exam questions

Exam PCCSE All Questions

View all questions & answers for the PCCSE exam

Exam PCCSE topic 1 question 30 discussion

Actual exam question from Palo Alto Networks's PCCSE
Question #: 30
Topic #: 1
[All PCCSE Questions]

The development team wants to block Cross Site Scripting attacks from pods in its environment.
How should the team construct the CNAF policy to protect against this attack?

  • A. create a Host CNAF policy, targeted at a specific resource, check the box for XSS attack protection, and set the action to ג€preventג€.
  • B. create a Container CNAF policy, targeted at a specific resource, check the box for XSS attack protection, and set the action to alert.
  • C. create a Container CNAF policy, targeted at a specific resource, check the box for XSS protection, and set the action to prevent.
  • D. create a Container CNAF policy, targeted at a specific resource, and they should set ג€Explicitly allowed inbound IP sourcesג€ to the IP address of the pod.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 10 months ago
Correct anser is C. pods run in k8s.
upvoted 7 times
...
Spippolo
Most Recent 1 month, 1 week ago
Selected Answer: C
C. Prevent - The request is denied from reaching the protected application, an audit is generated and WAAS responds with an HTML page indicating the request was blocked. Supported only in WAAS Inline proxy setup.
upvoted 1 times
...
Jihe
1 month, 2 weeks ago
C https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/waas/waas-intro
upvoted 1 times
...
kumar_57
3 months, 3 weeks ago
A is correct answer since pods are specified WAAS policy must be created for hosts where these pods might be running in your k8s environment.
upvoted 1 times
...
tipzzz
6 months ago
Containers are in pod, Pods are in host. If you want to protect pods, you have to protect host. A
upvoted 1 times
...
piipo
1 year, 3 months ago
Selected Answer: C
Pod is a container, not a Host
upvoted 3 times
...
SakeBomb
1 year, 5 months ago
Unlike other systems you may have used in the past, Kubernetes doesn't run containers directly; instead it wraps one or more containers into a higher-level structure called a pod. Any containers in the same pod will share the same resources and local network. Pods are used as the unit of replication in Kubernetes.
upvoted 1 times
...
SakeBomb
1 year, 5 months ago
Selected Answer: A
The "one-container-per-Pod" model is the most common Kubernetes use case; in this case, you can think of a Pod as a wrapper around a single container; Kubernetes manages Pods rather than managing the containers directly.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago