Securing AI Usage
Securing AI Build
Security Consulting
Secure Cloud Infra
AI Governance & Control
100

What is the primary operational risk and threat vector (commonly referred to as "Shadow AI") when employees bypass corporate IT to use public LLMs like ChatGPT or Claude?

A) Employees accessing phishing websites hosting cloned "lookalike" chatbot login portals

B) Unsanctioned copying and pasting of proprietary source code, financial projections, or sensitive customer PII into public chatbots

C) Infiltrating local browser memory caches to extract persistent OAuth session tokens

D) Malicious remote prompt injections executed by external public users targeting custom SaaS apps

B) Unsanctioned copying and pasting of proprietary source code, financial projections, or sensitive customer PII into public chatbots

100

Which core capability within the Prisma AIRS platform is responsible for inspecting live prompts and model responses, to prevent real-time data leaks?


A) AI Model Scanning

B) AI Runtime Security

C) AI Red Teaming

D) AI-SPM (Security Posture Management)

B) AI Runtime Security

100

What is the primary business outcome when selling a Unit 42 AI Security Assessment to an enterprise?


A) It provides real-time pen-testing of cloud workloads and automatically patches API vulnerabilities

B) It evaluates an organization's actual AI posture and delivers a strategic roadmap for safe AI adoption

C) It guarantees 100% regulatory compliance with global data protection laws through automated document drafting

D) It benchmarks model inference speed and recommends GPU cost-optimization strategiesB

B) It evaluates an organization's actual AI posture and delivers a strategic roadmap for safe AI adoption

100

What are the CSPs (Cloud Service Providers) where Palo Alto Networks has Native CNGFW (Cloud Next-Generation Firewall)?


A) AWS, Azure, GCP

B) AWS, Azure, Oracle Cloud

C) AWS, GCP, IBM Cloud

D) Azure, GCP, Alibaba CloudA

A) AWS, Azure, GCP

100

As an Account Manager, how can you pitch and sell the new KOI Agentic Endpoint Security solution to your

customers?


A) Only as a standalone, agentless endpoint security solution.

B) Only as an integrated, license-add on feature inside Cortex XDR.

C) Only as a natively integrated product inside the Prisma AIRS platform (managed via SCM).

D) All of the above (available as a standalone product, integrated with AIRS with no XDR requirement, or post-integration).

D) All of the above (available as a standalone product, integrated with AIRS with no XDR requirement, or post-integration).

200

When qualifying an enterprise opportunity for AI Access Security, which pair of discovery questions is most effective to uncover whether a CISO's organization is vulnerable to unsanctioned GenAI usage?

A) "Do you have active Web Application Firewalls blocking OWASP Top 10 exploits?" and "Are browsers restricted to one profile?"

B) "Is your sensitive corporate data currently training public LLMs?" and "Is your employees' AI-generated content copyright indemnified?"

C) "Which specific cloud databases do your developers query?" and "What is your long-term AWS S3 retention policy?"

D) "How many public IP addresses are registered on your firewalls?" and "Do you run monthly external API vulnerability scans?"

B) "Is your sensitive corporate data currently training public LLMs?" and "Is your employees' AI-generated content copyright indemnified?"

200

When speaking with an AppSec team or a CISO, what unique live runtime threats does Prisma AIRS currently stop that traditional, legacy firewalls are blind to?


A) Server-Side Request Forgery (SSRF) and XML External Entity (XXE) attacks on cloud API gateways

B) Unauthorized remote code execution (RCE) via outdated application framework dependencies

C)  Prompt injections, toxic content generation, and sensitive data leaks

D) Cross-Origin Resource Sharing (CORS) misconfigurations and insecure direct object references (IDOR)

C)  Prompt injections, toxic content generation, and sensitive data leaks

200

Which executive buyer profile is the ideal target persona for a Unit 42 AI Security Assessment discovery call?


A) Chief Financial Officers (CFO) looking to reduce infrastructure spending and software licensingB

) Chief Compliance Officers (CCO) and Legal Counsel auditing static GDPR policy documents

C) CISOs, CIOs, and CTOs struggling to balance intense business pressure to innovate in AI with corporate security and data risks

D) Chief Marketing Officers (CMO) and Product Managers launching public-facing AI chat services

C) CISOs, CIOs, and CTOs struggling to balance intense business pressure to innovate in AI with corporate security and data risks

200

How is the Cloud NGFW (Cloud Next-Generation Firewall) licensed?


