Prisma Public Cloud enables compliance monitoring and reporting by mapping which configurations to compliance standards?
A. RQL queries
B. alert rules
C. notification templates
D. policies
A customer CSO has asked you to demonstrate how to identify all "Amazon RDS" resources deployed and the region that they are deployed in. What are two ways that Prisma Public Cloud can show the relevant information?(Choose two.)
A. Generate a compliance report from the Compliance dashboard
B. Write an RQL query from the "Investigate" tab.
C. Configure an Inventory report from the "Alerts" tab
D. Open the Asset dashboard, filter on Amazon Web Services, and click "Amazon RDS" resources.
How is license utilization displayed within the Prisma Public Cloud interface?
A. navigate to the CLI and run show license command
B. navigate to General > Licensing
C. navigate to Dashboard > Asset Inventory
D. navigate to Settings (via the gear icon) > Licensing
In which two ways does Palo Alto Networks VM orchestration help service providers automatically provision security instances and policies? (Choose two.)
A. fully instrumented API
B. Aperture Orchestration Engine
C. VM Orchestration Policy Editor
D. support for Dynamic Address Groups
The customer has an Amazon Web Services Elastic Computing Cloud that provides a service to the internet directly and needs to secure that cloud with a VM-Series NGFW. Which component handles address translation?
A. The server VMs have private use only (RFC 1918) IPs. Amazon's cloud infrastructure translates those addresses to publicly accessible IP addresses. The VM-Series NGFW has publicly accessible IP addresses.
B. The server VMs have private use only (RFC 1918) IPs. The VM-Series NGFW translates those addresses to publicly accessible IP addresses.
C. The server VMs and the VM-Series NGFW have private use only (RFC 1918) IPs. Amazons cloud infrastructure translates those addresses to publicly accessible IP addresses
D. The servers and VM-Series NGFW have publicly accessible IP addresses for management purposes.
A client has a sensitive internet-facing application server in Microsoft Azure and is concerned about resource exhaustion because of distributed denial-of-service attacks What can be configured on the VM-Series firewall to specifically protect this server against this type of attack?
A. Custom threat signature
B. Zone Protection Profile
C. QoS Profile to limit incoming requests
D. DoS Protection Profile with specific session counts
What resource is required to receive inbound traffic from the internet to VM-Series NGFW deployed as a gateway for Azure Stack workloads?
A. Public IP for the VM-Series NGFW
B. NAT appliance
C. Azure Stack Edge Router
D. Border Customer Network
What is required for an EC2 instance to access the internet directly from an AWS VPC?
A. Internet Gateway
B. Transit Gateway
C. Virtual Private Gateway
D. Customer Gateway