Courseiva

Cybersecurity-Apprentice · domain

Cybersecurity Fundamentals

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Cybersecurity Fundamentals practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

27 questions12 easy9 medium6 hard

Focused practice

Practice Cybersecurity Fundamentals questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Cybersecurity Fundamentals

Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Cybersecurity Fundamentals exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Cybersecurity Fundamentals questions (27)

Click any question to see the full explanation, or start a practice session above.

1

A security analyst is hardening a Palo Alto Networks firewall against common reconnaissance and risk exposure vectors. Which TWO configuration steps should the analyst take to secure the management plane? (Choose two)

Medium
2

A security analyst is reviewing a suspicious inbound connection attempt blocked by the Palo Alto Networks firewall. Which log type contains the details of traffic that matched a Security policy drop or deny action?

Easy
3

An enterprise security administrator is designing a comprehensive security posture following Zero Trust principles on a Palo Alto Networks Next-Generation Firewall. Which TWO core concepts must be implemented to satisfy a true Zero Trust data and network architecture? (Choose two)

Hard
4

An administrator is configuring a File Blocking profile to prevent users from downloading potentially dangerous file types. However, users legitimately need to download password-protected archive files (such as .zip files encrypted with passwords) for business operations. How should the administrator configure the profile to handle encrypted archives safely?

Medium
5

An organization is preparing for a security audit and wants to ensure robust defense-in-depth measures are active on their Palo Alto Networks firewalls. Which TWO security profiles protect against protocol manipulation, evasion techniques, and vulnerability exploitation? (Choose two)

Hard
6

A security team is reviewing the threat landscape and common attack vectors. Which TWO threats represent prevalent risks that Next-Generation Firewalls mitigate through specialized security subscriptions? (Choose two)

Easy
7

What is the primary benefit of deploying multi-factor authentication (MFA) for administrative access to security infrastructure?

Easy
8

During an incident response investigation, a security analyst needs to determine the exact application identified within an encrypted HTTPS stream traversing the firewall. Which PAN-OS feature allows the firewall to identify applications even when obfuscated or using non-standard ports?

Easy
9

An organization is hardening its Palo Alto Networks firewalls against advanced persistent threats (APTs) and malware campaigns. Which THREE advanced features or profiles should be deployed to ensure maximum protection against zero-day exploits and multi-stage attacks? (Choose three)

Hard
10

What is the primary function of a Security Information and Event Management (SIEM) system in an enterprise security architecture?

Easy
11

Which security concept describes the practice of hiding internal network topology and IP address schemes from external entities using Network Address Translation (NAT)?

Easy
12

An enterprise firewall is experiencing high session utilization due to a distributed denial-of-service (DDoS) SYN flood attack targeting a public web server. Which feature on the Palo Alto Networks firewall should an administrator configure to protect the server from resource exhaustion?

Hard
13

A security engineer observes an increase in brute-force login attempts against an external-facing administrative portal. The attacks originate from thousands of distinct IP addresses over a short time window. Which profile type should the engineer configure and attach to the security rule to mitigate this volumetric attack?

Medium
14

An enterprise security team is implementing data protection controls on their Palo Alto Networks firewalls. Which THREE mechanisms can be utilized to prevent unauthorized data exfiltration? (Choose three)

Medium
15

An organization wants to implement the principle of least privilege for administrators accessing the Palo Alto Networks next-generation firewall. Where should an administrator configure custom Admin Roles to restrict specific configuration and operational tasks?

Easy
16

An organization is deploying a zero-trust network architecture using Palo Alto Networks firewalls. The security team needs to ensure that internal user traffic destined for sensitive database servers is strictly inspected for application-layer threats. Which security mechanism must be enforced to achieve Layer 7 visibility and control?

Medium
17

An organization is deploying a comprehensive threat prevention strategy using Palo Alto Networks Security Profiles. Which THREE security profile types are available out-of-the-box to inspect data plane traffic for specific threat vectors? (Choose three)

Hard
18

An organization wants to implement robust risk management and threat detection practices. Which THREE activities are fundamental components of a proactive threat intelligence and risk assessment program? (Choose three)

Medium
19

A network administrator notices that a critical internal host is continuously communicating with an external Command and Control (C2) server. To mitigate this risk instantly without disrupting all outbound traffic, where should the administrator check to verify if WildFire or Anti-Spyware signatures are actively blocking this specific traffic pattern?

Medium
20

A security engineer is reviewing the fundamental security design principles for deploying Palo Alto Networks firewalls in a high-security enterprise data center. Which THREE core practices align with a Zero Trust network architecture model? (Choose three)

Hard
21

An administrator needs to quickly identify active threats and infected endpoints communicating with known Command and Control (C2) servers across the network. Which Cortex XDR feature should the analyst inspect to view categorized threat alerts mapped to the MITRE ATT and CK framework?

Easy
22

An enterprise security team needs to protect remote workers connecting over public Wi-Fi networks by ensuring all their internet-bound and corporate traffic is securely tunneled back to the next-generation firewall. Which Palo Alto Networks solution provides this capability?

Easy
23

A security administrator wants to prevent employees from visiting known malicious and phishing domains. Which security profile should be attached to the security rule controlling outbound web traffic?

Easy
24

An administrator notices that a critical internal database server is continually targeted by automated vulnerability scanning tools from external IP addresses. Which security profile feature should be applied to the security rule to detect and block these reconnaissance scans?

Medium
25

Which core cybersecurity principle dictates that users and applications should only be granted the minimum necessary privileges required to perform their authorized tasks?

Easy
26

What is the primary purpose of deploying a Threat Intelligence platform (TIP) alongside traditional security controls?

Easy
27

A security analyst receives an alert from Cortex XDR indicating that a suspicious PowerShell script was executed on an employee workstation. Which underlying security telemetry mechanism enabled Cortex XDR to capture the exact process execution tree and command-line arguments?

Medium

Frequently asked questions

What does the Cybersecurity Fundamentals domain cover on the Cybersecurity-Apprentice exam?
Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 27 Cybersecurity Fundamentals questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cybersecurity Fundamentals questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cybersec-apprentice PANW-CYBERSEC-APPRENTICE cybersecurity fundamentals Practice Questions