Cybersecurity-Apprentice · domain
Cybersecurity Fundamentals
Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Cybersecurity Fundamentals practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cybersecurity Fundamentals questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cybersecurity Fundamentals
Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Cybersecurity Fundamentals exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Cybersecurity Fundamentals questions (27)
Click any question to see the full explanation, or start a practice session above.
A security analyst is hardening a Palo Alto Networks firewall against common reconnaissance and risk exposure vectors. Which TWO configuration steps should the analyst take to secure the management plane? (Choose two)
Medium2A security analyst is reviewing a suspicious inbound connection attempt blocked by the Palo Alto Networks firewall. Which log type contains the details of traffic that matched a Security policy drop or deny action?
Easy3An enterprise security administrator is designing a comprehensive security posture following Zero Trust principles on a Palo Alto Networks Next-Generation Firewall. Which TWO core concepts must be implemented to satisfy a true Zero Trust data and network architecture? (Choose two)
Hard4An administrator is configuring a File Blocking profile to prevent users from downloading potentially dangerous file types. However, users legitimately need to download password-protected archive files (such as .zip files encrypted with passwords) for business operations. How should the administrator configure the profile to handle encrypted archives safely?
Medium5An organization is preparing for a security audit and wants to ensure robust defense-in-depth measures are active on their Palo Alto Networks firewalls. Which TWO security profiles protect against protocol manipulation, evasion techniques, and vulnerability exploitation? (Choose two)
Hard6A security team is reviewing the threat landscape and common attack vectors. Which TWO threats represent prevalent risks that Next-Generation Firewalls mitigate through specialized security subscriptions? (Choose two)
Easy7What is the primary benefit of deploying multi-factor authentication (MFA) for administrative access to security infrastructure?
Easy8During an incident response investigation, a security analyst needs to determine the exact application identified within an encrypted HTTPS stream traversing the firewall. Which PAN-OS feature allows the firewall to identify applications even when obfuscated or using non-standard ports?
Easy9An organization is hardening its Palo Alto Networks firewalls against advanced persistent threats (APTs) and malware campaigns. Which THREE advanced features or profiles should be deployed to ensure maximum protection against zero-day exploits and multi-stage attacks? (Choose three)
Hard10What is the primary function of a Security Information and Event Management (SIEM) system in an enterprise security architecture?
Easy11Which security concept describes the practice of hiding internal network topology and IP address schemes from external entities using Network Address Translation (NAT)?
Easy12An enterprise firewall is experiencing high session utilization due to a distributed denial-of-service (DDoS) SYN flood attack targeting a public web server. Which feature on the Palo Alto Networks firewall should an administrator configure to protect the server from resource exhaustion?
Hard13A security engineer observes an increase in brute-force login attempts against an external-facing administrative portal. The attacks originate from thousands of distinct IP addresses over a short time window. Which profile type should the engineer configure and attach to the security rule to mitigate this volumetric attack?
Medium14An enterprise security team is implementing data protection controls on their Palo Alto Networks firewalls. Which THREE mechanisms can be utilized to prevent unauthorized data exfiltration? (Choose three)
Medium15An organization wants to implement the principle of least privilege for administrators accessing the Palo Alto Networks next-generation firewall. Where should an administrator configure custom Admin Roles to restrict specific configuration and operational tasks?
Easy16An organization is deploying a zero-trust network architecture using Palo Alto Networks firewalls. The security team needs to ensure that internal user traffic destined for sensitive database servers is strictly inspected for application-layer threats. Which security mechanism must be enforced to achieve Layer 7 visibility and control?
Medium17An organization is deploying a comprehensive threat prevention strategy using Palo Alto Networks Security Profiles. Which THREE security profile types are available out-of-the-box to inspect data plane traffic for specific threat vectors? (Choose three)
Hard18An organization wants to implement robust risk management and threat detection practices. Which THREE activities are fundamental components of a proactive threat intelligence and risk assessment program? (Choose three)
Medium19A network administrator notices that a critical internal host is continuously communicating with an external Command and Control (C2) server. To mitigate this risk instantly without disrupting all outbound traffic, where should the administrator check to verify if WildFire or Anti-Spyware signatures are actively blocking this specific traffic pattern?
Medium20A security engineer is reviewing the fundamental security design principles for deploying Palo Alto Networks firewalls in a high-security enterprise data center. Which THREE core practices align with a Zero Trust network architecture model? (Choose three)
Hard21An administrator needs to quickly identify active threats and infected endpoints communicating with known Command and Control (C2) servers across the network. Which Cortex XDR feature should the analyst inspect to view categorized threat alerts mapped to the MITRE ATT and CK framework?
Easy22An enterprise security team needs to protect remote workers connecting over public Wi-Fi networks by ensuring all their internet-bound and corporate traffic is securely tunneled back to the next-generation firewall. Which Palo Alto Networks solution provides this capability?
Easy23A security administrator wants to prevent employees from visiting known malicious and phishing domains. Which security profile should be attached to the security rule controlling outbound web traffic?
Easy24An administrator notices that a critical internal database server is continually targeted by automated vulnerability scanning tools from external IP addresses. Which security profile feature should be applied to the security rule to detect and block these reconnaissance scans?
Medium25Which core cybersecurity principle dictates that users and applications should only be granted the minimum necessary privileges required to perform their authorized tasks?
Easy26What is the primary purpose of deploying a Threat Intelligence platform (TIP) alongside traditional security controls?
Easy27A security analyst receives an alert from Cortex XDR indicating that a suspicious PowerShell script was executed on an employee workstation. Which underlying security telemetry mechanism enabled Cortex XDR to capture the exact process execution tree and command-line arguments?
MediumOther domains
All Cybersecurity-Apprentice exam domains
Frequently asked questions
- What does the Cybersecurity Fundamentals domain cover on the Cybersecurity-Apprentice exam?
- Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 27 Cybersecurity Fundamentals questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cybersecurity Fundamentals questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.