Cybersecurity-Practitioner · domain
Cybersecurity Fundamentals
Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) Cybersecurity Fundamentals practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cybersecurity Fundamentals questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cybersecurity Fundamentals
Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Cybersecurity Fundamentals exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Cybersecurity Fundamentals questions (47)
Click any question to see the full explanation, or start a practice session above.
A security operations center (SOC) team wants to reduce alert fatigue by ensuring that low-severity threat events do not inundate their SIEM, while ensuring high-severity exploit attempts trigger immediate escalation. How should the administrator configure the security profiles to manage this?
Easy2An administrator is reviewing firewall high availability (HA) states and configuration parameters. Which TWO settings must be identical on both firewall peers in an HA pair to ensure successful synchronization and cluster formation? (Choose two)
Easy3An enterprise wants to mitigate the risk of credential theft attacks where users type their corporate credentials into known phishing websites. Which Palo Alto Networks feature provides real-time protection against corporate credential phishing?
Medium4During an incident response investigation, a security analyst identifies a novel malware sample that evaded traditional signature-based detection. The security team needs to ensure that the firewall automatically blocks this exact malware variant globally across all deployed Next-Generation Firewalls within minutes without manual signature updates. Which platform component provides this capability?
Hard5A network administrator is troubleshooting why an internal application is unable to communicate with an external API over a non-standard TCP port. The firewall's security policy allows the IP addresses and port, but traffic is being dropped by threat prevention. Upon checking logs, the administrator sees a threat ID associated with a vulnerability signature. What is the most appropriate way to resolve a false positive safely?
Medium6A security administrator is reviewing security policy rules and notices that many rules use 'any' for the application field. According to security best practices and the attack lifecycle, why is allowing 'any' application dangerous?
Easy7A security analyst needs to verify whether a suspicious file hash observed in an external threat report has ever traversed the corporate network or been analyzed by WildFire. Which tool provides the fastest way to search historical WildFire sample analysis results across the entire enterprise?
Easy8A security team is designing a defense-in-depth strategy for lateral movement prevention inside the data center. They decide to deploy internal segmentation firewalls (ISFW). Which core Palo Alto Networks capability enables these firewalls to enforce precise access control between different application tiers inside the same network zone?
Medium9During a simulated phishing exercise, an employee clicks a link in an email that directs them to a credential-harvesting page mimicking the corporate single sign-on portal. According to the common attack lifecycle, which phase immediately follows this successful credential capture?
Hard10A security administrator is reviewing firewall logs and notices multiple outbound connection attempts from a client workstation to known command and control IP addresses. Which security profile component is primarily responsible for generating a threat log entry for this specific outbound traffic?
Easy11An incident responder is investigating a ransomware outbreak on an internal file server. During the analysis, the responder needs to categorize the attack steps using the cyber kill chain framework. Which THREE phases are part of the standard Lockheed Martin cyber kill chain? (Choose three)
Medium12An organization is reviewing its threat intelligence feeds and security posture to prepare for advanced persistent threat (APT) campaigns. Which TWO characteristics are typically associated with advanced persistent threats? (Choose two)
Medium13An enterprise is preparing for an external security audit and needs to ensure compliance with risk management frameworks regarding administrative accountability and change control. Which THREE features on a Palo Alto Networks firewall support these compliance requirements? (Choose three)
Hard14An organization is implementing compliance controls to ensure that employees do not upload proprietary source code to unauthorized cloud storage providers. Which security profile feature should be utilized to control and log specific file transfers within recognized cloud applications?
Medium15A security architect is designing a Zero Trust network where users must authenticate before accessing any internal application. However, legacy internal applications do not support modern identity federation protocols. Which Palo Alto Networks feature can be deployed to front-end these legacy applications and enforce authentication and access control without modifying the legacy applications?
Hard16An organization is updating its enterprise risk management framework to align with NIST SP 800-30 guidelines. The security team needs to prioritize mitigation efforts for a newly discovered vulnerability in a critical database. Which combination of factors must the team evaluate to determine the overall risk level?
Hard17An enterprise environment experiences a sophisticated zero-day attack where a custom malware binary is downloaded via HTTPS. Decryption is enabled on the firewall. For WildFire to successfully analyze this file, which specific configuration requirement must be met within the Security policy and WildFire analysis profile?
Hard18A security administrator is configuring User-ID to enforce identity-based security policies. Which TWO methods can the Palo Alto Networks firewall use to map IP addresses to usernames in an enterprise environment? (Choose two)
Medium19An attacker performs a reconnaissance scan against an enterprise perimeter using TCP SYN packets with randomized source ports and IP addresses to map active hosts. Which Palo Alto Networks feature is specifically designed to mitigate this type of volumetric reconnaissance and connection exhaustion attack at the ingress interface?
Hard20During an investigation of a compromised endpoint, an analyst needs to trace all network connections initiated by that specific host over the past 30 days, including the applications used, bytes transferred, and threat logs generated. Which Palo Alto Networks logging and visualization tool provides a consolidated session explorer view for this forensic analysis?
Hard21An enterprise is conducting a threat modeling exercise and evaluating risks associated with encrypted traffic. Which THREE security challenges are introduced when SSL/TLS encryption is enabled without decryption policies on the firewall? (Choose three)
Hard22A network security engineer is configuring a security policy rule and notices that the security profile attachment area shows options for Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, Data Filtering, and WildFire Analysis. What is the collective term for these configurable security inspection modules?
Easy23A security analyst wants to evaluate the organization's current threat exposure and understand the tactics, techniques, and procedures (TTPs) used by threat actors targeting their specific industry sector. Which Palo Alto Networks tool or feature should the analyst consult for contextual threat hunting and intelligence research?
Easy24An enterprise is deploying a Zero Trust network model where all traffic must be inspected, authenticated, and authorized. An auditor asks how the organization ensures that unmanaged BYOD devices do not connect to sensitive internal database zones even if they authenticate successfully. Which feature combination enforces this posture check?
Hard25An organization is adopting a Zero Trust architecture. During the implementation of Least Privilege Access, the network security team needs to configure security policies that restrict traffic based on user identity rather than IP addresses alone. Which feature must be enabled and integrated with the Palo Alto Networks firewall to achieve this?
Medium26A security operations team is reviewing firewall traffic logs. Which TWO key pieces of information does the App-ID engine provide for every recognized session? (Choose two)
Easy27An enterprise network runs custom internal applications that utilize non-standard encryption protocols. To maintain visibility without breaking application functionality, the security team needs to deploy decryption. Which type of decryption should be configured if the firewall does not possess the private keys of the internal servers, but internal clients trust the firewall's forward proxy certificate?
Hard28A security operations team is implementing zero trust network access (ZTNA) principles across the enterprise. According to foundational Zero Trust architecture guidelines, which THREE tenets must be enforced? (Choose three)
Hard29A security architect is designing high availability (HA) for a pair of Palo Alto Networks firewalls to ensure business continuity during hardware failures. Which HA operational mode ensures that both firewalls actively process traffic and synchronize session tables in real-time?
Medium30An enterprise security architect is designing a defense-in-depth strategy using Palo Alto Networks Panorama and Next-Generation Firewalls. Which implementation best exemplifies the defense-in-depth security principle?
Medium31A network security team is configuring URL Filtering profiles to protect users from malicious web content. Which THREE actions can be assigned to specific URL categories within a URL Filtering profile? (Choose three)
Medium32A security analyst is investigating common cyber threats targeting web applications. Which TWO threats are classified as web-based injection or application-layer attacks that can be mitigated by security profiles on a next-generation firewall? (Choose two)
Easy33A company's risk management framework requires multi-factor authentication (MFA) for all remote access connections. The organization utilizes GlobalProtect for remote workers. Where should the administrator configure the authentication profile to enforce MFA during the GlobalProtect connection phase?
Medium34A security administrator is configuring a WildFire analysis profile to protect the network from zero-day malware. Which THREE actions can be configured within a WildFire analysis profile when an unknown file is inspected? (Choose three)
Medium35An enterprise security architect is designing a Zero Trust architecture using Palo Alto Networks products. Which THREE foundational principles must be enforced to achieve a true Zero Trust network posture? (Choose three)
Hard36An administrator is configuring security profiles on a Palo Alto Networks Next-Generation Firewall to mitigate potential data exfiltration attempts. To best adhere to the principle of least privilege regarding outbound traffic, which action should the administrator take?
Medium37A network engineer is configuring a Palo Alto Networks firewall and wants to ensure that internal hosts cannot resolve malicious domains known to host malware delivery mechanisms. Which security profile should be configured and attached to the security rule?
Medium38A security analyst is investigating a security alert generated by the firewall indicating potential data exfiltration. Which security profile should the analyst inspect and tune to detect and prevent sensitive information, such as credit card numbers, from leaving the network?
Easy39During an incident response investigation using Palo Alto Networks Cortex XDR, an analyst identifies an endpoint exhibiting unusual outbound connections to a known command and control IP address. According to the cyber kill chain model, at which phase is this threat actor currently operating?
Easy40An organization is analyzing the Cyber Kill Chain framework to improve their defensive posture against advanced persistent threats (APTs). Which THREE phases of the Cyber Kill Chain involve active interaction between the attacker's infrastructure and the internal target enterprise network, where a Palo Alto Networks firewall can detect or disrupt the attack? (Choose three)
Hard41An organization is subjected to a distributed denial-of-service (DDoS) attack involving HTTP GET floods targeting their public-facing web server. The firewall is deployed inline. Which specific platform capability should be tuned to mitigate this application-layer attack without blocking legitimate users?
Hard42An organization is implementing a defense-in-depth security model using a Palo Alto Networks Next-Generation Firewall. Which TWO security profile types should be deployed to inspect content payloads for known malware and software exploit attempts? (Choose two)
Easy43During a risk assessment, a security auditor notes that administrator accounts share a single generic login on the firewall. The auditor recommends implementing Role-Based Access Control (RBAC) and individual administrator accounts. Which Palo Alto Networks feature supports granular administration controls and authentication integration?
Easy44A security analyst is reviewing alerts generated by Palo Alto Networks WildFire. An unknown executable file was uploaded, analyzed in the sandbox, and determined to exhibit malicious behavior such as registry modification and process injection. What type of threat analysis is WildFire primarily performing in this scenario?
Easy45A security team is implementing risk management practices by securing the firewall management plane. Which THREE best practices should be implemented to protect the management interface from unauthorized access? (Choose three)
Medium46An organization's security policy mandates that all software vulnerabilities with a CVSS score above 7.0 must be blocked at the network perimeter within 24 hours of disclosure. A new zero-day vulnerability is announced. While awaiting vendor patches, how can a Palo Alto Networks administrator immediately mitigate this threat using built-in platform features?
Hard47An organization's security policy requires that any detected malware file must be automatically blocked from entering the network during download. Which security profile and action combination ensures inline prevention against known malware?
MediumOther domains
All Cybersecurity-Practitioner exam domains
Frequently asked questions
- What does the Cybersecurity Fundamentals domain cover on the Cybersecurity-Practitioner exam?
- Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 47 Cybersecurity Fundamentals questions in the Cybersecurity-Practitioner question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cybersecurity Fundamentals questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.