Courseiva

Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) (Cybersecurity-Practitioner) — Questions 175

206 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
Multi-Selecthard

An administrator is reviewing Prisma Cloud Data Security reports and identifies several high-risk findings related to AWS S3 buckets. Which THREE conditions or findings would trigger an alert in Prisma Cloud Data Security? (Choose three)

Select 3 answers
A.An S3 bucket containing personally identifiable information (PII) shared externally with unauthorized third-party AWS accounts.
B.An invalid TLS certificate on an internal load balancer.
C.An S3 bucket containing credit card numbers or Social Security Numbers configured with public read ACLs.
D.An AWS EC2 instance running Linux kernel version 5.4 with missing security patches.
E.An S3 bucket storing unencrypted files classified as confidential financial records.
AnswersA, C, E

Correct. Unauthorized external sharing of PII is flagged by Data Security.

Why this answer

Prisma Cloud Data Security scans S3 buckets for public exposure, sensitive data (PII/PCI), and unencrypted sensitive objects.

2
Multi-Selecthard

An incident response team is analyzing an Advanced Persistent Threat (APT) group that has successfully infiltrated a corporate network. Which THREE characteristics are typically associated with APT campaigns compared to opportunistic malware? (Choose three)

Select 3 answers
A.Highly targeted objectives directed at specific intellectual property or geopolitical intelligence
B.Indiscriminate, mass distribution via automated spam campaigns aiming for immediate widespread ransom
C.Immediate self-destruction of the compromised infrastructure upon payload execution
D.High operational stealth and deliberate efforts to maintain long-term persistence without detection
E.Extensive use of custom malware and living-off-the-land techniques tailored to the victim environment
AnswersA, D, E

APTs are characterized by deliberate targeting of specific organizations for intelligence or IP theft.

Why this answer

APT campaigns are distinguished by targeted motives, stealthy persistence, custom tooling, and multi-stage manual objectives.

3
MCQeasy

An organization wants to inspect encrypted outbound HTTPS traffic to detect malware without causing certificate warnings on user workstations. Which component must be installed on the client endpoints to achieve this?

A.The GlobalProtect client certificate installed in the personal certificate store.
B.The public vendor certificate of the SaaS application.
C.The Palo Alto Networks root CA certificate installed in the browser or OS Trusted Root Certification Authorities store.
D.A self-signed untrusted certificate generated automatically by the firewall.
AnswerC

Clients must trust the firewall's Forward Trust certificate to avoid SSL warning prompts.

Why this answer

Forward Trust Certificate must be signed by the enterprise internal Certificate Authority (CA) and installed in the trusted root certificate store of all client endpoints.

4
Multi-Selecthard

An administrator notices that the firewall's management plane CPU utilization is consistently at 99%. Which THREE factors or troubleshooting steps should the administrator investigate? (Choose three)

Select 3 answers
A.Excessive XML API requests or frequent script-based configuration pushes.
B.An improperly sized Layer 3 forwarding table causing next-hop packet re-synthesis on the data plane.
C.High volume of logging queries, traffic log exports, or Panorama log forwarding activity.
D.Large or excessively frequent External Dynamic List (EDL) downloads saturating management plane retrieval threads.
E.GlobalProtect Gateway SSL VPN data tunnel encryption processing.
AnswersA, C, D

Automated scripts pushing API calls frequently consume management plane CPU resources.

Why this answer

High management plane CPU can be caused by heavy logging/reporting queries, large external dynamic list (EDL) downloads, excessive Panorama synchronization, or frequent XML API requests.

5
MCQmedium

An administrator wants to ensure that critical database servers are protected against vulnerability exploits, SQL injections, and buffer overflows. Which security profile must be applied to the relevant Security policy rule to provide this protection?

A.WildFire Analysis Profile
B.Vulnerability Protection Profile
C.URL Filtering Profile
D.Antivirus Profile
AnswerB

Vulnerability Protection Profiles inspect network traffic for protocol anomalies, buffer overflows, and exploit signatures.

Why this answer

Vulnerability Protection Profiles inspect traffic for known exploits, vulnerability signatures, and attacks like SQL injection and buffer overflows.

6
MCQhard

An administrator needs to configure Prisma Access to inspect traffic from remote workers using explicit proxy mode rather than the GlobalProtect tunnel. Which component or configuration is required for explicit proxy support in Prisma Access?

A.Enable transparent proxy mode on the VM-Series trust interface using Generic Routing Encapsulation (GRE).
B.Configure explicit proxy settings in the GlobalProtect portal agent configuration, specifying the Prisma Access proxy FQDN and port.
C.Configure AWS Route 53 resolver rules to forward proxy requests to WildFire.
D.Deploy an Apache Squid proxy server inside an AWS VPC and peer it with Panorama.
AnswerB

Correct. GlobalProtect agent can be configured to operate in explicit proxy mode, forwarding web traffic directly to Prisma Access proxy nodes.

Why this answer

Prisma Access supports explicit proxy configurations, allowing mobile users to send HTTP/HTTPS requests to Prisma Access proxy nodes without establishing a full VPN tunnel.

7
Multi-Selectmedium

Which TWO pieces of information are displayed in the Cortex XDR Endpoint Management inventory table for a managed agent? (Choose two)

Select 2 answers
A.Local user printer queue statuses.
B.Current BIOS manufacturer serial number and asset tag.
C.Wi-Fi router SSID signal strength percentage.
D.Operating system type and version.
E.Installed Cortex XDR agent version number.
AnswersD, E

OS details are captured and displayed in the inventory.

Why this answer

The inventory table provides comprehensive details including IP address, operating system, agent version, and content version.

8
MCQhard

An organization is deploying an explicit Zero Trust micro-segmentation strategy using Palo Alto Networks Next-Generation Firewalls. They want to ensure that if a workstation is compromised in the engineering VLAN, lateral movement to the financial VLAN is blocked, even if both belong to internal corporate subnets. Which firewall feature must be configured to achieve this?

A.Inter-zone Security Policy rules inspecting traffic between the engineering and finance zones
B.GlobalProtect split-tunnel configuration for remote workers
C.NAT hairpinning configuration on the outside interface
D.Default inter-zone forwarding without explicit security profiles
AnswerA

Explicit security policy rules between distinct internal zones enforce micro-segmentation and block lateral movement.

Why this answer

Internal segmentation firewall (ISFW) rules combined with App-ID and User-ID inspection are required to block unauthorized lateral traffic between internal VLANs.

9
MCQhard

An enterprise is deploying Prisma Access to secure remote workers and branch offices. The security team needs to ensure that user identity from Microsoft Entra ID is correctly mapped to traffic logs without requiring users to authenticate through an explicit captive portal. Which component must be deployed?

