Courseiva

Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) (Cybersecurity-Practitioner) — Questions 76150

206 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
Multi-Selecthard

Which THREE conditions or indicators typically trigger an automated endpoint isolation action in Cortex XDR? (Choose three)

Select 3 answers
A.Critical Behavioral Indicator of Compromise (BIOC) match indicating active data exfiltration.
B.High-confidence Command and Control (C2) communication detected by behavioral analysis.
C.A standard software update failing to install via Windows Update.
D.Confirmed ransomware execution encrypting local files.
E.A user attempting to access an unauthorized social media website during lunch.
AnswersA, B, D

Severe BIOC alerts often trigger automated playbooks including isolation.

Why this answer

Endpoint isolation is triggered by high-severity threats such as confirmed ransomware, critical C2 beaconing, or severe BIOC violations.

77
Multi-Selectmedium

A security analyst is investigating a suspected lateral movement attempt within an enterprise network protected by Palo Alto Networks firewalls. According to the MITRE ATT&CK framework, which TWO of the following techniques are commonly categorized under the Lateral Movement tactic? (Choose two)

Select 2 answers
A.Remote Services (e.g., SMB/Windows Admin Shares, RDP)
B.Phishing via Spearphishing Link
C.Automated Exfiltration Over C2 Channel
D.Exploitation of Remote Services
E.Steal Web Session Cookie
AnswersA, D

Using SMB and RDP to connect to remote systems within the internal network is a core Lateral Movement technique.

Why this answer

Remote Services (T1021) and Exploitation of Remote Services (T1210) are classic techniques used by adversaries to move laterally through an environment.

78
MCQeasy

When configuring Prisma Access to inspect traffic between different branch offices (Branch-to-Branch traffic), where is the inspection typically performed?

A.Inside the Prisma Access Cloud Security Processing Node (SPN) cloud infrastructure.
B.Inside the customer-managed AWS Transit Gateway associated with the remote network.
C.On the Panorama management server located in the customer's primary datacenter.
D.On the local physical firewall at the originating branch office before it leaves the LAN.
AnswerA

Correct. Prisma Access routes branch-to-branch traffic through the nearest Cloud Security Processing Node (SPN) for full security inspection.

Why this answer

Prisma Access inspects branch-to-branch traffic within the cloud security processing nodes (SPNs) managed by Palo Alto Networks.

79
MCQhard

During an investigation of a compromised endpoint, an analyst needs to trace all network connections initiated by that specific host over the past 30 days, including the applications used, bytes transferred, and threat logs generated. Which Palo Alto Networks logging and visualization tool provides a consolidated session explorer view for this forensic analysis?

A.Dynamic Address Group membership audit report
B.AutoFocus Campaign Tracker and malware family indicator list
C.GlobalProtect Clientless Portal connection history report
D.Panorama Log Viewer / Firewall Traffic and Threat logs filtered by source IP address
AnswerD

Correct. Filtering traffic and threat logs by source IP provides a complete history of sessions, applications, and security events.

Why this answer

Traffic logs combined with ACC (Application Command Center) or Panorama log queries allow detailed session-level forensic investigation per IP address.

80
Multi-Selecthard

An enterprise security team is reviewing its Zero Trust Architecture deployment to ensure compliance with modern identity and access management standards. Which TWO practices are fundamental requirements of a true Zero Trust identity strategy? (Choose two)

Select 2 answers
A.Requiring multi-factor authentication (MFA) with continuous risk-based adaptive validation
B.Granting permanent administrative access once a device passes initial corporate compliance checks
C.Enforcing strict least-privilege access permissions based on user role, device posture, and context
D.Trusting internal network traffic implicitly once the user connects via corporate VPN
E.Allowing users to bypass authentication prompts when accessing internal web applications from managed assets
AnswersA, C

MFA combined with continuous risk assessment is a core requirement for verifying identity in Zero Trust.

Why this answer

Zero Trust identity strategies mandate continuous, risk-based adaptive verification and the strict enforcement of least-privilege access rather than relying on perimeter location or static trust.

81
MCQmedium

An organization uses Prisma Access for secure internet access. Users in a specific branch office report that a SaaS application is loading slowly. Which Prisma Access monitoring tool should the administrator use to analyze end-to-end path performance, latency, and packet loss between the branch office and the SaaS application?

A.Panorama Traffic Log CSV export analyzed via spreadsheet formulas.
B.AWS CloudWatch Network Monitor dashboard.
C.Prisma Autonomous DEM (ADEM) workspace in the Prisma Access management portal.
D.WildFire Sample Analysis execution timeline graph.
AnswerC

Correct. ADEM provides synthetic and real-user monitoring to analyze end-to-end digital experience and network performance.

Why this answer

Autonomous DEM (ADEM) provides end-to-end digital experience monitoring from the endpoint or branch network to SaaS applications.

82
Multi-Selectmedium

An administrator is configuring authentication profiles in PAN-OS to integrate an external identity provider. Which TWO of the following server types can be directly configured as authentication server profiles in a Palo Alto Networks firewall? (Choose two)

Select 2 answers
A.LDAP
B.Syslog Forwarder Service
C.RADIUS
D.DHCP Scope Manager
E.SNMPv3 Trap Receiver
AnswersA, C

LDAP is natively supported as an authentication server profile in PAN-OS.

Why this answer

PAN-OS supports multiple external authentication server profiles including LDAP, RADIUS, TACACS+, and SAML.

83
Multi-Selecthard

An enterprise is conducting a threat modeling exercise and evaluating risks associated with encrypted traffic. Which THREE security challenges are introduced when SSL/TLS encryption is enabled without decryption policies on the firewall? (Choose three)

Select 3 answers
A.Data exfiltration of sensitive source code or credit cards over encrypted HTTPS sessions goes undetected by Data Filtering profiles
B.Command and control (C2) callback traffic disguised as standard HTTPS web traffic evades Anti-Spyware detection
C.App-ID fails entirely to identify any encrypted applications
D.Malware and trojans hidden inside HTTPS streams bypass Antivirus and WildFire inspection
E.The firewall is unable to forward Layer 3 IP packets across static routes
AnswersA, B, D

Correct. Data filtering cannot inspect encrypted text payloads.

Why this answer

Without SSL decryption, the firewall cannot inspect payloads, leading to hidden malware, undetected data exfiltration, and blind spots in threat signatures.

84
Multi-Selecthard

An enterprise is implementing a Zero Trust Architecture across its cloud and on-premises environments using Palo Alto Networks Prisma Access and Next-Generation Firewalls. Which THREE of the following principles are core tenets of a Zero Trust Architecture? (Choose three)

Select 3 answers
A.Rely primarily on perimeter firewalls to secure internal east-west traffic
B.Assume breach and verify explicitly at every access request
C.Use comprehensive telemetry and analytics to monitor and validate device posture continuously
D.Trust internal subnets implicitly once a user authenticates at the corporate perimeter
E.Enforce least privilege access with just-in-time and just-enough access controls
AnswersB, C, E

Assuming breach and performing explicit verification of every access request is a fundamental Zero Trust tenet.

Why this answer

Zero Trust tenets include continuous verification, least privilege access, assuming breach, and treating all networks as untrusted.

