロイされたイメージの脆弱性スキャンを自動化するにはどうすればよいですか?

  • A. 専用のイメージスキャナーを提供する Fargate Defender を指定する
  • B. レジストリに脆弱性スキャナーをセットアップする
  • C. Fargate Defender を埋め込み、脆弱性を自動的にスキャンする
  • D. クラウド コンプライアンスを使用して、設定が不適切な AWS アカウントを特定する

正解:B


質問 # 103
InfoSec チームは、セキュリティ グループの構成が誤るたびに電子メールで通知を受け取りたいと考えています。このリクエストを完了するには、どの Prisma Cloud タブを選択する必要がありますか?

  • A. イベント
  • B. 通知
  • C. ポリシー
  • D. アラート ルール

正解:D

解説:
In Prisma Cloud, to notify the InfoSec team via email about misconfigured Security Groups, the appropriate tab to use is "Alert Rules." Alert rules in Prisma Cloud define the conditions under which alerts are generated and the notification channels, including email, where these alerts are sent. By configuring alert rules related to Security Group misconfigurations, the platform can automatically notify the team when such an event occurs, ensuring prompt awareness and response to potential security issues.


質問 # 104
Jenkins パイプラインでコンテナー イメージをスキャンする 2 つの製品はどれですか? (2つお選びください。)

  • A. ツイストクリ
  • B. Jenkins と統合された Prisma Cloud Visual Studio Code プラグイン
  • C. Jenkins Docker プラグイン
  • D. Azure DevOps プラグインの計算
  • E. Jenkins プラグインの計算

正解:A、D

解説:
To integrate security scanning within Jenkins pipelines for container images, the most appropriate tools are the Compute Azure DevOps plugin and Twistcli. The Compute Azure DevOps plugin is designed to integrate with CI/CD workflows, allowing automated security scanning of container images as part of the build process in Azure DevOps environments. This plugin can be used in conjunction with Jenkins pipelines through integration points or scripting to trigger scans during the build or deployment stages. Twistcli, on the other hand, is a command-line interface tool provided by Prisma Cloud (formerly Twistlock) that allows for scanning of container images for vulnerabilities and compliance issues. Twistcli can be directly integrated into Jenkins pipelines using shell scripts or pipeline commands to perform security scans on container images before they are deployed. This ensures that only secure and compliant container images are used in production environments, aligning with DevSecOps practices.


質問 # 105
API を使用して取得できるポリシーの 2 つの属性はどれですか? (2つお選びください。)

  • A. ポリシーモード
  • B. ポリシー違反
  • C. ポリシー署名
  • D. ポリシーラベル

正解:A、D

解説:
Using the Prisma Cloud API, users can fetch various attributes of policies, including the policy label (Option A) and policy mode (Option C). The policy label helps in categorizing and organizing policies, while the policy mode determines how the policy is enforced (e.g., alert, enforce). The policy signature (Option B) is not a standard attribute exposed via the API for fetching, as it relates more to the internal identification and handling of policies. The policy violation (Option D) is an outcome or event resulting from a policy breach, not an attribute of the policy itself that can be fetched via the API.


質問 # 106
開発チームは、イメージ内に特定の CVE が含まれている CI ジョブを失敗させたいと考えています。開発チームは、この結果を生成するためにパイプラインまたはポリシーをどのように構成する必要がありますか?

  • A. 特定の CVE 例外を Jenkins または twistcli のオプションとして設定します。
  • B. コンソールの CI ポリシーで特定の CVE 例外を設定します。
  • C. コンソールでマジック ストリングを使用して、特定の CVE 例外をオプションとして設定します。
  • D. 特定の CVE 例外を、スキャンを実行する Defender のオプションとして設定します。

正解:B

解説:
Reference tech docs: https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/continuous_integration/set_policy_ci_plugins.html Vulnerability rules that target the build tool can allow specific vulnerabilities by creating an exception and setting the effect to 'ignore'. Block them by creating an exception and setting hte effect to 'fail'. For example, you could create a vulnerability rule that explicitly allows CVE-2018-1234 to suppress warnings in the scan results.


質問 # 107
コンソールは Kubernetes クラスターで実行されており、このクラスター内のノードに Defender をデプロイする必要があります。
デフォルトのコンソール サービス名を使用して Kubernetes に Defender を展開する手順を示すオプションはどれですか?

  • A. コンソールのデプロイ ページから、コンソール識別子のポッド名を選択し、DaemonSet ファイルを生成して、DaemonSet を twistlock 名前空間に適用します。
  • B. コンソールのデプロイ ページから、コンソール識別子として twistlock-console を選択し、curl | コマンドを実行します。マスター Kubernetes ノードの bash スクリプト。
  • C. コンソールのデプロイメント ページから、コンソール識別子として twistlock-console を選択し、DaemonSet ファイルを生成して、DaemonSet を twistlock 名前空間に適用します。
  • D. 展開ページから、コンソールでクラウド資格情報を構成し、クラウド検出で Kubernetes ノードを自動保護できるようにします。

正解:C


質問 # 108
開発チームは、環境内のポッドからのクロスサイトスクリプティング攻撃をブロックしたいと考えています。チームは、この攻撃から保護するためにCNAFポリシーをどのように構築する必要がありますか?

  • A. 特定のリソースを対象としたコンテナCNAFポリシーを作成し、XSS攻撃保護のチェックボックスをオンにして、警告するアクションを設定します。
  • B. 特定のリソースを対象としたコンテナCNAFポリシーを作成し、XSS保護のチェックボックスをオンにして、防止するアクションを設定します。
  • C. 特定のリソースを対象としたコンテナCNAFポリシーを作成し、ポッドのIPアドレスに「明示的に許可されたインバウンドIPソース」を設定する必要があります。
  • D. 特定のリソースを対象としたホストCNAFポリシーを作成し、XSS攻撃保護のチェックボックスをオンにして、アクションを「防止」に設定します。

正解:D


質問 # 109
Prisma Cloud の新しい API リリース情報を受け取ることができるクラウド サービス プロバイダーはどれですか?

  • A. AWS、Azure、GCP、IBM、Alibaba
  • B. AWS、Azure、GCP、Oracle、Alibaba
  • C. AWS、Azure、GCP、Oracle、IBM
  • D. AWS、Azure、GCP、IBM

正解:B

解説:
Prisma Cloud, developed by Palo Alto Networks, is known for its comprehensive cloud security capabilities across various cloud service providers (CSPs). The integration and support extend to major CSPs, including AWS (Amazon Web Services), Azure (Microsoft's Cloud), GCP (Google Cloud Platform), Oracle Cloud, and Alibaba Cloud. This wide range of support ensures that organizations leveraging multi-cloud environments can maintain consistent security postures across all their cloud assets. The information regarding supported CSPs by Prisma Cloud can typically be found in their official documentation and release notes, which detail the features, integrations, and enhancements specific to each CSP.


質問 # 110
顧客は、Prisma Cloud Enterprise に接続された Defender を持っています。Defender は、OpenShift で DaemonSet としてデプロイされます。
管理者は、ホストの脆弱性のレポートをどのように取得する必要がありますか?

  • A. [監視] > [脆弱性] > [CVE ビューアー] に移動します。
  • B. [防御] > [脆弱性] > [ホスト] に移動します。
  • C. [防御] > [脆弱性] > [VM イメージ] に移動します。
  • D. [監視] > [脆弱性] > [ホスト] に移動します。

正解:D


質問 # 111
Prisma Cloud で SSO を構成するために必要な 2 つのフィールドはどれですか? (2つ選んでください。)

  • A. ID プロバイダー発行者
  • B. ID プロバイダーのログアウト URL
  • C. Prisma Cloud Access SAML URL
  • D. 証明書

正解:A、C


質問 # 112
Jenkinsまたはtwistcliを使用した画像スキャンのCIポリシーで選択できる3つのオプションはどれですか? (3つ選択してください。)

  • A. スコープ-スキャンは特定のホストで実行されます
  • B. 猶予期間
  • C. 障害しきい値
  • D. ベンダーの修正が利用可能な場合にのみルールを適用します
  • E. 資格情報

正解:B、C、E


質問 # 113
ネットワーク上のリソースの 1 つが、デフォルト構成ポリシーのアラートをトリガーしました。
次のリソース JSON スニペットがあるとします。

どの RQL が脆弱性を検出しましたか?

  • A.
  • B.
  • C.
  • D.

正解:C


質問 # 114
顧客が自動修復を有効にしたいと考えています。
修復用の組み込み CLI コマンドがあるポリシーの種類はどれですか?

  • A. 異常
  • B. 構成
  • C. ネットワーク
  • D. 監査イベント

正解:B


質問 # 115
コンテナ ランタイム モデルの学習フェーズ中に、Prisma Cloud は何時間の「ドライ ラン」期間に入りますか?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:B

解説:
In the context of Prisma Cloud and its Container Runtime Model, the Learning phase is a crucial period where the system observes and understands the normal behaviors and patterns of container activities. This "dry run" period allows Prisma Cloud to establish a baseline of what is considered normal, which later helps in identifying anomalies or malicious activities. A 48-hour period is typically used for this learning phase to ensure that a sufficient amount of data is collected across various times and conditions, providing a comprehensive understanding of typical container operations.


質問 # 116
......

正確でかつ完璧 アンサーはまるでリアル試験問題:https://www.passtest.jp/Palo-Alto-Networks/PCCSE-JPN-shiken.html