Cybersecurity-Apprentice · domain
Endpoint Security
Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Endpoint Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Endpoint Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Endpoint Security
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).
SLAAC vs DHCPv6 vs stateful assignment.
Neighbor Discovery Protocol replacing ARP.
IPv6 routing differences and dual-stack coexistence.
Watch out for
Common Endpoint Security exam traps
- ▸Link-local addresses are not routable beyond the local link.
- ▸SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
- ▸NDP uses ICMPv6, not ARP.
- ▸An IPv6 prefix is /64 for most host subnets, not /24.
Question index
All Endpoint Security questions (30)
Click any question to see the full explanation, or start a practice session above.
Which TWO actions can an administrator perform from the Cortex XDR management console when responding to an active endpoint security incident? (Choose two)
Easy2Which component of the Cortex XDR architecture provides continuous endpoint data collection and threat prevention directly on the host operating system?
Easy3An organization's security policy requires all endpoint security logs to be forwarded to a centralized SIEM in real time. How does Cortex XDR support this requirement?
Hard4Which TWO types of files or threats are typically inspected and analyzed by the WildFire cloud service when integrated with Cortex XDR? (Choose two)
Easy5An administrator wants to prevent users from tampering with or uninstalling the Cortex XDR agent on Windows workstations. Which feature must be configured in the agent settings?
Medium6An administrator is troubleshooting a scenario where Cortex XDR agents are failing to report incident data to the cloud console. Which TWO network-related items should be verified? (Choose two)
Hard7Which THREE actions occur when an endpoint is placed into 'Isolation' mode using Cortex XDR? (Choose three)
Medium8Which THREE features are provided by the Cortex XDR agent to protect endpoints against modern malware and advanced threats? (Choose three)
Medium9An endpoint has been compromised by an advanced persistent threat (APT). The incident response team needs to reconstruct the entire attack lifecycle, showing how the initial access led to lateral movement and persistence. Which Cortex XDR feature provides this visualization?
Hard10An administrator needs to upgrade Cortex XDR agents across all enterprise endpoints. What is the recommended method in the Cortex XDR management console?
Easy11What is the primary function of WildFire integration within the Cortex XDR ecosystem?
Easy12An administrator needs to configure granular endpoint settings for different departments within the organization. Which THREE components of Cortex XDR should be utilized? (Choose three)
Hard13An administrator wants to verify which prevention modules (e.g., Malware, Exploit, Behavioral Threat Protection) are enabled for a specific set of workstations. Where should the administrator check?
Easy14An organization wants to verify that the Cortex XDR agent is actively communicating with the Cortex XDR cloud tenant. Which status indicator should the administrator look for in the Endpoint Management view?
Easy15A security analyst notices that a specific PowerShell script is being blocked on an endpoint by Cortex XDR behavioral threat protection. However, the development team confirms the script is legitimate. Where should the analyst create an exception to allow this specific script execution while maintaining behavioral monitoring?
Medium16An administrator is deploying Cortex XDR agent to corporate Windows endpoints and needs to ensure that the agent runs in full prevention mode without user intervention. Which configuration setting in the installation profile must be verified?
Easy17An endpoint running macOS encounters a kernel extension loading blockage when installing the Cortex XDR agent. What action must the administrator take to resolve this?
Medium18An administrator needs to deploy Cortex XDR agents across a large enterprise using an Active Directory Group Policy Object (GPO). The installation fails on Windows endpoints with an error indicating missing prerequisites. What must be verified first?
Hard19An endpoint generates an alert indicating that a known malicious file was detected and quarantined by the Cortex XDR agent. Where can the administrator review details about this quarantine action?
Easy20An enterprise environment contains legacy Windows servers that cannot support the latest Cortex XDR agent version due to OS limitations. How does Cortex XDR handle protection for these older operating systems?
Hard21Which TWO operating systems are officially supported for deployment of the standard Cortex XDR agent? (Choose two)
Easy22A security analyst is reviewing a BIOC (Behavioral Indicator of Compromise) alert in the Cortex XDR incident view. What distinguishes a BIOC alert from a standard malware alert?
Medium23Which THREE methods can be used to deploy the Cortex XDR agent package across an enterprise Windows environment? (Choose three)
Medium24A security analyst is investigating a polymorphic malware sample that attempts to inject code into legitimate Windows processes (Process Injection). Which Cortex XDR protection module is primarily responsible for detecting and blocking this technique?
Medium25An endpoint generates an alert for a suspicious script execution, but the analyst determines it is a false positive generated by a legitimate administrative tool. What is the best practice for handling this false positive in Cortex XDR?
Medium26An administrator is troubleshooting a Cortex XDR agent that has stopped reporting to the management console. The local agent service is running, but network traces show TLS handshake failures with the Cortex XDR server. What is the most likely cause?
Hard27An endpoint has been isolated via the Cortex XDR console due to a suspected ransomware outbreak. The incident responder needs to allow one specific management server to communicate with this isolated endpoint for forensics collection. What is the correct procedure?
Hard28An administrator is reviewing security events in Cortex XDR and notices multiple alerts tagged with MITRE ATT&CK techniques. Which THREE benefits does integrating MITRE ATT&CK taxonomy into Cortex XDR provide for analysts? (Choose three)
Hard29An endpoint experiences a zero-day fileless attack where shellcode is executed directly in memory via a vulnerable service. Which Cortex XDR protection feature is specifically designed to detect and block this type of attack prior to file drop?
Hard30An endpoint user reports that a legitimate internal application is failing to run because the Cortex XDR agent flags its behavior as suspicious. The administrator wants to collect forensic data specifically for this application to analyze its behavior. Which Cortex XDR feature should be enabled?
MediumOther domains
All Cybersecurity-Apprentice exam domains
Frequently asked questions
- What does the Endpoint Security domain cover on the Cybersecurity-Apprentice exam?
- IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
- How many questions are in this domain?
- This page lists all 30 Endpoint Security questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Endpoint Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.