85
MCQeasy

A network security engineer is configuring a security policy rule and notices that the security profile attachment area shows options for Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, Data Filtering, and WildFire Analysis. What is the collective term for these configurable security inspection modules?

A.Zone Protection Profiles
B.Decryption Profiles
C.Security Profiles
D.App-ID Custom Signature Objects
AnswerC

Correct. These modules are collectively referred to as Security Profiles attached to security rules.

Why this answer

Security profiles inspect data plane traffic for threats, malware, and policy violations and are collectively known as Security Profiles.

86
MCQeasy

An administrator needs to configure a Palo Alto Networks firewall to decrypt inbound SSL traffic destined for a public-facing web server. Which type of Decryption rule must be created?

A.SSL Forward Proxy
B.SSH Proxy
C.SSL Outbound Inspector
D.Inbound Decryption
AnswerD

Correct. Inbound Decryption is designed for protecting internal servers by decrypting inbound traffic using the server's private key.

Why this answer

Inbound Decryption is specifically used to decrypt traffic originating externally and destined for a protected internal web server where the firewall possesses the server private key and certificate.

87
MCQeasy

A security analyst wants to evaluate the organization's current threat exposure and understand the tactics, techniques, and procedures (TTPs) used by threat actors targeting their specific industry sector. Which Palo Alto Networks tool or feature should the analyst consult for contextual threat hunting and intelligence research?

A.AutoFocus threat intelligence service
B.Panorama Log Collector forwarding engine
C.Application Command Center (ACC) dashboard
D.GlobalProtect Host Information Profile (HIP) engine
AnswerA

Correct. AutoFocus provides deep visibility into threat actors, campaigns, and associated TTPs tailored to specific industries.

Why this answer

AutoFocus provides contextual threat intelligence derived from WildFire and other sources, allowing analysts to search threat groups, campaigns, and TTPs.

88
MCQhard

An enterprise deploying VM-Series firewalls in Google Cloud Platform (GCP) requires centralized license management via Panorama. Which licensing mode should be configured so that firewalls automatically obtain their licenses from Panorama based on consumption or pre-purchased credits?

A.Configure GCP Secret Manager to inject floating MAC addresses into the management interface.
B.Connect each VM-Series firewall directly to an on-premises hardware License Key Server (LKS) via a dedicated VPN.
C.Manually upload a permanent .lic license file via SSH to every autosscaled GCP instance upon boot.
D.Configure VM-Series Bootstrap with a Panorama AuthKey and Plugin for VM-Series Auto-Registration and Software-based Licensing.
AnswerD

Correct. Software-based licensing integrated with Panorama auth keys enables automated licensing for cloud deployments.

Why this answer

VM-Series firewalls support AuthCodes or VM-Series Bootstrap with Panorama using the CSS (Customer Support Portal) plugin and Smart Licensing / AuthCode provisioning. For cloud-native dynamic scaling, bootstrapping with Panorama auth keys and Auto-Registration is used.

89
Multi-Selecteasy

Which TWO platforms are officially supported for deploying the Cortex XDR Agent? (Choose two)

Select 2 answers
A.Personal gaming consoles.
B.Apple macOS endpoints.
C.Microsoft Windows workstations and servers.
D.Legacy mainframe operating systems from the 1980s.
E.Consumer smart home IoT routers running embedded proprietary firmware.
AnswersB, C

macOS is supported with agent protection and monitoring features.

Why this answer

Cortex XDR supports multiple operating systems including Windows and macOS.

90
Multi-Selecthard

Which THREE mechanisms are employed by Cortex XDR to protect endpoints against unknown zero-day file-based malware? (Choose three)

Select 3 answers
A.Cloud-based WildFire static and dynamic analysis sandbox.
B.Traditional static MD5 hash blocklists updated hourly.
C.Behavioral Threat Protection (BTP) monitoring execution chains.
D.Manual user verification prompts upon every file execution.
E.Local machine learning models executed directly on the endpoint.
AnswersA, C, E

Unknown files are uploaded to WildFire for comprehensive behavioral sandbox analysis.

Why this answer

Zero-day file defense utilizes local machine learning analysis, cloud-based WildFire static/dynamic analysis, and behavioral threat protection.

91
MCQhard

An enterprise is deploying a Zero Trust network model where all traffic must be inspected, authenticated, and authorized. An auditor asks how the organization ensures that unmanaged BYOD devices do not connect to sensitive internal database zones even if they authenticate successfully. Which feature combination enforces this posture check?

A.WildFire automated sandbox analysis combined with Data Filtering profiles
B.User-ID agent IP-to-user mapping combined with NAT translation tables
C.GlobalProtect Host Information Profiles (HIP) combined with Security policy zone and posture criteria
D.App-ID application signatures combined with URL Filtering categories
AnswerC

Correct. HIP checks client posture and enforces access restrictions in security policy based on device compliance.

Why this answer

GlobalProtect HIP (Host Information Profile) checks endpoint security posture (OS version, disk encryption, patch level) and feeds into security policies to restrict access.

92
MCQmedium

An administrator is deploying VM-Series firewalls in Microsoft Azure using an Azure Standard Load Balancer for inbound application traffic. Which component is required to handle asymmetry when routing return traffic from backend application VMs back through the firewall?

A.Configure Azure ExpressRoute Global Reach to bypass the Azure Load Balancer entirely.
B.Deploy an Azure Bastion host to proxy all inbound administrative and application sessions.
C.Configure an Azure Application Gateway in front of the Standard Load Balancer to perform Layer 7 proxying.
D.Enable Source NAT (SNAT) on the VM-Series firewall untrust/trust interface policies so return traffic flows back through the active firewall IP.
AnswerD

Correct. SNAT ensures that the backend server sees the firewall's IP as the source, guaranteeing that return traffic routes back through the firewall.

Why this answer

Azure Standard Load Balancer supports HA ports and SNAT, but inbound asymmetric traffic routed via user-defined routes (UDRs) requires careful load balancer configuration or floating IP (Direct Server Return) considerations, or utilizing Azure Gateway Load Balancer. For standard load balancers with firewalls, SNAT is typically enabled on the load balancer or firewall to maintain flow symmetry.

93
Multi-Selecthard

An administrator wants to configure Zone Protection Profiles to safeguard the internal network against common layer 2 and layer 3 attacks. Which THREE attack mitigation features are available within a Zone Protection Profile? (Choose three)

Select 3 answers
A.ICMP and UDP flood protection setting packet rate thresholds.
B.SYN Flood protection using SYN cookies or RED (Random Early Drop).
C.Advanced URL filtering categorization of malicious phishing links.
D.IP Spoofing detection and blocking of packets with source IPs matching internal subnets on external interfaces.
E.Automatic kernel-level malware sandboxing of unknown executable attachments.
AnswersA, B, D

Flood protection sets packet rate thresholds for ICMP, UDP, and other protocols.

Why this answer

Zone Protection Profiles protect against SYN floods, ICMP/UDP floods, IP spoofing, packet-based attacks (e.g., overlapping fragments, land attacks), and reconnaissance.

94
MCQmedium

An analyst investigating an APT campaign notes that the threat group modified Windows registry run keys to maintain persistence. In the context of MITRE ATT&CK, under which Tactic should this specific technique be documented?