A.Configure an explicit SAML authentication proxy on the Panorama management plane.
B.Configure an explicit proxy PAC file pointing all browser traffic to the Prisma Access Remote Networks gateway IP.
C.Install a dedicated VM-Series User-ID Agent on an EC2 instance in every public cloud VPC.
D.Deploy the Cloud Identity Engine (CIE) agent and configure directory synchronization with Microsoft Entra ID.
AnswerD

Correct. The Cloud Identity Engine securely synchronizes user and group identity data from identity providers like Microsoft Entra ID for Prisma Access policy enforcement.

Why this answer

Prisma Access integrates with User-ID via the Syslog listener, GlobalProtect agent, or Cloud Identity Engine (CIE) to map IP addresses to usernames.

10
Multi-Selecthard

An administrator is configuring Prisma Cloud Compute to protect serverless functions in AWS Lambda. Which THREE features are supported for serverless function protection? (Choose three)

Select 3 answers
A.Direct physical RAID disk array encryption management.
B.Compliance and configuration auditing of serverless function settings (such as overly permissive IAM roles or environment variables).
C.Vulnerability scanning of function code packages and dependencies.
D.Real-time BGP routing table advertisement to AWS Transit Gateway.
E.Runtime defense instrumentation to block unauthorized outbound network connections or anomalous function behavior.
AnswersB, C, E

Correct. Compute evaluates serverless configuration compliance.

Why this answer

Prisma Cloud Compute supports vulnerability scanning for serverless functions, function compliance checks, and runtime function firewalls (runtime defense).

11
MCQeasy

Which Prisma Cloud feature continuously scans cloud resource configurations to detect compliance violations against frameworks such as CIS Benchmarks, HIPAA, and PCI-DSS?

A.Prisma Cloud CSPM Compliance Dashboard
B.WildFire Compliance Analyzer
C.Prisma Access Panorama Compliance Reporter
D.GlobalProtect Compliance Agent
AnswerA

Correct. CSPM continuously assesses cloud environments against major compliance frameworks.

Why this answer

Prisma Cloud CSPM (Cloud Security Posture Management) performs continuous compliance and misconfiguration scanning.

12
MCQmedium

An administrator is reviewing WildFire submissions in the Prisma Access monitoring dashboard and notices a custom PowerShell script was classified as malware. Where can the administrator view the detailed behavioral analysis report showing registry modifications and API calls made by the sample?

A.In Prisma Cloud Compute > Defend > Access Control logs.
B.In the WildFire portal or Prisma Access Monitor > WildFire Submissions report, click on the specific sample hash to view the behavioral analysis report.
C.In the Prisma Access Cloud Identity Engine audit logs.
D.In Panorama > Managed Devices > WildFire Appliance CLI.
AnswerB

Correct. Clicking the sample hash in WildFire Submissions opens the comprehensive dynamic analysis report.

Why this answer

WildFire provides detailed behavioral threat analysis reports showing process trees, registry changes, file modifications, and network connections.

13
MCQhard

An administrator configures an external dynamic list (EDL) pointing to a URL hosting a plain-text list of malicious IP addresses. The firewall successfully downloads the EDL, but security rules referencing this EDL fail to block traffic to those IPs. Inspection reveals that the EDL entries are showing as 'parsing error' in the system logs. What is the most likely cause of this issue?

A.External dynamic lists require a valid Anti-Spyware profile attached to the security rule to parse correctly.
B.The EDL file contains domain names instead of IPv4 addresses while the EDL type is configured as IP.
C.The firewall management plane does not have an outbound route to the internet to download the file.
D.The EDL update schedule is set to 'daily' instead of 'real-time'.
AnswerB

Mismatched EDL types (e.g., configuring an IP EDL type for a file containing domains or malformed CIDR blocks) cause parsing errors.

Why this answer

EDLs have strict formatting requirements (plain text, one IP/URL per line, max limits). If the list contains invalid IP formatting, CIDR masks outside /0-/32, or HTML headers instead of pure text, the parser fails.

14
MCQhard

An administrator is investigating a security alert in Prisma Cloud where a container image in an Amazon ECR registry has a critical CVE. The engineering team wants to prevent CI/CD pipelines from building or pushing images that contain critical vulnerabilities. Which Prisma Cloud feature should be implemented?

A.Configure an AWS CloudWatch alarm to trigger a Lambda function that deletes the ECR registry repository.
B.Integrate the Prisma Cloud Compute CI/CD scanner plugin into the pipeline to block builds containing critical vulnerabilities.
C.Enable Prisma Access Threat Prevention on the CI/CD runner network interface.
D.Configure Prisma Cloud CSPM to automatically revoke AWS IAM credentials for the CI/CD builder.
AnswerB

Correct. Prisma Cloud Compute CI/CD plugins scan images during build and can block builds if vulnerabilities exceed policy thresholds.

Why this answer

Prisma Cloud Compute provides CI/CD scanner plugins (Jenkins, GitLab, GitHub Actions, etc.) that evaluate container images during the build phase and fail the build if vulnerabilities exceed a specified threshold.

15
Multi-Selecthard

An organization is building a Zero Trust Architecture and deploying Palo Alto Networks Next-Generation Firewalls to enforce micro-segmentation. Which THREE design elements are essential for a successful Zero Trust segmentation deployment? (Choose three)

Select 3 answers
A.Explicit security policy rules enforcing least privilege between internal security zones
B.Integration with User-ID to enforce identity-based access control rules
C.Reliance on port-based port-allow rules for broad internal network blocks
D.Granular App-ID policies that inspect application payloads regardless of port or protocol
E.Default allow policies across all internal zones to maximize operational efficiency
AnswersA, B, D

Explicit inter-zone security rules enforce micro-segmentation and prevent lateral movement.

Why this answer

Zero Trust segmentation requires App-ID application inspection, User-ID identity awareness, and explicit inter-zone security policies.

16
Multi-Selecthard

When mapping adversary behaviors to the MITRE ATT&CK framework within a Cortex XDR incident investigation, an analyst identifies techniques associated with the 'Credential Access' tactic. Which TWO techniques fall under the Credential Access tactic category? (Choose two)

Select 2 answers
A.Masquerading
B.Data Exfiltration Over C2 Channel
C.Brute Force
D.Automated Exfiltration
E.OS Credential Dumping
AnswersC, E

Brute forcing authentication mechanisms to acquire credentials is a standard Credential Access technique.

Why this answer

Credential Access techniques are used by adversaries to steal credentials such as account names and passwords, including OS Credential Dumping and Brute Force attacks.

17
MCQhard

An organization running Kubernetes clusters across multiple public clouds wants to enforce runtime protection that blocks unauthorized container process execution and file system writes. Which Prisma Cloud component performs this enforcement?

A.Panorama Kubernetes Plugin communicating with kubelet via SSH tunnels.
B.Prisma Cloud Compute Defender daemonset installed on each Kubernetes cluster node.
C.Prisma Cloud CSPM API scanner querying the Kubernetes control plane API server every 15 minutes.
D.Prisma Access cloud security processing node intercepting Kubernetes egress traffic.
AnswerB

Correct. The Compute Defender daemonset monitors system calls and container activity to enforce runtime rules locally.

Why this answer

Prisma Cloud Compute Defender runs as a daemonset on Kubernetes nodes to enforce runtime defense rules.

18
MCQmedium

An administrator needs to protect serverless AWS Lambda functions using Prisma Cloud Compute. Which method should be used to instrument the Lambda functions for vulnerability and compliance scanning?

A.Mount an Amazon EFS volume containing the Prisma Cloud scanner binary to the Lambda execution environment.
B.Configure AWS Inspector to forward Lambda scan results directly to the Prisma Cloud Console via an SNS topic.
C.Deploy a Prisma Cloud Compute Defender container inside the same VPC subnet as the Lambda functions.
D.Attach the Prisma Cloud Compute Lambda layer and configure the runtime wrapper to automatically scan the function upon invocation.
AnswerD

Correct. Prisma Cloud Compute provides a specialized Lambda layer that instruments the function to perform runtime vulnerability and compliance assessments.

Why this answer

Prisma Cloud Compute uses serverless defenders that are added directly to the Lambda function layer to inspect function code and dependencies.

19
Multi-Selectmedium

An administrator needs to configure Active Directory-based User-ID mapping without installing a dedicated User-ID agent on a Windows Server. Which TWO methods are natively supported by PAN-OS for agentless user mapping? (Choose two)

Select 2 answers
A.Server Monitoring via Windows Security Event Logs (WMI or WinRM).
B.Automatic SNMP trap polling of user workstations.
C.RADIUS Accounting start/stop message parsing without User-ID agents.
D.Captive Portal authentication prompts.
E.Direct LDAP querying of active user sessions via continuous TCP port scanning.
AnswersA, D

The firewall can poll domain controller Windows Security event logs directly to extract logon/logoff events.

Why this answer

PAN-OS supports agentless User-ID mapping via Windows security event log monitoring (WMI or WinRM) and Kerberos decryption/ticket log inspection.

20
MCQmedium

A security analyst is investigating an alert in Palo Alto Networks Cortex XDR where an attacker successfully dumped LSASS memory to harvest credentials. According to the MITRE ATT&CK framework, under which Tactic should this technique be cataloged?

A.Defense Evasion
B.Collection
C.Discovery
D.Credential Access
AnswerD

Dumping LSASS memory directly targets credential material, placing it under Credential Access.

Why this answer

LSASS memory dumping is classified under the Credential Access tactic (TA0006) as attackers attempt to acquire account names and passwords.

21
MCQeasy

A security analyst is investigating an unauthorized modification of user permissions in a Palo Alto Networks Prisma Access environment. When evaluating the breach under the MITRE ATT&CK framework, which specific Tactic best categorizes the attacker's actions to establish higher-level access?

A.Initial Access
B.Exfiltration
C.Privilege Escalation
D.Credential Access
AnswerC

Modifying permissions to achieve higher-level access directly maps to the Privilege Escalation tactic.

Why this answer

Privilege Escalation (TA0004) consists of techniques that adversaries use to gain higher-level permissions on a system or network, such as modifying roles or permissions.

22
MCQeasy

A security operations center (SOC) team wants to reduce alert fatigue by ensuring that low-severity threat events do not inundate their SIEM, while ensuring high-severity exploit attempts trigger immediate escalation. How should the administrator configure the security profiles to manage this?

A.Configure an Application Override policy to bypass threat inspection for all traffic
B.Disable all logging in the Security policy rules for internal zones
C.Lower the firewall management plane CPU threshold limits
D.Adjust the action settings within Vulnerability Protection and Anti-Spyware profiles based on threat severity
AnswerD

Correct. Administrators can configure custom actions per severity level within security profiles to handle alerts appropriately.

Why this answer

Security profiles allow administrators to customize the action (such as alert, drop, reset-both) taken based on threat severity or specific threat IDs.

23
MCQhard

An administrator configures a decryption exclusion based on the 'Pre-defined SSL Decryption Exclusions' list. However, an internal audit reveals that a specific sensitive medical portal is still being intercepted and decrypted. The portal uses certificate pinning and a non-standard port (TCP 8443). How can the administrator ensure this specific traffic is never decrypted?

A.Add the medical portal's URL to the File Blocking Profile under Objects.
B.Enable strict SSL Decryption fallback on the Decryption Profile.
C.Create an explicit Decryption rule at the top of the Decryption policy with action 'No Decrypt', specifying the custom port and destination server address.
D.Disable App-ID inspection on port 8443 using an Application Override policy.
AnswerC

Explicit No Decrypt rules take precedence over dynamic/pre-defined lists and can target custom service ports like TCP 8443.

Why this answer

When applications use non-standard ports or custom URLs that evade pre-defined exclusions, the administrator must create an explicit Decryption rule with action 'No Decrypt', specifying the destination address object or URL category, and ensuring service/port 8443 is matched.

24
MCQeasy

Where in the Cortex XDR management console can an administrator view the operational health, connection status, and version of all deployed agents?

A.Incident Response workbench
B.WildFire Analysis submissions portal
C.Endpoint Management view
D.Threat Intelligence Feed manager
AnswerC

Endpoint Management displays agent health, IP addresses, OS versions, content versions, and connection states.

Why this answer

The Endpoint Management view provides a centralized inventory and status list of all managed endpoints.

25
Multi-Selecteasy

An administrator is reviewing firewall high availability (HA) states and configuration parameters. Which TWO settings must be identical on both firewall peers in an HA pair to ensure successful synchronization and cluster formation? (Choose two)

Select 2 answers
A.Management IP addresses of the individual firewall control planes
B.Hostname configured in the device management settings
C.PAN-OS software version
D.Hardware model (e.g., PA-3220 paired with PA-3220)
E.DNS server IP addresses configured in device setup
AnswersC, D

Correct. Both peers must run the exact same PAN-OS software version.

Why this answer

HA peers must share identical hardware models, software versions, and license configurations to function properly.

26
MCQmedium

An enterprise wants to mitigate the risk of credential theft attacks where users type their corporate credentials into known phishing websites. Which Palo Alto Networks feature provides real-time protection against corporate credential phishing?

A.Data Filtering profile configured for credit card pattern matching
B.URL Filtering profile configured with Credential Theft Prevention settings
C.Vulnerability Protection profile with HTTP header inspection
D.Anti-Spyware profile configured with DNS sinkholing
AnswerB

Correct. URL filtering profiles can detect and block or alert when users submit corporate credentials to phishing sites.

Why this answer

URL Filtering profiles include Credential Theft Prevention features that inspect HTTP submissions against corporate credential settings.

27
MCQeasy

A security analyst is provisioning a new User-ID agent to map IP addresses to usernames in a Windows Active Directory domain. To adhere to least-privilege principles, what level of access should be granted to the service account used by the User-ID agent?

A.Local Administrator on all domain controllers
B.Read-only access to Active Directory security logs and event viewer access
C.Domain Administrator privileges
D.Schema Administrator privileges
AnswerB

Reading security event logs is all that is required for IP-to-user mapping, adhering to least privilege.

Why this answer

The User-ID agent service account requires read-only permissions to query Active Directory security logs and the security event log, avoiding administrative privileges.

28
MCQmedium

A security architect is designing a Zero Trust network segmentation model using Palo Alto Networks Next-Generation Firewalls. To prevent lateral movement of malware across internal VLANs, which operational rule must be strictly enforced?

A.Trust all traffic originating from authenticated internal subnets by default
B.Permit all communication between endpoints sharing the same Active Directory domain
C.Inspect and restrict all east-west internal traffic based on least-privilege application context
D.Rely solely on perimeter firewalls to block inbound threats from the internet
AnswerC

Zero Trust dictates that all internal (east-west) traffic must be inspected and authorized based on context.

Why this answer

Zero Trust requires micro-segmentation and inspecting all traffic—including east-west traffic between internal segments—based on explicit application and user context.

29
MCQhard

During an incident response investigation, a security analyst identifies a novel malware sample that evaded traditional signature-based detection. The security team needs to ensure that the firewall automatically blocks this exact malware variant globally across all deployed Next-Generation Firewalls within minutes without manual signature updates. Which platform component provides this capability?

A.WildFire cloud-based analysis and automated signature generation
B.Palo Alto Networks MineMeld open-source threat intelligence
C.Traps Advanced Endpoint Protection cloud service
D.AutoFocus Context-Aware Threat Intelligence service
AnswerA

Correct. WildFire analyzes unknown files, determines if they are malicious, and distributes automated signatures globally within minutes.

Why this answer

WildFire provides cloud-based automated analysis of unknown files and generates global protections within minutes without waiting for manual signature releases.

30
MCQmedium

An organization is implementing a Zero Trust Architecture on their Palo Alto Networks Next-Generation Firewall. They want to ensure that access to internal financial databases is granted based on explicit verification of user identity, device health, and application context, rather than implicit trust based on network location. Which core principle of Zero Trust is being applied?

A.Perimeter-based defense centralization
B.Never trust, always verify through continuous context
C.Implicit trust verification via subnet placement
D.Static role-based implicit authorization
AnswerB

The core principle of Zero Trust is 'never trust, always verify', evaluating context such as user identity and device health.

Why this answer

Zero Trust mandates that access be granted based on continuous verification of context, identity, and posture, completely eliminating implicit trust zones.

31
MCQhard

An administrator configures a dynamic address group (DAG) based on User-ID tags, but security rules referencing this DAG fail to match traffic from users who have successfully authenticated via GlobalProtect. What is the most likely root cause?

A.The User-ID agent or GlobalProtect portal has not been configured to register the user's IP address with the specific tag name used in the DAG filter.
B.Security policy rules cannot reference DAGs unless a Decryption profile is explicitly attached.
C.The XML API key lacks administrative privileges to register IP-to-tag mappings on the management plane.
D.The address object must be converted to a static IP subnet because DAGs do not support User-ID tags.
AnswerA

If tags are not explicitly registered and associated with the user IPs, the dynamic address group evaluates to empty.

Why this answer

Dynamic address groups rely on User-ID or VM-Info tags being correctly registered. If the firewall lacks the XML API permissions or the User-ID agent is not configured to register tags for that source, the dynamic address group remains empty.

32
Multi-Selectmedium

Which TWO metrics or features are provided by Prisma Autonomous DEM (ADEM) to troubleshoot remote user application performance issues? (Choose two)

Select 2 answers
A.Automated quarantine of infected container workloads in public cloud Kubernetes clusters.
B.Direct decryption and viewing of private banking user passwords traversing HTTPS sessions.
C.Synthetic test monitoring that periodically simulates user interactions and application access from remote locations.
D.Automated firmware flashing for branch office switch hardware.
E.Real-user monitoring capturing endpoint device metrics (CPU utilization, Wi-Fi signal strength, and network path latency).
AnswersC, E

Correct. Synthetic tests proactively measure app availability and performance.

Why this answer

ADEM provides synthetic testing (scripted user actions) and real-user monitoring (capturing device metrics, Wi-Fi, CPU, and network path latency).

33
MCQmedium

A network administrator is troubleshooting why an internal application is unable to communicate with an external API over a non-standard TCP port. The firewall's security policy allows the IP addresses and port, but traffic is being dropped by threat prevention. Upon checking logs, the administrator sees a threat ID associated with a vulnerability signature. What is the most appropriate way to resolve a false positive safely?

A.Disable the Vulnerability Protection profile globally across all security rules
B.Create a Vulnerability Protection Exception for the specific threat ID, optionally restricting it to the source or destination IP
C.Configure an Application Override policy for the custom API port
D.Delete the threat signature from the firewall's local database cache
AnswerB

Correct. Exceptions allow administrators to whitelist specific signatures without disabling the entire profile.

Why this answer

False positives in vulnerability protection can be resolved by creating a Vulnerability Protection Exception for the specific signature ID.

34
MCQhard

An organization deploys Cortex XDR disk encryption management. An endpoint fails to escrow its BitLocker recovery key to the Cortex XDR console. What is the most effective troubleshooting step to verify escrow status using the agent command-line tool?

A.Run 'cytool encryption status' to check BitLocker integration and key escrow status.
B.Run 'manage-bde -status' from an elevated command prompt.
C.Review the Windows Application event log for BitLocker Group Policy errors.
D.Run 'cytool set-token' to re-register the encryption keys.
AnswerA

'cytool encryption status' displays detailed disk encryption states and escrow confirmation.

Why this answer

The cytool command-line interface provides specific commands to query disk encryption and key escrow status.

35
MCQeasy

A security administrator is reviewing security policy rules and notices that many rules use 'any' for the application field. According to security best practices and the attack lifecycle, why is allowing 'any' application dangerous?

A.It prevents the firewall from performing Layer 3 IP address routing
B.It disables the generation of threat logs for all established sessions
C.It allows unauthorized applications to traverse standard ports like 80 and 443, expanding the attack surface
D.It automatically enables SSL decryption on all matching traffic flows
AnswerC

Correct. 'any' permits blind acceptance of applications, increasing risk and violating least-privilege principles.

Why this answer

Allowing 'any' application permits unknown or unwanted applications to traverse ports like 80 and 443, bypassing traditional port-based security controls.

36
MCQhard

An enterprise security team discovers that a custom line-of-business application is triggering a Behavioral Threat Protection (BTP) alert in Cortex XDR. The behavior involves unusual process injection techniques that are legitimate for this application. How can the administrator suppress this specific alert without disabling BTP for other applications?

A.Lower the threat severity threshold for Behavioral Threat Protection in the agent profile.
B.Set the Cortex XDR Agent to troubleshooting mode for the affected subnet.
C.Add the application directory to the system-wide exclusion list in the Malware Profile.
D.Create a Behavioral Threat Protection exception specifying the application hash and the triggered rule ID.
AnswerD

BTP exceptions can be precisely scoped using file hashes and specific rule identifiers.

Why this answer

Creating an exception based on the BIOC rule ID or signature hash prevents specific false positives while keeping behavioral monitoring active.

37
Multi-Selecthard

Which TWO methods can be utilized to distribute Cortex XDR agent installation packages across an enterprise Windows environment? (Choose two)

Select 2 answers
A.Direct user self-service installation via public app store downloads.
B.Broadcasting the installer binary unencrypted over local subnet broadcast domains.
C.Active Directory Group Policy Object (GPO) software installation.
D.Embedding the installer inside incoming corporate email attachments for users to execute.
E.Centralized software deployment tools such as Microsoft Endpoint Configuration Manager (SCCM) or Microsoft Intune.
AnswersC, E

GPO is a standard mechanism for deploying MSI packages across domain-joined machines.

Why this answer

Enterprise deployment typically relies on Active Directory GPO or centralized software deployment tools like SCCM/Intune.

38
MCQeasy

A security analyst needs to verify whether a suspicious file hash observed in an external threat report has ever traversed the corporate network or been analyzed by WildFire. Which tool provides the fastest way to search historical WildFire sample analysis results across the entire enterprise?

A.Application Command Center (ACC) network activity tab
B.WildFire Portal or firewall WildFire submission logs searched by file hash (SHA-256)
C.GlobalProtect client log exporter utility
D.Zone Protection event log viewer
AnswerB

Correct. Searching by SHA-256 hash in the WildFire portal or firewall logs reveals historical analysis results.

Why this answer

The WildFire portal or Panorama/Firewall WildFire submission logs allow searching by file hash.

39
MCQmedium

During a threat hunting exercise on a Palo Alto Networks firewall, an analyst identifies an adversary scanning internal subnets to map out open ports and active hosts prior to launching an exploit. According to MITRE ATT&CK, which Tactic describes this phase?

A.Discovery
B.Lateral Movement
C.Defense Evasion
D.Initial Access
AnswerA

Scanning internal networks and probing for open ports falls directly under the Discovery tactic.

Why this answer

Discovery (TA0007) consists of techniques an adversary may use to gain knowledge about the internal network, system settings, and connected infrastructure.

40
MCQeasy

An administrator needs to temporarily disable the Cortex XDR agent on an endpoint for troubleshooting purposes. What mechanism is used to authorize this action locally using the command line?

A.An Anti-Tamper password generated from the Cortex XDR management console.
B.A local administrator password configured during OS installation.
C.A registry override key set by group policy.
D.A network firewall bypass token.
AnswerA

Anti-tamper protection prevents unauthorized stopping of the agent and requires a console-generated password.

Why this answer

Disabling the agent locally requires an anti-tamper password generated from the Cortex XDR management console.

41
MCQmedium

A security team is designing a defense-in-depth strategy for lateral movement prevention inside the data center. They decide to deploy internal segmentation firewalls (ISFW). Which core Palo Alto Networks capability enables these firewalls to enforce precise access control between different application tiers inside the same network zone?

A.NAT policy source translation mapping
B.Static routing table optimization
C.App-ID based security policies
D.Zone Protection profiles against SYN floods
AnswerC

Correct. App-ID identifies applications independent of ports, enabling granular micro-segmentation policies.

Why this answer

App-ID identifies applications regardless of ports, allowing administrators to restrict traffic between internal tiers (e.g., web to database) down to the specific application command.

42
Multi-Selectmedium

An administrator wants to configure User-ID mapping sources on a Palo Alto Networks Next-Generation Firewall to identify users behind IP addresses. Which TWO of the following are valid methods supported by PAN-OS for gathering User-ID mappings? (Choose two)

Select 2 answers
A.ICMP Ping sweeps of internal subnet scopes
B.BGP routing table advertisements
C.User-ID Agent mapping and Windows Security Event Log polling
D.Direct DNS Zone Transfer requests initiated by the firewall data plane
E.GlobalProtect client connection logs and captive portal authentication
AnswersC, E

Polling Windows security logs and using User-ID agents are native mapping methods.

Why this answer

PAN-OS supports User-ID agent mapping, captive portal, Exchange monitoring, Syslog listening, and GlobalProtect as mapping sources.

43
Multi-Selecthard

An administrator is troubleshooting a high availability (HA1) heartbeat failure between two firewall peers. Which THREE configuration or physical items should be checked? (Choose three)

Select 3 answers
A.Verify physical connectivity of the HA1 fiber or Ethernet cables between both firewall peers.
B.Verify that the Panorama management server is online and syncing policies.
C.Ensure the HA1 backup IP addresses are configured correctly and reside on a reachable subnet.
D.Check intermediate switch configurations to ensure HA control ports are not blocked by ACLs or storm control.
E.Check that GlobalProtect portals are licensed and operational on both peers.
AnswersA, C, D

Physical layer verification is the primary troubleshooting step for broken heartbeat links.

Why this answer

HA1 issues are typically caused by physical cable disconnection, IP address conflicts on the HA1 subnet, or firewall/switch port filtering of HA control traffic (UDP/TCP ports used by HA).

44
MCQeasy

An administrator wants to configure authentication for firewall administrators using RADIUS. Where in the Panorama Web Interface should the administrator configure the RADIUS server profile?

A.Objects > Addresses
B.Device > Server Profiles > RADIUS
C.Policies > Security
D.Network > GlobalProtect > Portals
AnswerB

External authentication server profiles are configured under Device > Server Profiles in the firewall interface.

Why this answer

Server profiles such as RADIUS, TACACS+, LDAP, and SAML are configured under Device > Server Profiles (or Panorama > Server Profiles) in Palo Alto Networks products.

45
MCQhard

During a simulated phishing exercise, an employee clicks a link in an email that directs them to a credential-harvesting page mimicking the corporate single sign-on portal. According to the common attack lifecycle, which phase immediately follows this successful credential capture?

A.Use of valid accounts for initial access or lateral movement
B.Exploitation of client-side software vulnerabilities
C.Passive network sniffing to harvest additional certificates
D.Immediate domain controller encryption via ransomware
AnswerA

Stolen credentials are subsequently used for initial access or lateral movement within the environment.

Why this answer

After obtaining valid user credentials through phishing, the adversary enters the credential access phase and typically moves to lateral movement or initial access using those compromised credentials.

46
MCQmedium

An incident responder notices that a threat actor used living-off-the-land binaries (like PowerShell and Certutil) to download malicious payloads onto endpoints monitored by Cortex XDR. Under the MITRE ATT&CK framework, which Tactic encompasses these execution methods?

A.Resource Development
B.Execution
C.Exfiltration
D.Reconnaissance
AnswerB

Using scripting tools and command-line utilities to run payloads falls directly under the Execution tactic.

Why this answer

Execution (TA0002) consists of techniques that result in running adversary-controlled code on a local system, such as leveraging scripting languages and utilities.

47
MCQeasy

A security administrator is reviewing firewall logs and notices multiple outbound connection attempts from a client workstation to known command and control IP addresses. Which security profile component is primarily responsible for generating a threat log entry for this specific outbound traffic?

A.URL Filtering profile configured to block malicious categories
B.Anti-Spyware profile configured with DNS Signatures and Spyware signatures
C.Vulnerability Protection profile configured to block buffer overflows
D.WildFire analysis profile configured for forward unkown file actions
AnswerB

Correct. Anti-Spyware profiles inspect outbound traffic for C2 communication and generate threat logs.

Why this answer

An Anti-Spyware profile detects and blocks command-and-control (C2) traffic when infected hosts attempt to communicate with external malicious servers, generating a threat log.

48
Multi-Selectmedium

An incident responder is investigating a ransomware outbreak on an internal file server. During the analysis, the responder needs to categorize the attack steps using the cyber kill chain framework. Which THREE phases are part of the standard Lockheed Martin cyber kill chain? (Choose three)

Select 3 answers
A.Mitigation
B.Actions on Objectives
C.Weaponization
D.Continuous Patching
E.Delivery
AnswersB, C, E

Actions on Objectives is the final phase where the attacker accomplishes their primary mission, such as data encryption or exfiltration.

Why this answer

The cyber kill chain includes Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives.

49
Multi-Selectmedium

An organization is reviewing its threat intelligence feeds and security posture to prepare for advanced persistent threat (APT) campaigns. Which TWO characteristics are typically associated with advanced persistent threats? (Choose two)

Select 2 answers
A.High visibility and aggressive network scanning to maximize immediate impact
B.Exclusive reliance on unencrypted HTTP protocols for command and control
C.Automated, indiscriminate ransomware distribution targeting consumer endpoints
D.Prolonged, stealthy presence within the compromised network over an extended period
E.Targeted objectives focusing on specific intellectual property or espionage
AnswersD, E

Persistence and stealth over long durations are core defining traits of APT campaigns.

Why this answer

APTs are characterized by prolonged, stealthy campaigns targeting specific organizations for intelligence gathering or espionage, requiring sustained, low-profile access rather than noisy, quick disruptions.

50
Multi-Selecthard

An organization wants to secure a Kubernetes cluster using Prisma Cloud Compute. Which THREE capabilities can the Prisma Cloud Compute Defender provide for the cluster? (Choose three)

Select 3 answers
A.Runtime defense monitoring of container system calls to block unauthorized process execution and file modifications.
B.Vulnerability scanning of container images in registries and during CI/CD build pipelines.
C.BGP dynamic routing session establishment with external Azure ExpressRoute circuits.
D.Automatic remediation of AWS IAM user policy attachments via automated CLI execution.
E.Compliance and configuration auditing of Kubernetes cluster nodes and namespace configurations.
AnswersA, B, E

Correct. Compute Defender monitors container system calls in real-time.

Why this answer

Prisma Cloud Compute Defender provides vulnerability scanning for images, runtime protection for containers, and compliance auditing for Kubernetes manifests and nodes.

51
MCQmedium

An administrator needs to run a live forensic artifact collection on a suspected compromised endpoint using Cortex XDR. Which capability allows the administrator to execute scripts and retrieve files directly from the endpoint in real time?

A.Host Insights Response Actions
B.Agent Profile Distribution task
C.BIOC automated remediation playbooks
D.Cortex XDR Remote Response tool
AnswerD

Remote Response enables administrators to run scripts, collect triage files, and investigate endpoints interactively.

Why this answer

Remote Response is the Cortex XDR feature that provides a secure interactive shell and script execution capability on managed endpoints.

52
MCQhard

An organization implementing a Zero Trust Architecture wants to ensure that administrators accessing Panorama use hardware-backed cryptographic tokens (such as FIDO2 / WebAuthn keys) rather than software-based OTPs. Which authentication method integration should the administrator configure in Panorama?

A.TACACS+ single-connection mode with static PINs
B.Local database with plaintext password hashing
C.RADIUS PAP protocol without secondary token prompts
D.SAML 2.0 authentication profile pointing to an IdP supporting FIDO2 / WebAuthn
AnswerD

SAML 2.0 allows integration with advanced identity providers supporting hardware-backed FIDO2/WebAuthn credentials.

Why this answer

SAML authentication allows integration with enterprise IdPs (like Azure AD or Okta) that support modern FIDO2 and hardware-backed MFA tokens.

53
MCQeasy

An administrator needs to configure a Palo Alto Networks firewall interface to connect to an untrusted ISP router. Which interface type is appropriate for this connection?

A.Tap interface assigned to an Internal zone
B.Virtual Wire interface assigned to a DMZ zone
C.Layer 3 interface assigned to an Untrust security zone
D.HA1 interface assigned to the Management zone
AnswerC

Layer 3 interfaces process IP packets and participate in routing, making them standard for ISP connections.

Why this answer

Interfaces connected to external untrusted networks (like ISPs) are configured as Layer 3 interfaces and assigned to an Untrust security zone.

54
Multi-Selectmedium

Which THREE diagnostic or troubleshooting steps can be performed using the 'cytool' command-line utility on a local endpoint? (Choose three)

Select 3 answers
A.Generating support logs and diagnostic dumps ('cytool support dump').
B.Checking protection module states ('cytool protection query').
C.Configuring enterprise LDAP domain controller replication schedules.
D.Querying overall agent status and operational health ('cytool query status').
E.Modifying global firewall NAT routing tables on the core switch.
AnswersA, B, D

Support dumps are generated via cytool for troubleshooting.

Why this answer

Cytool supports querying agent status, checking protection module states, and dumping support logs.

55
Multi-Selecthard

An enterprise is preparing for an external security audit and needs to ensure compliance with risk management frameworks regarding administrative accountability and change control. Which THREE features on a Palo Alto Networks firewall support these compliance requirements? (Choose three)

Select 3 answers
A.Automated daily factory reset scripts executed on the management plane
B.Disabling all logging to prevent unauthorized access to log databases
C.Administrator activity and authentication logs recording login timestamps and source IPs
D.Role-Based Access Control (RBAC) restricting administrative privileges to necessary tasks only
E.Configuration Audit logs tracking every administrative commit, change, and user responsible
AnswersC, D, E

Correct. Admin logs track login events and management plane access.

Why this answer

Administrative accountability is maintained via Configuration Audit logs, Administrator Activity logs, and external authentication/RBAC.

56
MCQmedium

An organization is implementing compliance controls to ensure that employees do not upload proprietary source code to unauthorized cloud storage providers. Which security profile feature should be utilized to control and log specific file transfers within recognized cloud applications?

A.Data Filtering profile configured with URL category exceptions
B.WildFire analysis profile configured for static code review
C.File Blocking profile configured to block specific application file types
D.URL Filtering profile configured with Custom URL categories
AnswerC

Correct. File Blocking profiles inspect traffic for specific file types and can block or log uploads within cloud applications.

Why this answer

File Blocking profiles can be configured to block or log the upload or download of specific file types (such as source code archives or executables) within applications.

57
MCQhard

An administrator is configuring disk encryption management in Cortex XDR for macOS endpoints. Which underlying native macOS technology does Cortex XDR manage and report on for disk encryption?

A.Apple Disk Utility RAID encryption
B.FileVault
C.DM-Crypt / LUKS
D.BitLocker to Go
AnswerB

Cortex XDR manages and enforces Apple FileVault encryption and escrows recovery keys.

Why this answer

FileVault is the native macOS disk encryption technology managed and monitored by Cortex XDR.

58
MCQhard

An organization requires compliance reporting showing that all endpoints are actively protected by Cortex XDR modules (Anti-Malware, Exploit Prevention, Behavioral Threat Protection). Where can an administrator generate this comprehensive compliance report in the Cortex XDR management console?

A.Navigate to Cortex XDR Dashboards and Reports > Report Builder / Compliance views.
B.Run 'cytool report generate' on each endpoint locally.
C.Check the Windows Security Center dashboard on individual machines.
D.Export the raw endpoint inventory to CSV and correlate with firewall logs.
AnswerA

The reporting engine in Cortex XDR includes pre-built templates and custom report builders for agent module status.

Why this answer

Reporting and dashboard views provide status summaries and compliance reporting for agent protection modules.

59
MCQeasy

A security analyst is configuring administrative access on a Cortex XDR platform to ensure that users only have permissions necessary to perform their specific job functions. Which core principle is the analyst implementing?

A.Role-Based Access Control expansion
B.Zero Trust Architecture
C.Least-privilege principles
D.Federated Identity Management
AnswerC

Limiting permissions strictly to what is needed for job functions is the definition of least privilege.

Why this answer

Least-privilege principles dictate that users and accounts are granted only the minimum necessary access required to complete their designated tasks.

60
Multi-Selecthard

Which THREE actions are recommended best practices when securing the management plane of a Palo Alto Networks firewall? (Choose three)

Select 3 answers
A.Disable administrative services like HTTP and Telnet, utilizing HTTPS and SSH instead.
B.Restrict administrative access to the management interface using a dedicated Management Profile with allowed source IP addresses.
C.Assign all administrative users the 'superuser' role to simplify troubleshooting.
D.Configure a dedicated out-of-band management network separated from data traffic.
E.Enable SSHv1 and SSLv2 to ensure legacy administrative tool compatibility.
AnswersA, B, D

Correct. Disabling unencrypted protocols prevents cleartext credential interception.

Why this answer

Management plane security best practices include restricting access via IP, using dedicated management interfaces, and disabling unnecessary services.

61
MCQhard

A security architect is designing a Zero Trust network where users must authenticate before accessing any internal application. However, legacy internal applications do not support modern identity federation protocols. Which Palo Alto Networks feature can be deployed to front-end these legacy applications and enforce authentication and access control without modifying the legacy applications?

A.GlobalProtect clientless VPN acting as a reverse proxy with SAML authentication
B.Zone Protection SYN proxy configuration
C.WildFire cloud analysis submission API
D.App-ID custom application signature generator
AnswerA

Correct. Clientless VPN provides secure access to internal web applications with SAML authentication without requiring client software or app modifications.

Why this answer

GlobalProtect service provider / SAML integration or Prisma Access proxy capabilities allow authentication enforcement before traffic reaches protected backend resources.

62
MCQhard

An organization is updating its enterprise risk management framework to align with NIST SP 800-30 guidelines. The security team needs to prioritize mitigation efforts for a newly discovered vulnerability in a critical database. Which combination of factors must the team evaluate to determine the overall risk level?

A.Network bandwidth consumption and CPU utilization overhead
B.Patch availability time and vendor support lifecycle status
C.Asset replacement cost and regulatory fine amounts
D.Threat likelihood and impact magnitude
AnswerD

Risk is fundamentally calculated by assessing the likelihood of a threat exploiting a vulnerability and the resulting impact.

Why this answer

NIST SP 800-30 defines risk as a function of the likelihood of a given threat source exercising a particular potential vulnerability and the resulting impact of that adverse event.

63
MCQeasy

An administrator is integrating Okta with Palo Alto Networks Prisma Cloud using SAML 2.0 to handle administrative logins. Which component of Identity and Access Management (IAM) is primarily responsible for validating the user's credentials?

A.Authorization
B.Auditing
C.Accounting
D.Authentication
AnswerD

Authentication is the verification of identity before granting access to a system.

Why this answer

Authentication is the process of verifying who a user is (e.g., via credentials in Okta), whereas authorization determines what they can access.

64
MCQeasy

Which Palo Alto Networks product provides Cloud Infrastructure Entitlement Management (CIEM) to discover, analyze, and remediate excessive permissions and identities across multi-cloud environments?

A.Prisma Access Identity Service
B.GlobalProtect Entitlement Manager
C.Prisma Cloud IAM Security (CIEM)
D.WildFire Entitlement Scanner
AnswerC

Correct. Prisma Cloud IAM Security discovers entitlements and enforces least privilege across multi-cloud IAM.

Why this answer

Prisma Cloud provides CIEM capabilities to manage identities and permissions across multi-cloud environments.

65
MCQeasy

A SOC manager wants to restrict administrator access so that network engineers can modify firewall security policies, but cannot modify system-level settings or firewall high-availability (HA) parameters. Where should the manager configure this restriction in Panorama?

A.Objects > Custom Objects > URL Category
B.Panorama > Admin Roles
C.Network > Interfaces > VLAN
D.Device > Setup > Management
AnswerB

Panorama Admin Roles allow administrators to define precise feature-level permissions and access scopes.

Why this answer

Admin Role Profiles in Panorama allow granular control over feature access, specifying exactly which tabs and actions an administrator can view or modify.

66
MCQhard

An enterprise environment experiences a sophisticated zero-day attack where a custom malware binary is downloaded via HTTPS. Decryption is enabled on the firewall. For WildFire to successfully analyze this file, which specific configuration requirement must be met within the Security policy and WildFire analysis profile?

A.The decryption policy must exempt WildFire inspection traffic to prevent performance degradation on the data plane
B.A custom URL Filtering profile must be applied to decrypt traffic matching the unknown-file category
C.The Security rule must utilize an application override to bypass App-ID processing for encrypted file transfers
D.SSL Decryption must be active, and the security rule must have a WildFire Analysis profile set to forward the specific file type to the WildFire cloud
AnswerD

Correct. Encrypted traffic must be decrypted for WildFire to inspect the payload, and the WildFire profile must be configured to forward that file format.

Why this answer

WildFire requires explicit inspection of SSL/TLS decrypted traffic and an appropriate WildFire Analysis profile attached to the security rule allowing the file type to be forwarded.

67
MCQeasy

An administrator wants to configure the frequency at which the Cortex XDR agent checks in with the management server. Where is this heartbeat interval configured?

A.Directly within the local Windows registry on each endpoint.
B.In the Agent Settings profile under Communication parameters.
C.In the Malware Prevention profile settings.
D.In the Global Protect Gateway configuration.
AnswerB

Communication intervals and polling frequencies are defined in the Agent Settings profile.

Why this answer

Agent communication settings, including heartbeat intervals, are managed within the Agent Settings profile.

68
Multi-Selectmedium

A security administrator is configuring User-ID to enforce identity-based security policies. Which TWO methods can the Palo Alto Networks firewall use to map IP addresses to usernames in an enterprise environment? (Choose two)

Select 2 answers
A.Configuring App-ID custom signature regex patterns
B.Configuring static IPv4-to-IPv6 NAT translation tables
C.Using Captive Portal authentication to prompt unmapped users for credentials
D.Mapping IP addresses via Windows User-ID Agent reading Active Directory security event logs
E.Enabling GlobalProtect clientless portal DNS proxy forwarding
AnswersC, D

Correct. Captive portal prompts users for authentication when an IP address is unmapped, establishing the User-ID mapping.

Why this answer

User-ID can map IP addresses to usernames using integration with Active Directory security event logs (Windows User-ID Agent / WMI) and captive portal authentication.

69
MCQhard

An attacker performs a reconnaissance scan against an enterprise perimeter using TCP SYN packets with randomized source ports and IP addresses to map active hosts. Which Palo Alto Networks feature is specifically designed to mitigate this type of volumetric reconnaissance and connection exhaustion attack at the ingress interface?

A.Zone Protection profile configured with SYN Flood protection (SYN cookies or random drop)
B.WildFire inline machine learning analysis engine
C.User-ID syslog mapping listener service
D.URL Filtering profile configured with credential theft prevention
AnswerA

Correct. Zone Protection profiles protect against SYN floods and reconnaissance scans at the zone ingress.

Why this answer

Zone Protection profiles include defenses against TCP SYN floods, port scans, and other layer 3/4 network attacks.

70
MCQmedium

An endpoint has been flagged in Cortex XDR with multiple high-severity alerts. The security operations team decides to isolate the endpoint immediately to prevent lateral movement. Which network traffic remains permitted by default when an endpoint is placed in isolation mode in Cortex XDR?

A.All network protocols without restriction.
B.Communication with the Cortex XDR server and essential DNS/DHCP services.
C.SMB and RDP traffic to internal domain controllers.
D.All outbound traffic to external internet websites via HTTPS.
AnswerB

Isolation blocks lateral movement but preserves management connectivity so administrators can still issue commands and collect forensics.

Why this answer

When an endpoint is isolated, network access is blocked except for communication with the Cortex XDR management server and specified DNS/DHCP services.

71
MCQeasy

An administrator is reviewing endpoint security profiles and notices the term 'BIOC'. What does BIOC stand for in the context of Cortex XDR?

A.Blocked Internal Operating Component
B.Basic Intelligent Output Control
C.Binary Indicator of Code
D.Behavioral Indicator of Compromise
AnswerD

BIOC rules detect suspicious sequences of events indicative of attacks.

Why this answer

BIOC stands for Behavioral Indicator of Compromise, representing rules that detect suspicious behaviors.

72
MCQmedium

A security analyst wants to configure a custom alert rule in Cortex XDR that triggers whenever a specific command-line pattern is observed across multiple endpoints. Which feature should the analyst use to create this behavioral alert?

A.WildFire Signature Generator
B.Custom BIOC (Behavioral Indicator of Compromise) rules
C.Agent Profile Exploit Exception builder
D.Host Insights Scheduled Query task
AnswerB

Custom BIOC rules enable security teams to write tailored detection logic for specific process executions and command lines.

Why this answer

BIOC (Behavioral Indicator of Compromise) rules allow administrators to define custom detection criteria based on process behaviors and command lines.

73
MCQhard

An administrator notices that an internal client is infected with malware that is attempting to exfiltrate data over HTTPS using a custom encrypted protocol that evades standard signatures. The administrator wants to configure WildFire inline machine learning to block this zero-day threat in real-time. Which feature must be enabled and configured?

A.Enable SSL Decryption with a custom Decryption Forward Trust certificate.
B.Set the Anti-Spyware profile action to 'Reset Both' for all severity levels.
C.Enable Inline Machine Learning in the WildFire Analysis Profile attached to the Security policy rule.
D.Configure a custom Application Override rule for the encrypted stream.
AnswerC

Inline machine learning evaluates files and sessions in real-time before the complete payload is downloaded or exfiltrated.

Why this answer

WildFire inline machine learning provides real-time detection of zero-day threats during the initial session handshake. This requires a WildFire Analysis Profile with inline ML enabled, attached to the Security policy rule.

74
Multi-Selectmedium

Which TWO actions can an administrator perform within the Prisma Cloud Cloud Security Posture Management (CSPM) console to remediate misconfigured cloud resources? (Choose two)

Select 2 answers
A.Execute automated single-click or automated API-driven remediation scripts for supported resource misconfigurations.
B.View step-by-step manual remediation instructions and generated CLI commands for correcting the resource configuration.
C.Modify the PAN-OS dataplane packet buffer allocation settings on remote VM-Series firewalls.
D.Reboot physical branch routers connected to Prisma Access remote networks.
E.Directly patch the Linux kernel version running inside an AWS EC2 instance via SSH terminal emulation.
AnswersA, B

Correct. CSPM supports auto-remediation for many common cloud misconfigurations via cloud provider APIs.

Why this answer

Prisma Cloud CSPM allows administrators to view remediation CLI scripts, execute automated API remediation, or integrate with ticketing/SOAR tools.

75
MCQeasy

An administrator wants to prevent users from accessing specific URL categories such as 'gambling' and 'adult' while allowing all other business-related sites. Where should this restriction be configured?

A.Zone Protection Profile applied to the external zone
B.Data Filtering Profile attached to the NAT policy
C.URL Filtering Profile attached to the relevant Security policy rule
D.Authentication Profile configured under Device > Setup
AnswerC

URL Filtering Profiles define actions (allow, block, alert, continue) for specific URL categories.

Why this answer

URL Filtering Profiles allow administrators to categorize and block/allow specific web categories, and are attached to Security policy rules.

Page 1 of 3

Page 2

All pages

Practice Cybersecurity-Practitioner by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →