Practice Cybersecurity-Apprentice Endpoint Security questions with full explanations on every answer.
Start practicing
Endpoint Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An endpoint has been isolated via the Cortex XDR console due to a suspected ransomware outbreak. The incident responder needs to allow one specific management server to communicate with this isolated endpoint for forensics collection. What is the correct procedure?
2An administrator is deploying Cortex XDR agent to corporate Windows endpoints and needs to ensure that the agent runs in full prevention mode without user intervention. Which configuration setting in the installation profile must be verified?
3A security analyst is investigating a polymorphic malware sample that attempts to inject code into legitimate Windows processes (Process Injection). Which Cortex XDR protection module is primarily responsible for detecting and blocking this technique?
4A security analyst notices that a specific PowerShell script is being blocked on an endpoint by Cortex XDR behavioral threat protection. However, the development team confirms the script is legitimate. Where should the analyst create an exception to allow this specific script execution while maintaining behavioral monitoring?
5An organization wants to verify that the Cortex XDR agent is actively communicating with the Cortex XDR cloud tenant. Which status indicator should the administrator look for in the Endpoint Management view?
6An endpoint generates an alert indicating that a known malicious file was detected and quarantined by the Cortex XDR agent. Where can the administrator review details about this quarantine action?
7An administrator needs to deploy Cortex XDR agents across a large enterprise using an Active Directory Group Policy Object (GPO). The installation fails on Windows endpoints with an error indicating missing prerequisites. What must be verified first?
8An endpoint user reports that a legitimate internal application is failing to run because the Cortex XDR agent flags its behavior as suspicious. The administrator wants to collect forensic data specifically for this application to analyze its behavior. Which Cortex XDR feature should be enabled?
9An administrator is troubleshooting a Cortex XDR agent that has stopped reporting to the management console. The local agent service is running, but network traces show TLS handshake failures with the Cortex XDR server. What is the most likely cause?
10What is the primary function of WildFire integration within the Cortex XDR ecosystem?
11An endpoint running macOS encounters a kernel extension loading blockage when installing the Cortex XDR agent. What action must the administrator take to resolve this?
12An organization's security policy requires all endpoint security logs to be forwarded to a centralized SIEM in real time. How does Cortex XDR support this requirement?
13Which component of the Cortex XDR architecture provides continuous endpoint data collection and threat prevention directly on the host operating system?
14An administrator wants to prevent users from tampering with or uninstalling the Cortex XDR agent on Windows workstations. Which feature must be configured in the agent settings?
15An endpoint experiences a zero-day fileless attack where shellcode is executed directly in memory via a vulnerable service. Which Cortex XDR protection feature is specifically designed to detect and block this type of attack prior to file drop?
16An administrator needs to upgrade Cortex XDR agents across all enterprise endpoints. What is the recommended method in the Cortex XDR management console?
17An endpoint has been compromised by an advanced persistent threat (APT). The incident response team needs to reconstruct the entire attack lifecycle, showing how the initial access led to lateral movement and persistence. Which Cortex XDR feature provides this visualization?
18A security analyst is reviewing a BIOC (Behavioral Indicator of Compromise) alert in the Cortex XDR incident view. What distinguishes a BIOC alert from a standard malware alert?
19Which TWO actions can an administrator perform from the Cortex XDR management console when responding to an active endpoint security incident? (Choose two)
20An enterprise environment contains legacy Windows servers that cannot support the latest Cortex XDR agent version due to OS limitations. How does Cortex XDR handle protection for these older operating systems?
21An administrator wants to verify which prevention modules (e.g., Malware, Exploit, Behavioral Threat Protection) are enabled for a specific set of workstations. Where should the administrator check?
22An endpoint generates an alert for a suspicious script execution, but the analyst determines it is a false positive generated by a legitimate administrative tool. What is the best practice for handling this false positive in Cortex XDR?
23Which THREE features are provided by the Cortex XDR agent to protect endpoints against modern malware and advanced threats? (Choose three)
24An administrator is troubleshooting a scenario where Cortex XDR agents are failing to report incident data to the cloud console. Which TWO network-related items should be verified? (Choose two)
25Which TWO operating systems are officially supported for deployment of the standard Cortex XDR agent? (Choose two)
26Which THREE methods can be used to deploy the Cortex XDR agent package across an enterprise Windows environment? (Choose three)
27Which TWO types of files or threats are typically inspected and analyzed by the WildFire cloud service when integrated with Cortex XDR? (Choose two)
28Which THREE actions occur when an endpoint is placed into 'Isolation' mode using Cortex XDR? (Choose three)
29An administrator needs to configure granular endpoint settings for different departments within the organization. Which THREE components of Cortex XDR should be utilized? (Choose three)
30An administrator is reviewing security events in Cortex XDR and notices multiple alerts tagged with MITRE ATT&CK techniques. Which THREE benefits does integrating MITRE ATT&CK taxonomy into Cortex XDR provide for analysts? (Choose three)
The Endpoint Security domain covers the key concepts tested in this area of the Cybersecurity-Apprentice exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all Cybersecurity-Apprentice domains — no account required.
The Courseiva Cybersecurity-Apprentice question bank contains 30 questions in the Endpoint Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included