A.Persistence
B.Impact
C.Execution
D.Credential Access
AnswerA

Modifying Windows registry run keys is a textbook technique for achieving persistence.

Why this answer

Persistence (TA0003) includes modifying registry run keys and startup folders to ensure code execution upon system reboot.

95
MCQhard

While investigating a sophisticated adversary group using the MITRE ATT&CK navigator, a SOC analyst notes that the threat actor leveraged valid accounts to maintain persistence while modifying group memberships to escalate privileges. Which combination of MITRE ATT&CK tactics best describes these observed phases?

A.Execution and Credential Access
B.Collection and Exfiltration
C.Persistence and Privilege Escalation
D.Initial Access and Defense Evasion
AnswerC

Maintaining access via valid accounts maps to Persistence, and altering group memberships maps to Privilege Escalation.

Why this answer

Using valid accounts for persistence falls under the Persistence tactic, and modifying group memberships to gain higher access falls under Privilege Escalation.

96
MCQeasy

An administrator is deploying Cortex XDR Agent to Windows workstations using an Active Directory Group Policy Object (GPO). Which installation parameter must be used to ensure the agent registers correctly with the assigned Cortex XDR tenant using a specific installation token?

A.Use the /REGKEY= parameter followed by the tenant activation password.
B.Use the /SERVER= parameter to define the cloud instance URL.
C.Use the /TENANTID= parameter followed by the fully qualified domain name.
D.Use the /INSTALLTOKEN= parameter followed by the unique registration token string.
AnswerD

This is the correct syntax for specifying the installation token during MSI execution.

Why this answer

The INSTALLTOKEN parameter is required during unattended or mass installations to associate the agent instance with the correct tenant in Cortex XDR.

97
MCQhard

An administrator configures a QoS profile to prioritize VoIP traffic over bulk data transfers. However, after applying the profile, VoIP packets are still experiencing high latency during peak business hours. Inspection shows that the QoS profile is applied correctly to the security rules, but the packets are not being placed into the correct QoS class. What is missing in the interface configuration?

A.The firewall requires an active Advanced URL Filtering license to classify VoIP packets.
B.QoS must be explicitly enabled on the egress Layer 3 interface settings with configured guaranteed and maximum bandwidth limits.
C.GlobalProtect VPN tunnels must be configured in full-tunnel mode to preserve QoS headers.
D.An Application Override policy must be created to bypass App-ID processing for VoIP streams.
AnswerB

Enabling QoS globally or in rules is insufficient; bandwidth allocation and QoS types (IP precedence or DSCP) must be configured on the specific interface.

Why this answer

For QoS to function properly on Palo Alto Networks firewalls, QoS must be enabled on the egress interface settings, and clear-text or DSCP/IP Precedence classification mapping must be defined on the interface.

98
Multi-Selectmedium

Which TWO deployment methods are officially supported for provisioning VM-Series firewalls in public cloud environments like AWS and Azure? (Choose two)

Select 2 answers
A.Flashing the PAN-OS virtual appliance image onto an AWS Snowball physical storage device.
B.Using Docker container daemonsets to host the PAN-OS management plane on AWS Lambda.
C.Installing physical PAN-OS supervisor cards directly into AWS EC2 bare-metal hypervisor chassis slots.
D.Using cloud-native orchestration tools (AWS CloudFormation or Azure Resource Manager templates) combined with bootstrap packages.
E.Deploying directly from the cloud provider marketplace (AWS Marketplace or Azure Marketplace) using bring-your-own-license (BYOL) or pay-as-you-go (PAYG).
AnswersD, E

Correct. CloudFormation and ARM templates with bootstrapping are widely used for automated deployment.

Why this answer

VM-Series firewalls can be deployed using cloud marketplace native methods (such as AWS AMI or Azure Marketplace) or via automated Infrastructure as Code / bootstrapping templates.

99
MCQhard

A security operations team is tracking an Advanced Persistent Threat (APT) group that exhibits custom command-and-control (C2) behavior, slow and low data exfiltration, and leverages living-off-the-land binaries. Which characteristic most reliably distinguishes this APT activity from a commodity malware campaign?

A.Rapid, automated encryption of all endpoints for immediate financial ransom
B.Mass distribution via untargeted spam campaigns with out-of-the-box exploit kits
C.Immediate self-replication across all reachable network segments without persistence goals
D.Persistent, targeted, and methodical human-driven objective execution with customized tooling
AnswerD

APTs are characterized by long-term persistence, human-driven operational adaptability, and custom tooling tailored to the target.

Why this answer

APTs are distinguished by their persistence, targeted focus, use of legitimate system tools (living off the land), and deliberate, stealthy manual intervention over automated destruction.

100
MCQmedium

A security analyst notices that WildFire has successfully analyzed a suspicious file uploaded from an endpoint, but the local Cortex XDR agent did not automatically block it upon first encounter. What is the most likely explanation for this behavior?

A.WildFire only analyzes network traffic passing through a Palo Alto Networks Next-Generation Firewall.
B.Local analysis blocks all files by default without cloud consultation.
C.The file was unknown to WildFire at execution time and was subsequently sent for analysis, resulting in a retroactive verdict.
D.The Cortex XDR agent does not integrate with WildFire cloud intelligence.
AnswerC

Zero-day files executed before WildFire analysis result in retroactive alerts once the sandbox determines maliciousness.

Why this answer

If a file is entirely novel, local analysis or global intelligence may require dynamic analysis before a verdict is reached, or the file was executed before the verdict populated.

101
MCQmedium

An organization is adopting a Zero Trust architecture. During the implementation of Least Privilege Access, the network security team needs to configure security policies that restrict traffic based on user identity rather than IP addresses alone. Which feature must be enabled and integrated with the Palo Alto Networks firewall to achieve this?

A.GlobalProtect with Clientless VPN
B.App-ID cloud-based application signatures
C.User-ID agent or Panorama User-ID mapping
D.WildFire threat intelligence cloud
AnswerC

Correct. User-ID provides identity-based visibility and policy enforcement by mapping usernames to IP addresses.

Why this answer

User-ID integrates the firewall with enterprise directory services to map IP addresses to usernames, enabling policy enforcement based on user and group identity.

102
Multi-Selecteasy

A security operations team is reviewing firewall traffic logs. Which TWO key pieces of information does the App-ID engine provide for every recognized session? (Choose two)

Select 2 answers
A.The application risk level (ranging from 1 to 5)
B.The exact BIOS version of the client workstation
C.The ambient room temperature of the firewall chassis hardware
D.The physical MAC address of the destination server
E.The specific application name (e.g., 'ssl', 'zoom-video', 'ms-office-365')
AnswersA, E

Correct. App-ID assigns a risk factor score to applications based on characteristics like evasion potential and file transfer capabilities.

Why this answer

App-ID identifies the specific application name and the underlying transport protocol/port characteristics, along with risk ratings.

103
Multi-Selecteasy

Which THREE parameters or settings can be configured within a Cortex XDR Agent Settings profile? (Choose three)

Select 3 answers
A.Agent heartbeat and check-in frequency intervals.
B.Proxy server IP address, port, and authentication details.
C.GlobalProtect VPN gateway tunnel encryption keys.
D.Agent operating mode (Prevention vs. Audit).
E.Palo Alto Networks firewall security policy rulebases.
AnswersA, B, D

Heartbeat intervals are configured in the Agent Settings profile.