A) Based on the total number of VPC/VNet peering connections active in the cloud account

B) Based on the volume of outbound/inbound cloud network traffic secured (measured in GB processed)

C) Based on the number of container clusters and virtual machines protected on a monthly basis

D) Based on the count of active security rules and policies processed per second by the engine

B) Based on the volume of outbound/inbound cloud network traffic secured (measured in GB processed)

200

What kind of targets can you setup in AI Red Teaming?


A) Web Application Firewalls, API Proxies, and Content Delivery Networks (CDNs)

B) Applications, Agents and Models

C) Kubernetes Clusters, Docker Registries, and Code Repositories

D) User Sessions, Browser Extensions, and Identity Providers (IdP)

B) Applications, Agents and Models

300

Traditional Cloud Access Security Brokers (CASBs) can only block or allow entire AI websites. How does the Prisma Access Browser competitively differentiate to secure AI usage without hurting user productivity?

A) It runs a cloud sandbox that routes and decodes API payloads using standard SSL proxies

B) It dynamically replaces sensitive strings in outbound traffic with generated synthetic data at the SWG layer

C) It enforces granular, context-aware policies directly inside the browser (such as blocking "paste" actions of SSNs or source code)

D) It deploys localized, agent-based host file configurations that restrict API endpoint access to approved subdomains

C) It enforces granular, context-aware policies directly inside the browser (such as blocking "paste" actions of SSNs or source code)

300

The latest evolution in our platform, Prisma AIRS 3.0, is specifically engineered to address which massive shift in enterprise AI adoption?


A) Transitioning from static, user-driven models to autonomous Agentic systems and workflows

B) Moving from server-hosted centralized LLM models to edge-computed decentralized AI models

C) Shifting from proprietary commercial APIs to open-source self-hosted models

D) Scaling from single-model applications to federated, multi-cloud RAG architectures

A) Transitioning from static, user-driven models to autonomous Agentic systems and workflows

300

Why is discovering employee AI interactions considered a critical first step in a Unit 42 AI Security Assessment?


A) Because unmonitored "Shadow AI" adoption by employees introduces massive, hidden corporate risks like data leakage and IP exposure

B) Because it identifies which employee-facing SaaS tools are under-utilized to help optimize licensing costs

C) Because it provides the IT team with a complete list of personal devices connected to the corporate VPN

D) Because it allows the security team to benchmark network latency across all employee-accessed web domainsA

A) Because unmonitored "Shadow AI" adoption by employees introduces massive, hidden corporate risks like data leakage and IP exposure

300

What are the 3 core assessment components that make up the CLARA (Cloud Network and AI Risk Assessment) framework?

A) Cloud Security Posture Management, Cloud Workload Protection, and Cloud Identity Entitlement

B) Cloud Network Risk Assessment, Cloud Firewall Benchmarking, and AI Risk Assessment

C) Cloud Network Architecture Assessment, Virtual Firewall Sizing, and Prompt Vulnerability Scanning

D) Cloud Traffic Inspection, Cloud Security Group Auditing, and LLM Posture Assessment

B) Cloud Network Risk Assessment, Cloud Firewall Benchmarking, and AI Risk Assessment

300

How is the licensing calculated for the AI Runtime API, and what is its base unit?


A) Based on the number of concurrently connected active host nodes running the model API

B) Based on Monthly Tokens (In Billions)

C) Based on the total number of API requests per minute (RPM)

D) Based on the total gigabytes (GB) of vector storage processed by the search index

B) Based on Monthly Tokens (In Billions)

400

A CISO claims: "We already have an enterprise WAF and standard DLP. We can just write custom regex patterns to stop sensitive data from going to AI endpoints." How do you handle this objection?


A) Explain that WAF and DLP only scan incoming GET requests, while LLM traffic uses encrypted POST requests

B) Explain that traditional DLP/WAFs are built for static formats (like a 9-digit SSN) and struggle with contextual AI traffic and obfuscated jailbreaks

C) Detail how custom regex patterns cause extreme CPU overhead on legacy proxies, resulting in application timeouts

D) Point out that standard DLPs cannot decrypt traffic sent to public APIs because they use custom WebSocket layers

B) Explain that traditional DLP/WAFs are built for static formats (like a 9-digit SSN) and struggle with contextual AI traffic and obfuscated jailbreaks

400

How does Prisma AIRS protect the developer CI/CD pipeline and model training phase before the custom AI application is deployed into live cloud production?

A) By dynamically encrypting the model weights and training datasets using homomorphic cryptography during training

B) By implementing local host firewalls that restrict developer access to public code sharing sites like GitHub

C) By integrating model scanning and vulnerability checks directly into container registries and CI/CD tools to block insecure open-source models

D) By using automated static application security testing (SAST) to rewrite the model's source code before compilation

C) By integrating model scanning and vulnerability checks directly into container registries and CI/CD tools to block insecure open-source models

400

Why does the market shift toward "Autonomous AI Agents" make a proactive Unit 42 assessment so urgent for enterprises right now?


A) Because AI agents natively bypass public cloud identity roles and can access internal resources without SSO verification

B) Because agents bridge human and machine identities to take independent real-time actions, exponentially expanding identity and data attack surfaces

C) Because the use of multiple autonomous agents leads to network packet looping that can crash cloud routing protocols

D) Because agents utilize dynamic web-socket connections that evade detection by standard threat intelligence feeds

B) Because agents bridge human and machine identities to take independent real-time actions, exponentially expanding identity and data attack surfaces

400

Which specific components of the CLARA assessment framework have official landing zones in India, providing a competitive edge for compliance and local data residency?


A) Cloud Network Risk Assessment and Cloud Firewall Benchmarking

B) Cloud Firewall Benchmarking and AI Risk Assessment

C) Cloud Network Risk Assessment and AI Risk Assessment

D) Cloud Network Risk Assessment, Cloud Firewall Benchmarking, and AI Risk Assessment (all three)

A) Cloud Network Risk Assessment and Cloud Firewall Benchmarking

400

Which security concept extends traditional identity and access management to ensure autonomous agents follow the same perimeter protocols as human employees?


A) Workload Identity Federation

B) Agent Identity Security

C) Service Account Token Volume Projection

D) Machine-to-Machine (M2M) OAuth Profiling

B) Agent Identity Security

500

What is the seamless deployment mechanism for Prisma Access Browser that allows a CISO to roll it out to 10,000+ employees instantly without manual laptop setups?


A) Executing a silent kernel-level background patch via Windows Update Registry keys

B) Deploying it as an enterprise browser policy or managed extension via existing MDM tools (like Intune or Jamf) syncing with Okta/Azure AD

C) Deploying dynamic proxy-auto-config (PAC) files via Active Directory group policy objects (GPO)

D) Enforcing a hard network-access-control (NAC) redirect at the core switch layer that quarantines unmanaged browsers

B) Deploying it as an enterprise browser policy or managed extension via existing MDM tools (like Intune or Jamf) syncing with Okta/Azure AD

500

What potential threat can occuer when a company builds a RAG based AI system?


A) Timing attacks executed against physical GPU memory cards in servers.

B) Bad data added to the vector database that tricks the AI into bad actions.

C) Network flood attacks aimed at container control planes in public clouds.

D) Certificate spoofing attacks carried out on internal database connections.

B) Bad data added to the vector database that tricks the AI into bad actions.

500

Once a Unit 42 AI Security Assessment reveals high-risk employee "Shadow AI" leaks, what is the strategic "Land & Expand" sales playbook to close a larger deal?


A) Recommend a hard web block on all public LLM domains and position legacy next-generation firewalls

B) Focus exclusively on selling long-term security consulting services to rewrite their internal AI usage policies

C) Position Prisma Access Browser immediately to secure employee usage, while mapping AIRS to protect internal developer models

D) Offer a discounted pricing bundle on their existing cloud security licensing to cover future AI workloads

C) Position Prisma Access Browser immediately to secure employee usage, while mapping AIRS to protect internal developer models

500

Which specific component of the CLARA assessment framework contains the AIRS (AI Runtime Security) feature?


A) Cloud Network Risk Assessment

B) Cloud Firewall Benchmarking

C) AI Risk Assessment

D) Cloud Native Security AssessmentC

C) AI Risk Assessment

500

How does Portkey’s multi-LLM routing and caching architecture directly solve an enterprise's business challenges regarding unpredictable model API costs?


A) By compressing token payloads using Gzip algorithms before transmitting them across standard HTTP tunnels

B) By implementing semantic caching to reuse previous identical queries and using dynamic load balancing to route traffic to backup models

C) By automatically converting complex models into low-cost, smaller parameter models at the gateway layer

D) By using predictive API throttling to block user requests when daily cloud infrastructure budget thresholds are exceeded

B) By implementing semantic caching to reuse previous identical queries and using dynamic load balancing to route traffic to backup models