Courseiva
Back to Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
Cybersecurity-Apprentice
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related Cybersecurity-Apprentice topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

When onboarding multi-account cloud environments into Prisma Cloud, administrators can choose from several integration methods. Which THREE advantages are gained by setting up centralized cloud account onboarding and role aggregation? (Choose three)

Question 2hardmulti select
Full question →

An administrator is configuring Prisma Cloud Compute defense mechanisms for serverless functions (FaaS) such as AWS Lambda. Which THREE capabilities does Prisma Cloud provide for serverless security? (Choose three)

Question 3easymulti select
Full question →

An administrator is reviewing the core components and capabilities of Prisma Cloud Cloud Security Posture Management (CSPM). Which TWO capabilities are primary functions of Prisma Cloud CSPM? (Choose two)

Question 4hardmulti select
Full question →

An enterprise security architect is reviewing Prisma Cloud integration options for securing cloud-native applications throughout their lifecycle. Which THREE activities are supported by Prisma Cloud Application Security (IaC Security)? (Choose three)

Question 5mediummulti select
Full question →

An organization wants to implement robust risk management and threat detection practices. Which THREE activities are fundamental components of a proactive threat intelligence and risk assessment program? (Choose three)

Question 6hardmulti select
Full question →

A security engineer is reviewing the fundamental security design principles for deploying Palo Alto Networks firewalls in a high-security enterprise data center. Which THREE core practices align with a Zero Trust network architecture model? (Choose three)

Question 7hardmulti select
Full question →

An organization is hardening its Palo Alto Networks firewalls against advanced persistent threats (APTs) and malware campaigns. Which THREE advanced features or profiles should be deployed to ensure maximum protection against zero-day exploits and multi-stage attacks? (Choose three)

Question 8mediummulti select
Full question →

An enterprise security team is implementing data protection controls on their Palo Alto Networks firewalls. Which THREE mechanisms can be utilized to prevent unauthorized data exfiltration? (Choose three)

Question 9mediummulti select
Review the full routing breakdown →

An administrator needs to configure static routing on a PAN-OS Virtual Router. Which THREE parameters are required when defining a static route entry? (Choose three)

Question 10mediummulti select
Full question →

A security analyst is hardening a Palo Alto Networks firewall against common reconnaissance and risk exposure vectors. Which TWO configuration steps should the analyst take to secure the management plane? (Choose two)

Question 11easymulti select
Full question →

Which TWO roles or responsibilities are typically associated with a Tier-1 SOC analyst in a standard security operations structure? (Choose two)

Question 12hardmulti select
Full question →

An administrator is reviewing security events in Cortex XDR and notices multiple alerts tagged with MITRE ATT&CK techniques. Which THREE benefits does integrating MITRE ATT&CK taxonomy into Cortex XDR provide for analysts? (Choose three)

Question 13mediummulti select
Review the full OSPF breakdown →

An administrator is configuring OSPF on a Palo Alto Networks virtual router. Which THREE parameters must match between OSPF routers for an adjacency to form successfully? (Choose three)

Question 14easymulti select
Full question →

Which TWO interface types are available when configuring physical ports on a Palo Alto Networks firewall? (Choose two)

Question 15mediummulti select
Read the full NAT/PAT explanation →

An administrator is configuring NAT on a Palo Alto Networks firewall. Which THREE address types can be used as translation sources in a Source NAT rule? (Choose three)

Question 16mediummulti select
Full question →

An enterprise requires remote access users to connect securely via GlobalProtect. Which TWO authentication methods are natively supported by PAN-OS for verifying GlobalProtect user credentials? (Choose two)

Question 17hardmulti select
Read the full Ansible explanation →

A SOC automation engineer is building a playbook in Cortex XSOAR to handle compromised credentials. Which THREE common integration actions or automations are typically included in such a playbook? (Choose three)

Question 18mediummulti select
Full question →

Which THREE components are required to successfully configure an SSL Forward Proxy decryption policy on a PAN-OS firewall? (Choose three)

Question 19hardmulti select
Full question →

An administrator is reviewing security logs and notices several sessions marked as 'App-ID' change mid-session from 'unknown-tcp' to a specific application like 'ssl' or 'web-browsing'. Which TWO mechanisms explain this behavior? (Choose two)

A security engineer is setting up Cortex XDR data collection on endpoint hosts. Which THREE telemetry types does the Cortex XDR agent collect to enable advanced behavioral analytics and threat hunting? (Choose three)

These Cybersecurity-Apprentice practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style Cybersecurity-Apprentice questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.