Why this answer

Agent Settings profiles govern communication intervals, proxy servers, and operational modes.

104
MCQmedium

An incident responder analyzing an APT intrusion discovers that the attacker compressed and encrypted sensitive files locally on a compromised server before staging them for exfiltration. Under the MITRE ATT&CK framework, which Tactic describes this staging behavior?

A.Collection
B.Exfiltration
C.Persistence
D.Execution
AnswerA

Staging, archiving, and encrypting data prior to theft falls under the Collection tactic.

Why this answer

Collection (TA0009) consists of techniques adversaries use to gather and stage data, such as archiving and encrypting files prior to exfiltration.

105
Multi-Selecteasy

Which THREE types of data are gathered and ingested by Cortex XDR to provide comprehensive endpoint visibility? (Choose three)

Select 3 answers
A.Registry modification events.
B.Personal user email message bodies and browser photo uploads.
C.Process execution and termination telemetry.
D.Network connection and socket activity logs.
E.Internal corporate cafeteria menu preferences.
AnswersA, C, D

Registry changes are tracked to identify persistence mechanisms.

Why this answer

Cortex XDR ingests process execution telemetry, registry modifications, and network connection logs.

106
Multi-Selectmedium

Which TWO methods can be used to authenticate remote users connecting to Prisma Access via GlobalProtect? (Choose two)

Select 2 answers
A.LDAP or RADIUS authentication profiles configured via the Cloud Identity Engine or local firewalls.
B.Physical USB smartcard hardware serial number validation via local PAN-OS USB ports on user laptops.
C.SAML 2.0 integration with enterprise identity providers (such as Microsoft Entra ID, Okta, or Ping Identity).
D.Plaintext HTTP Basic Authentication embedded in URL parameters.
E.Static MAC address whitelisting on enterprise Wi-Fi routers.
AnswersA, C

Correct. Legacy or directory-based authentication via LDAP/RADIUS is fully supported.

Why this answer

Prisma Access supports multiple authentication methods including SAML 2.0 Identity Providers (IdPs) and LDAP/RADIUS directories via Cloud Identity Engine or explicit authentication profiles.

107
Multi-Selectmedium

An administrator is configuring Zone Protection profiles to mitigate potential network attacks. Which TWO flood protection mechanisms are available within a Zone Protection profile? (Choose two)

Select 2 answers
A.Cross-site scripting (XSS) protection
B.Antivirus payload inspection
C.SYN flood protection
D.UDP flood protection
E.SQL injection protection
AnswersC, D

Correct. SYN flood protection is a core feature of Zone Protection profiles.

Why this answer

Zone Protection profiles protect against external flood attacks, including SYN floods, UDP floods, and ICMP floods.

108
MCQhard

An administrator is troubleshooting a BGP routing peer connection between the Palo Alto Networks firewall and an external provider router. The BGP session is stuck in the 'Connect' state. Inspection of system logs indicates TCP port 179 packets sent by the firewall are being transmitted, but no SYN-ACK is received. Which troubleshooting step or feature verification should be performed first?

A.Verify that a Security policy rule with application 'bgp' (or service tcp-179) from the external zone to 'zone: 'to-firewall'' permits control plane traffic, or check Zone Protection / Management Profile settings.
B.Reconfigure the Virtual Wire interface pair to handle BGP encapsulation headers.
C.Restart the Management server process using the CLI command 'debug software restart management-server'.
D.Convert the BGP peer to OSPFv3 protocol.
AnswerA

Control plane traffic destined for the firewall itself from external zones requires appropriate zone protection, management profile, or security policy evaluation depending on interface configuration.

Why this answer

BGP uses TCP port 179. If SYN packets are sent but no SYN-ACK is returned, the issue is either upstream filtering, incorrect peer IP, or Zone Protection / Security policies blocking the control plane traffic destined for the firewall's routing daemon.

109
MCQhard

An organization is configuring exploit prevention rules in Cortex XDR to protect legacy browser plugins. An application crashes repeatedly due to an overly aggressive protection profile. Which action should the administrator take to troubleshoot without completely disabling exploit protection?

A.Add the browser executable path to the OS exclusions list in Cortex XDR.
B.Change the exploit protection behavior for the specific technique to 'Report' instead of 'Terminate'.
C.Disable memory protection features globally in the agent settings profile.
D.Enable Agent Self-Protection to prevent local interference.
AnswerB

Switching the action to Report logs the violation without terminating the application, enabling effective troubleshooting.

Why this answer

Putting the exploit protection module into Report (Audit) mode allows verification of potential blocks without disrupting user productivity.

110
MCQeasy

When setting up Prisma Access Mobile Users, what is the recommended client software installed on end-user laptops to establish secure connections to the cloud security processing nodes?

A.Panorama Admin Agent
B.Prisma Cloud Defender Agent
C.Prisma Access CLI Client
D.GlobalProtect app
AnswerD

Correct. The GlobalProtect agent connects mobile users securely to the nearest Prisma Access SPN.

Why this answer

GlobalProtect is the client software used to connect mobile users to Prisma Access.

111
MCQhard

An organization is deploying Palo Alto Networks firewalls in a Zero Trust Architecture. The security team wants to ensure that administrative access follows the principle of least privilege by tying administrator accounts to dynamic group memberships managed in an external LDAP directory, rather than maintaining static local accounts. Which feature in PAN-OS supports this?

A.Disabling authentication and relying on physical console keylocks
B.Local administrator accounts with never-expiring passwords
C.Shared superuser account with multi-person shared keys
D.Administrator role mapping via external LDAP/RADIUS group attributes
AnswerD

Mapping external directory groups to PAN-OS admin roles ensures dynamic least privilege access control.

Why this answer

Admin role mapping via LDAP/RADIUS allows administrators to inherit their role profile dynamically based on their directory group memberships.

112
MCQhard

An enterprise network runs custom internal applications that utilize non-standard encryption protocols. To maintain visibility without breaking application functionality, the security team needs to deploy decryption. Which type of decryption should be configured if the firewall does not possess the private keys of the internal servers, but internal clients trust the firewall's forward proxy certificate?

A.SSL Inbound Inspection Decryption
B.SSL Forward Proxy Decryption
C.Kerberos Decryption Service integration
D.SSH Decryption Proxy mode
AnswerB

Correct. SSL Forward Proxy intercepts outbound SSL/TLS traffic to external sites by re-signing sessions with a local root CA certificate.

Why this answer

SSL Forward Proxy decryption inspects outbound traffic to external servers by generating a forward proxy certificate on the firewall.

113
MCQhard

An organization is using Prisma Cloud to monitor AWS IAM policies. A custom policy check fails because an IAM role allows overly permissive actions on S3 buckets. Where in Prisma Cloud should the administrator navigate to view and remediate this specific cloud infrastructure misconfiguration?

A.Navigate to Prisma Cloud CSPM > Alerts, filter by AWS IAM service, and use RQL or built-in auto-remediation.
B.Navigate to Panorama > Cloud Services > Native Security to update IAM roles.
C.Navigate to Prisma Cloud Compute > Vulnerabilities > Functions to review IAM policy JSON files.
D.Navigate to Prisma Access > Traffic > Monitor to inspect IAM API call logs.
AnswerA

Correct. Prisma Cloud CSPM Alerts display misconfigurations and provide remediation guidance or CLI/API auto-remediation scripts.

Why this answer

Prisma Cloud Cloud Security Posture Management (CSPM) evaluates resource configurations against compliance standards and policies in the Investigate or Alerts tab.

114
Multi-Selecthard

A security operations team is implementing zero trust network access (ZTNA) principles across the enterprise. According to foundational Zero Trust architecture guidelines, which THREE tenets must be enforced? (Choose three)

Select 3 answers
A.Verify explicitly by authenticating and authorizing based on all available data points
B.Trust users and devices automatically once they successfully authenticate at the network perimeter
C.Assume breach and continuously monitor all sessions for anomalous behavior
D.Limit user access with Just-In-Time and Just-Enough-Access (JIT/JEA) principles
E.Grant broad internal network access to trusted partners and contractors to streamline operations
AnswersA, C, D

Explicit verification requires validating identity, location, device health, and service context for every access request.

Why this answer

Zero Trust mandates verifying explicitly, using least privilege access, and assuming breach, regardless of whether traffic originates inside or outside the traditional network perimeter.

115
MCQhard

An administrator needs to deploy VM-Series firewalls in an AWS environment using an AWS Gateway Load Balancer (GWLB). Which CloudFormation template or method should the administrator use to ensure traffic is transparently routed through the firewall without requiring destination NAT?

A.Deploy a standard VPC peering connection and configure AWS Client VPN endpoints to steer traffic to the untrust interface.
B.Deploy using the AWS GWLB quick start template with Geneve encapsulation configured on the VM-Series data interfaces.
C.Use AWS Lambda functions to dynamically update security group rules whenever a new workload instance is provisioned.
D.Configure an AWS Transit Gateway with route tables pointing to an Elastic Load Balancer in front of the VM-Series trust interface.
AnswerB

Correct. The standard Palo Alto Networks AWS GWLB CloudFormation template automates the deployment of the GWLB, target groups, and VM-Series firewalls with Geneve protocol support.

Why this answer

AWS GWLB uses Geneve encapsulation on port 6081 to securely exchange traffic between the GWLB and the VM-Series firewalls, allowing transparent inline inspection without SNAT/DNAT.

116
Multi-Selectmedium

Which TWO benefits are achieved by integrating Prisma Cloud with cloud provider audit logs (such as AWS CloudTrail, Azure Activity Logs, and GCP Audit Logs)? (Choose two)

Select 2 answers
A.Automatic kernel-level patching of vulnerable operating systems inside cloud virtual machines.
B.Hardware-level encryption acceleration for TLS traffic traversing VM-Series firewalls.
C.Ability to perform forensic investigations to track which user or IAM role performed specific resource modifications.
D.Real-time detection of suspicious API activities and anomalous user behavior (UEBA) across the cloud environment.
E.Automated load balancing of inbound web traffic across multiple availability zones.
AnswersC, D

Correct. Audit log integration provides complete traceability of who made configuration changes in the cloud.

Why this answer

Cloud provider audit log integration enables real-time threat detection (UEBA) and historical forensic investigation of API activities.

117
MCQmedium

A security architect is designing high availability (HA) for a pair of Palo Alto Networks firewalls to ensure business continuity during hardware failures. Which HA operational mode ensures that both firewalls actively process traffic and synchronize session tables in real-time?

A.Cluster mode with dynamic routing ECMP multipath load balancing
B.Virtual Router redundancy protocol (VRRP) standalone failover groups
C.HA Active/Passive mode with preemption enabled
D.HA Active/Active mode with session synchronization enabled
AnswerD

Correct. Active/Active mode enables both firewalls to process traffic simultaneously with synchronized session state tables.

Why this answer

HA Active/Active mode allows both firewalls to process traffic simultaneously, requiring session synchronization and floating IP addresses.

118
MCQeasy

An administrator is preparing to deploy Cortex XDR agents to 500 remote endpoints using a software deployment tool. Where can the administrator download the latest installation packages and transforms?

A.Navigate to Cortex XDR management console > Settings > Distributions.
B.Run the 'cytool download-installer' command on an existing endpoint.
C.Access the Palo Alto Networks Customer Support Portal under Software Updates.
D.Log in to the Prisma Access management portal and select Endpoints.
AnswerA

The Distributions page houses all installer packages, upgrades, and installer scripts for different operating systems.

Why this answer

Installation packages are generated and downloaded directly from the Cortex XDR management console under the Distributions page.

119
Multi-Selecthard

Which TWO actions should an administrator take when a legitimate software application is falsely blocked by Cortex XDR Behavioral Threat Protection (BTP)? (Choose two)

Select 2 answers
A.Create a Behavioral Threat Protection exception rule specifying the relevant criteria and file attributes.
B.Disable operating system firewall services globally.
C.Submit the false positive sample to Palo Alto Networks for analysis and signature adjustment.
D.Completely uninstall the Cortex XDR agent from all corporate endpoints.
E.Format the hard drive and reinstall the operating system.
AnswersA, C

Creating a BTP exception properly suppresses the false positive while keeping protection active.

Why this answer

False positives can be resolved by creating a BTP exception rule or submitting the false positive for analysis and whitelist update.

120
MCQmedium

An enterprise security architect is designing a defense-in-depth strategy using Palo Alto Networks Panorama and Next-Generation Firewalls. Which implementation best exemplifies the defense-in-depth security principle?

A.Using automated patch management software as the sole security control for all internal servers.
B.Relying entirely on cloud-delivered security services without deploying physical or virtual firewalls on-premises.
C.Deploying a single, highly powerful firewall at the perimeter with all security profiles enabled and no internal segmentation.
D.Implementing perimeter firewalls with threat prevention, internal segmentation firewalls, endpoint protection via Cortex XDR, and multi-factor authentication for user access.
AnswerD

This approach uses multiple distinct layers of security controls across the network, endpoints, and identity.

Why this answer

Defense-in-depth relies on multiple layers of security controls so that if one control fails, subsequent layers continue to protect the environment.

121
Multi-Selectmedium

A network security team is configuring URL Filtering profiles to protect users from malicious web content. Which THREE actions can be assigned to specific URL categories within a URL Filtering profile? (Choose three)

Select 3 answers
A.Continue (prompts the user with a warning page requiring acknowledgment before proceeding)
B.Block (terminates the session and displays a response page)
C.Quarantine (isolates the client workstation into an isolated VLAN)
D.Alert (permits the traffic but generates a URL log entry)
E.Encrypt (automatically forces SSL forward proxy decryption for the URL)
AnswersA, B, D

Correct. Continue prompts users with a warning page requiring click-through to proceed.

Why this answer

URL filtering profile categories can be assigned actions such as block, allow, alert, continue, or override.

122
MCQhard

An administrator configures a Security policy rule with an application dependency on 'ssl', but the target application is 'custom-app'. When committing the configuration, the firewall generates a warning or error regarding application dependencies. What is the correct way to handle application dependencies in Palo Alto Networks firewalls?

A.Place the dependent application above the dependency in the Security policy table.
B.Create a custom App-Override policy for the dependent application to bypass Layer 7 inspection.
C.Disable application dependency checking globally under Device > Setup > Content.
D.Explicitly include both the dependent application and all required dependent applications in the Security policy rule.
AnswerD

Correct. PAN-OS requires security rules to permit both the target application and its underlying dependencies (like ssl or web-browsing).

Why this answer

When an application has a dependency, the dependent application (e.g., custom-app) requires the underlying application (e.g., ssl) to also be allowed in the security policy rule for proper identification and functionality.

123
Multi-Selecteasy

A security analyst is investigating common cyber threats targeting web applications. Which TWO threats are classified as web-based injection or application-layer attacks that can be mitigated by security profiles on a next-generation firewall? (Choose two)

Select 2 answers
A.Fiber optic cable fiber cut
B.Physical server hardware power supply failure
C.Management plane cooling fan speed degradation
D.SQL Injection attacks
E.Cross-Site Scripting (XSS) attacks
AnswersD, E

Correct. Vulnerability protection contains signatures to detect and block SQL injection payload attempts.

Why this answer

SQL injection and Cross-Site Scripting (XSS) are common application-layer web threats that can be detected by Vulnerability Protection signatures.

124
MCQmedium

A company's risk management framework requires multi-factor authentication (MFA) for all remote access connections. The organization utilizes GlobalProtect for remote workers. Where should the administrator configure the authentication profile to enforce MFA during the GlobalProtect connection phase?

A.Via the Decryption policy rule pointing to an external LDAP server
B.Through the App-ID custom signature editor
C.Within the GlobalProtect Portal and Gateway configurations referencing an Authentication Profile tied to an MFA provider
D.Inside the Zone Protection profile attached to the external untrusted zone interface
AnswerC

Correct. GlobalProtect Portal and Gateway settings reference authentication profiles that support MFA integration (such as SAML or RADIUS).

Why this answer

GlobalProtect Gateway and Portal configurations reference Authentication Profiles, which integrate with external RADIUS, SAML, or LDAP servers to enforce MFA.

125
MCQmedium

An organization wants to inspect east-west traffic between different microservices running inside an Amazon Elastic Kubernetes Service (EKS) cluster using VM-Series firewalls. Which architectural pattern is recommended?

A.Deploy Panorama as a sidecar container inside every Kubernetes pod namespace.
B.Attach the Prisma Access remote network VPN gateway directly to the Kubernetes cgroup filesystem.
C.Route inter-subnet pod traffic through VM-Series firewall interfaces using AWS VPC route tables and secondary IP configurations.
D.Configure AWS Route 53 to proxy all TCP traffic between pods.
AnswerC

Correct. Routing traffic between subnets through VM-Series firewall interfaces enables east-west inspection of cloud workloads.

Why this answer

East-west inspection in Kubernetes or public cloud environments is typically handled by container-native controls or by routing inter-subnet traffic through VM-Series firewalls acting as gateway routers using AWS Transit Gateway or custom routing tables.

126
Multi-Selectmedium

Which THREE security modules are included as core components of the Cortex XDR agent architecture? (Choose three)

Select 3 answers
A.Behavioral Threat Protection (BTP) module
B.Enterprise BGP Routing protocol daemon
C.Exploit Prevention module
D.Stateful Packet Inspection Firewall core routing engine
E.Anti-Malware prevention module
AnswersA, C, E

BTP monitors process behavior to catch advanced attacks.

Why this answer

Cortex XDR integrates anti-malware, exploit prevention, and behavioral threat protection as core agent modules.

127
Multi-Selectmedium

A security administrator is configuring a WildFire analysis profile to protect the network from zero-day malware. Which THREE actions can be configured within a WildFire analysis profile when an unknown file is inspected? (Choose three)

Select 3 answers
A.Automatically downgrade user access privileges upon file detection
B.Forward the unknown file to the WildFire cloud for sandboxing analysis
C.Reboot the firewall data plane CPU cores to clear memory caches
D.Block the file download until WildFire analysis completes (inline machine learning / malware prevention)
E.Generate an alert log when an unknown file type is detected
AnswersB, D, E

Correct. WildFire profiles can be configured to forward unknown files for cloud analysis.

Why this answer

WildFire analysis profiles support actions such as forward, block, and dynamic analysis settings for unknown file types.

128
MCQeasy

An administrator wants to view real-time session information, including source/destination ports, translated IPs, and matched security rules, for active traffic flowing through the firewall. Which CLI command should the administrator execute?

A.show high-availability state
B.show interface management
C.show system resources
D.show session all
AnswerD

'show session all' lists all active sessions currently maintained in the firewall session table.

Why this answer

The 'show session all' command displays active session table entries in the firewall CLI.

129
MCQeasy

What is the primary function of the Prisma Cloud Data Security module?

A.Tunnel database traffic securely from on-premises data centers to AWS RDS instances.
B.Encrypt database tables in Microsoft Azure SQL using customer-managed HSM keys.
C.Discover, classify, and protect sensitive data (such as PII and financial records) stored in cloud object storage like AWS S3.
D.Inspect TLS certificates on public-facing load balancers for expiration dates.
AnswerC

Correct. Prisma Cloud Data Security scans object storage to detect exposed sensitive data and compliance violations.

Why this answer

Prisma Cloud Data Security discovers, classifies, and protects sensitive data stored in cloud object storage like AWS S3 buckets.

130
MCQmedium

A firewall is deployed in an environment with asymmetric routing. Packets belonging to the same TCP session enter on different interfaces due to multi-path upstream routing. What configuration change is required on the Palo Alto Networks firewall to prevent the traffic from being dropped?

A.Configure an explicit Security policy rule with 'Any' to 'Any' action set to accept asymmetric flows.
B.Set Asymmetric Path to 'bypass' or 'loose' under Device > Setup > Session > Session Settings.
C.Enable strict TCP validation under Device > Setup > Session.
D.Disable stateful inspection globally using a custom Application Override policy.
AnswerB

This setting allows the firewall to accept session packets even if the initial handshake occurred on a different interface.

Why this answer

Asymmetric routing causes path mismatch where SYN goes through one interface/firewall node and ACK goes through another. Asymmetric Path settings under Device > Setup > Session must be set to 'bypass' or 'loose-check'.

131
Multi-Selectmedium

An administrator is configuring security policies on a Palo Alto Networks firewall and wants to ensure best practices for rule organization and management. Which TWO practices are recommended when designing security rules? (Choose two)

Select 2 answers
A.Group related security rules into logical rule categories for easier management and auditing.
B.Disable logging on all security rules to conserve management plane CPU resources.
C.Always use the 'any' source zone to ensure all internal subnets are covered simultaneously.
D.Use specific Application definitions (App-ID) instead of generic port-based rules wherever feasible.
E.Place broad, permissive rules at the top of the security policy base to speed up rule evaluation.
AnswersA, D

Rule categories help organize policies logically (e.g., Intra-Zone, Inter-Zone, VPN).

Why this answer

Best practices for security rules include grouping related rules into rule categories, using descriptive names, avoiding overly broad 'any-any' rules where possible, and leveraging Security-ID/App-ID rather than port-based rules.

132
MCQmedium

An administrator is configuring DNS Security on VM-Series firewalls protecting a multi-cloud environment. Which mechanism does DNS Security use to protect against newly registered domains and command-and-control (C2) domains that lack traditional signatures?

A.Enforcing DNSSEC validation on all outbound UDP port 53 traffic traversing the untrust interface.
B.Real-time cloud-based machine learning analytics that analyze DNS query patterns and domain generation algorithms (DGAs).
C.Performing automated zone transfers (AXFR) with public root DNS servers every hour.
D.Local DNS response caching on the firewall hard drive to block blacklisted IP addresses.
AnswerB

Correct. DNS Security leverages machine learning in the cloud to detect unknown malicious domains and DGA traffic instantly.

Why this answer

DNS Security uses machine learning and predictive analytics in the cloud to identify malicious domains in real-time.

133
MCQmedium

An enterprise is deploying VM-Series firewalls across AWS, Azure, and GCP. The security team wants a single pane of glass to manage firewall security policies, rule deployments, and software updates across all cloud and on-premises firewalls. Which tool should be used?

A.Panorama Centralized Management
B.AWS Systems Manager Parameter Store
C.Prisma Access Cloud Management Portal (CMP) for Remote Networks only.
D.Prisma Cloud Compute Console
AnswerA

Correct. Panorama manages physical, virtual (VM-Series), and container (CN-Series) firewalls across all environments.

Why this answer

Panorama provides centralized management for both physical and virtual (VM-Series and CN-Series) firewalls across multi-cloud and on-prem environments.

134
Multi-Selecthard

When configuring Prisma Access Remote Networks, which THREE core components or settings are mandatory to establish a secure IPsec tunnel from a branch office firewall to a Prisma Access mobile gateway? (Choose three)

Select 3 answers
A.BGP routing protocol configuration or static routes pointing branch traffic into the IPsec tunnel interface.
B.IPsec Tunnel configuration defining proxy IDs or traffic selectors and associating the tunnel with a virtual router.
C.Direct AWS Direct Connect physical cross-connect circuit ID assignment.
D.IKE Gateway configuration specifying the pre-shared key (PSK) or certificate and remote Prisma Access gateway IP address.
E.Local MySQL database replication credentials for logging synchronization.
AnswersA, B, D

Correct. Routing is required to steer branch traffic across the IPsec tunnel.

Why this answer

Configuring Prisma Access Remote Networks requires defining the IKE crypto profile, IPsec crypto profile, and the peer IP address / tunnel interface settings on the branch firewall.

135
MCQmedium

During an incident investigation in Cortex XDR, an analyst identifies that an attacker utilized Windows Management Instrumentation (WMI) to execute commands remotely across multiple endpoints. According to the MITRE ATT&CK framework, under which tactic should this activity be categorized?

A.Execution
B.Discovery
C.Command and Control
D.Credential Access
AnswerA

WMI is commonly abused by adversaries to execute code and scripts on systems, falling under the Execution tactic.

Why this answer

Windows Management Instrumentation is a legitimate administrative feature that adversaries abuse to execute code and move laterally, placing it under Execution or Lateral Movement depending on context, but specifically Execution when used to run scripts locally/remotely.

136
MCQmedium

A security analyst is investigating a threat where a legitimate administrative tool (Living off the Land) was used maliciously. Cortex XDR generated an alert via Local Analysis. Which mechanism powers the Local Analysis engine to detect this type of threat without requiring an internet connection?

A.Periodic scheduled scans against the Palo Alto Networks threat intelligence cloud.
B.Real-time signature matching against a local antivirus definition database.
C.Continuous DNS tunneling queries sent to WildFire.
D.Embedded machine learning classifiers executed directly on the endpoint.
AnswerD

Local Analysis uses advanced machine learning models running locally on the agent to detect zero-day and file-based threats offline.

Why this answer

Local Analysis uses embedded machine learning models running locally on the endpoint to evaluate file features.

137
Multi-Selecthard

An enterprise security architect is designing a Zero Trust architecture using Palo Alto Networks products. Which THREE foundational principles must be enforced to achieve a true Zero Trust network posture? (Choose three)

Select 3 answers
A.Assume breach by minimizing blast radius and segmenting networks, and inspecting all traffic
B.Verify explicitly by authenticating and authorizing based on all available data points (identity, location, device health)
C.Use least privilege access by restricting user and device access with risk-based adaptive policies
D.Trust the internal network perimeter implicitly once a user successfully authenticates via VPN
E.Bypass security inspection for internal-to-internal data center traffic to maximize network performance
AnswersA, B, C

Correct. Assuming breach requires continuous monitoring, micro-segmentation, and end-to-end encryption/inspection.

Why this answer

Zero Trust principles include verifying explicitly, using least privilege access, and assuming breach while inspecting all traffic.

138
MCQmedium

An administrator is configuring security profiles on a Palo Alto Networks Next-Generation Firewall to mitigate potential data exfiltration attempts. To best adhere to the principle of least privilege regarding outbound traffic, which action should the administrator take?

A.Disable decryption entirely to prevent performance degradation and rely solely on source IP zoning.
B.Allow all outbound traffic on standard ports such as 80 and 443 to ensure uninterrupted business application functionality.
C.Create a single any-to-any allow rule for the internal development subnet to speed up troubleshooting.
D.Implement App-ID policies to permit only explicitly required business applications and inspect all allowed traffic using WildFire and Anti-Spyware profiles.
AnswerD

Using App-ID to restrict traffic to only required applications enforces least privilege effectively.

Why this answer

Least privilege mandates restricting access and capabilities to only what is strictly necessary for operational needs, which includes blocking unexpected outbound ports and protocols.

139
MCQeasy

An administrator needs to restrict access to malicious command-and-control (C2) domains. Which security profile should be attached to the outbound Security policy rules to inspect and block this traffic?

A.Quality of Service (QoS) Profile
B.File Blocking Profile
C.Anti-Spyware Profile
D.Data Filtering Profile
AnswerC

Anti-Spyware profiles detect and block command-and-control traffic, DNS queries to malicious domains, and spyware.

Why this answer

Anti-Spyware profiles inspect traffic for spyware, command-and-control (C2) traffic, and phone-home activities.

140
MCQeasy

An administrator configures a Security policy rule to block all file-sharing applications. However, users are still able to upload files using an authorized cloud collaboration tool that shares the same parent application family. Which feature should the administrator use to granularly block file uploads while permitting standard document viewing?

A.WildFire Analysis Profile set to block all files
B.File Blocking Profile applied to the Security rule
C.URL Filtering Profile with custom file blocking categories
D.Data Filtering Profile
AnswerB

File Blocking Profiles allow granular control over specific file types and actions (e.g., block uploads).

Why this answer

File Blocking Profiles allow administrators to inspect traffic by application, file type, and direction (upload/download), blocking specific file transfers while allowing the app to run.

141
MCQeasy

Which Prisma Cloud module provides Cloud Workload Protection (CWP) capabilities, including runtime defense, vulnerability management, and compliance for containers, hosts, and serverless functions?

A.Prisma Access Network Security
B.Prisma Cloud IAM Security
C.Prisma Cloud Compute
D.Prisma Cloud CSPM
AnswerC

Correct. Prisma Cloud Compute delivers comprehensive cloud workload protection across hosts, containers, and serverless.

Why this answer

Prisma Cloud Compute is the module dedicated to Cloud Workload Protection (CWP).

142
MCQmedium

A security analyst notices that a benign internal software development tool is being incorrectly blocked by Cortex XDR Prevent as malware. What is the most granular method to whitelist this application while maintaining maximum security posture?

A.Add the file path as an exclusion in the OS-level Windows Defender settings.
B.Disable the local analysis module entirely for the affected endpoint group.
C.Create a Profile Exception in the Malware Profile using the SHA-256 hash of the executable.
D.Change the agent profile operating mode from Prevention to Audit mode globally.
AnswerC

Using the SHA-256 hash ensures only the exact approved file is exempted from blocking.

Why this answer

Hashing the specific file or using a signed certificate exception provides targeted remediation without compromising endpoint security.

143
MCQeasy

An administrator wants to ensure that end users cannot tamper with or uninstall the Cortex XDR agent from their workstations. Which feature provides this protection?

A.Anti-Tamper Protection
B.Active Directory Software Restriction Policies
C.GlobalProtect Client Lockdown
D.Windows User Account Control (UAC)
AnswerA

Anti-Tamper protects agent files, registry keys, and processes from local modification or removal.

Why this answer

Anti-Tamper protection prevents unauthorized users from stopping services, modifying files, or uninstalling the agent.

144
Multi-Selecthard

A security operations team is reviewing MITRE ATT&CK Tactic classifications for an incident involving credential theft and subsequent unauthorized actions on a Palo Alto Networks protected network. Which THREE of the following Tactics fall under the 'Post-Compromise' or later stages of the attack lifecycle? (Choose three)

Select 3 answers
A.Exfiltration
B.Initial Access
C.Lateral Movement
D.Command and Control
E.Reconnaissance
AnswersA, C, D

Exfiltration occurs late in the lifecycle after data has been collected and staged.

Why this answer

In MITRE ATT&CK, tactics like Exfiltration, Lateral Movement, and Command and Control occur after initial access and execution.

145
Multi-Selectmedium

A SOC analyst is investigating a suspected Advanced Persistent Threat (APT) group that exhibits classic characteristics during its operation lifecycle. Which THREE traits are typically associated with advanced persistent threat campaigns? (Choose three)

Select 3 answers
A.Exclusive reliance on publicly available penetration testing scripts
B.Utilization of stealthy techniques designed to evade standard security monitoring tools
C.Deployment of custom command and control infrastructure tailored to specific targets
D.Short dwell times with aggressive, noisy data encryption
E.Targeted, long-term persistence within the compromised environment
AnswersB, C, E

Evading detection systems is a hallmark of APT operations to ensure prolonged access.

Why this answer

APTs are characterized by long dwell times, stealthy behavior to evade automated detection, and customized tools targeted at specific organizational objectives.

146
MCQmedium

A security administrator is troubleshooting an issue where internal users cannot reach a specific external website, and the traffic is being dropped by the firewall. The administrator suspects a Threat Prevention profile is blocking the response as a command-and-control callback. Where should the administrator look to verify the exact threat signature ID and packet capture that triggered the block?

A.Monitor > Logs > Threat
B.Policies > Security
C.Network > Network Profiles > Zones
D.Monitor > Logs > Traffic
AnswerA

Correct. Threat logs contain the specific signature ID, severity, and packet capture links for dropped threats.

Why this answer

Threat log entries record details about security profile violations, including the threat ID, threat name, and packet captures if enabled.

147
Multi-Selectmedium

An administrator is troubleshooting a scenario where internal clients cannot resolve external domain names through the firewall configured as a DNS proxy. Which TWO settings should be verified on the firewall? (Choose two)

Select 2 answers
A.Ensure captive portal redirection is enabled on the loopback address.
B.Verify that the DNS Proxy object has valid primary and secondary external DNS server IP addresses configured.
C.Verify that BGP routing is enabled on all Layer 2 trust interfaces.
D.Check that the GlobalProtect portal certificate is installed in the trusted root store.
E.Ensure the interface receiving client DNS requests has the DNS Proxy enabled in its Network Profile settings.
AnswersB, E

The DNS proxy needs upstream DNS servers to forward client queries to.

Why this answer

When configuring DNS Proxy on a Palo Alto Networks firewall, the administrator must ensure primary/secondary DNS servers are configured, the interface is enabled for DNS proxy, and client requests are pointed to the correct proxy interface IP.

148
MCQmedium

An organization requires that Cortex XDR agents verify their connection to the Cortex XDR server through a corporate HTTP proxy. Where is the proxy configuration defined for the Cortex XDR agent?

A.Configured via the Windows Registry under HKEY_LOCAL_MACHINE\Software\Palo Alto Networks\Proxy.
B.Configured through the local Windows Internet Options control panel.
C.Managed automatically via DNS SRV records without console configuration.
D.Configured directly in the Agent Settings profile within the Cortex XDR console.
AnswerD

Agent settings profiles allow defining proxy servers, ports, and credentials for agent communication.

Why this answer

Proxy settings for the agent are typically defined within the installation parameters or agent settings profile within the console.

149
MCQhard

An administrator needs to upgrade Cortex XDR agents across a large enterprise environment. To minimize network congestion and control the rollout, how should the administrator manage the upgrade process?

A.Execute 'cytool upgrade force' remotely using a PowerShell remoting script.
B.Enable the 'Auto-Update' feature in the Windows Update service settings.
C.Configure automatic scheduled agent upgrades within the Distributions and Software management view.
D.Manually download the MSI and push it via group policy to all endpoints simultaneously.
AnswerC

The Distributions view allows administrators to test and schedule controlled upgrades across different endpoint groups.

Why this answer

Upgrades are managed by uploading new agent versions to the console and deploying them via scheduled upgrade tasks in the Distributions view.

150
MCQhard

An administrator configures a decryption policy to 'No Decrypt' for financial institution websites to comply with privacy regulations. However, the firewall is still decrypting traffic to certain banking sites. Upon investigation, the administrator discovers that the firewall is matching a pre-defined PAN-OS SSL Decryption Exclusion list. How can the administrator override or modify this behavior?

A.Delete the pre-defined system files directly from the FreeBSD CLI shell.
B.Change the Application Override policy to drop TLS handshake packets for banking apps.
C.Downgrade the WildFire dynamic content version to remove the hardcoded exclusion database.
D.Create a higher-precedence Decryption rule with action set to 'No Decrypt' and disable the dynamic decryption exclusion list if permitted.
AnswerD

Decryption rules are evaluated top-down. Placing an explicit 'No Decrypt' rule above default or implicit evaluations ensures correct handling.

Why this answer

PAN-OS includes built-in SSL Decryption Exclusions for sensitive sites (e.g., banking, healthcare) maintained by Palo Alto Networks. Administrators can view or manage these exclusions, but cannot directly disable built-in dynamic updates unless specifically configured via Decryption exclusions settings. Specifically, administrators can configure custom Decryption rules with a higher precedence or manage SSL Exclusion settings.

Page 1

Page 2 of 3

Page 3

All pages

Practice Cybersecurity-Practitioner by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →