Sample questions
Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) practice questions
An administrator wants to prevent users from accessing specific URL categories such as 'gambling' and 'adult' while allowing all other business-related sites. Where should this res…
A firewall is deployed in an environment with asymmetric routing. Packets belonging to the same TCP session enter on different interfaces due to multi-path upstream routing. What c…
An administrator needs to configure a security rule that applies specifically to traffic destined for a DMZ web server using its public NAT IP address (Destination NAT). Which IP a…
An administrator notices that an internal client is infected with malware that is attempting to exfiltrate data over HTTPS using a custom encrypted protocol that evades standard si…
An administrator configures a QoS profile to prioritize VoIP traffic over bulk data transfers. However, after applying the profile, VoIP packets are still experiencing high latency…
An administrator configures a decryption policy to 'No Decrypt' for financial institution websites to comply with privacy regulations. However, the firewall is still decrypting tra…
An administrator wants to ensure that critical database servers are protected against vulnerability exploits, SQL injections, and buffer overflows. Which security profile must be a…
An administrator needs to configure a Palo Alto Networks firewall interface to connect to an untrusted ISP router. Which interface type is appropriate for this connection?
An administrator is configuring security policies on a Palo Alto Networks firewall and wants to ensure best practices for rule organization and management. Which TWO practices are…
An administrator is troubleshooting a scenario where internal clients cannot resolve external domain names through the firewall configured as a DNS proxy. Which TWO settings should…
An administrator notices that the firewall's management plane CPU utilization is consistently at 99%. Which THREE factors or troubleshooting steps should the administrator investig…
An administrator wants to configure Zone Protection Profiles to safeguard the internal network against common layer 2 and layer 3 attacks. Which THREE attack mitigation features ar…
An administrator wants to secure outbound web browsing traffic by inspecting HTTP/HTTPS traffic for malicious URLs, malware, and exploits. Which TWO security profiles should be att…
A network engineer has deployed an active/passive HA pair of PA-5220 firewalls. During a routine failover test, the engineer notices that existing TCP sessions are dropped and must…
An enterprise is integrating Azure Active Directory (Azure AD) with Palo Alto Networks GlobalProtect for SAML authentication. The SOC wants to enforce conditional access policies s…
An administrator wants to ensure that critical server traffic is always prioritized over standard guest internet traffic during periods of network congestion. Which feature should…
Which THREE actions are recommended best practices when securing the management plane of a Palo Alto Networks firewall? (Choose three)
A security analyst is investigating an unauthorized modification of user permissions in a Palo Alto Networks Prisma Access environment. When evaluating the breach under the MITRE A…
A security analyst is investigating an alert in Palo Alto Networks Cortex XDR where an attacker successfully dumped LSASS memory to harvest credentials. According to the MITRE ATT&…
A security operations team is tracking an Advanced Persistent Threat (APT) group that exhibits custom command-and-control (C2) behavior, slow and low data exfiltration, and leverag…
An organization is implementing a Zero Trust Architecture on their Palo Alto Networks Next-Generation Firewall. They want to ensure that access to internal financial databases is g…
An administrator needs to configure administrative access to Panorama so that a junior SOC analyst can view firewall configurations and logs, but cannot make any changes. Which con…
A security analyst reviews a Palo Alto Networks firewall traffic log showing an outbound connection over an encrypted tunnel to an unknown external IP address. The analyst suspects…
An analyst reviewing Cortex XDR alerts observes an attacker attempting to encode malicious scripts using Base64 to bypass signature-based detection mechanisms on an endpoint. Under…