Cybersecurity-Practitioner · domain
Endpoint Security
Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) Endpoint Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Endpoint Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Endpoint Security
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).
SLAAC vs DHCPv6 vs stateful assignment.
Neighbor Discovery Protocol replacing ARP.
IPv6 routing differences and dual-stack coexistence.
Watch out for
Common Endpoint Security exam traps
- ▸Link-local addresses are not routable beyond the local link.
- ▸SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
- ▸NDP uses ICMPv6, not ARP.
- ▸An IPv6 prefix is /64 for most host subnets, not /24.
Question index
All Endpoint Security questions (36)
Click any question to see the full explanation, or start a practice session above.
Which TWO pieces of information are displayed in the Cortex XDR Endpoint Management inventory table for a managed agent? (Choose two)
Medium2Where in the Cortex XDR management console can an administrator view the operational health, connection status, and version of all deployed agents?
Easy3An organization deploys Cortex XDR disk encryption management. An endpoint fails to escrow its BitLocker recovery key to the Cortex XDR console. What is the most effective troubleshooting step to verify escrow status using the agent command-line tool?
Hard4An enterprise security team discovers that a custom line-of-business application is triggering a Behavioral Threat Protection (BTP) alert in Cortex XDR. The behavior involves unusual process injection techniques that are legitimate for this application. How can the administrator suppress this specific alert without disabling BTP for other applications?
Hard5Which TWO methods can be utilized to distribute Cortex XDR agent installation packages across an enterprise Windows environment? (Choose two)
Hard6An administrator needs to temporarily disable the Cortex XDR agent on an endpoint for troubleshooting purposes. What mechanism is used to authorize this action locally using the command line?
Easy7An administrator needs to run a live forensic artifact collection on a suspected compromised endpoint using Cortex XDR. Which capability allows the administrator to execute scripts and retrieve files directly from the endpoint in real time?
Medium8Which THREE diagnostic or troubleshooting steps can be performed using the 'cytool' command-line utility on a local endpoint? (Choose three)
Medium9An administrator is configuring disk encryption management in Cortex XDR for macOS endpoints. Which underlying native macOS technology does Cortex XDR manage and report on for disk encryption?
Hard10An organization requires compliance reporting showing that all endpoints are actively protected by Cortex XDR modules (Anti-Malware, Exploit Prevention, Behavioral Threat Protection). Where can an administrator generate this comprehensive compliance report in the Cortex XDR management console?
Hard11An administrator wants to configure the frequency at which the Cortex XDR agent checks in with the management server. Where is this heartbeat interval configured?
Easy12An endpoint has been flagged in Cortex XDR with multiple high-severity alerts. The security operations team decides to isolate the endpoint immediately to prevent lateral movement. Which network traffic remains permitted by default when an endpoint is placed in isolation mode in Cortex XDR?
Medium13An administrator is reviewing endpoint security profiles and notices the term 'BIOC'. What does BIOC stand for in the context of Cortex XDR?
Easy14A security analyst wants to configure a custom alert rule in Cortex XDR that triggers whenever a specific command-line pattern is observed across multiple endpoints. Which feature should the analyst use to create this behavioral alert?
Medium15Which THREE conditions or indicators typically trigger an automated endpoint isolation action in Cortex XDR? (Choose three)
Hard16Which TWO platforms are officially supported for deploying the Cortex XDR Agent? (Choose two)
Easy17Which THREE mechanisms are employed by Cortex XDR to protect endpoints against unknown zero-day file-based malware? (Choose three)
Hard18An administrator is deploying Cortex XDR Agent to Windows workstations using an Active Directory Group Policy Object (GPO). Which installation parameter must be used to ensure the agent registers correctly with the assigned Cortex XDR tenant using a specific installation token?
Easy19A security analyst notices that WildFire has successfully analyzed a suspicious file uploaded from an endpoint, but the local Cortex XDR agent did not automatically block it upon first encounter. What is the most likely explanation for this behavior?
Medium20Which THREE parameters or settings can be configured within a Cortex XDR Agent Settings profile? (Choose three)
Easy21Which THREE types of data are gathered and ingested by Cortex XDR to provide comprehensive endpoint visibility? (Choose three)
Easy22An organization is configuring exploit prevention rules in Cortex XDR to protect legacy browser plugins. An application crashes repeatedly due to an overly aggressive protection profile. Which action should the administrator take to troubleshoot without completely disabling exploit protection?
Hard23An administrator is preparing to deploy Cortex XDR agents to 500 remote endpoints using a software deployment tool. Where can the administrator download the latest installation packages and transforms?
Easy24Which TWO actions should an administrator take when a legitimate software application is falsely blocked by Cortex XDR Behavioral Threat Protection (BTP)? (Choose two)
Hard25Which THREE security modules are included as core components of the Cortex XDR agent architecture? (Choose three)
Medium26A security analyst is investigating a threat where a legitimate administrative tool (Living off the Land) was used maliciously. Cortex XDR generated an alert via Local Analysis. Which mechanism powers the Local Analysis engine to detect this type of threat without requiring an internet connection?
Medium27A security analyst notices that a benign internal software development tool is being incorrectly blocked by Cortex XDR Prevent as malware. What is the most granular method to whitelist this application while maintaining maximum security posture?
Medium28An administrator wants to ensure that end users cannot tamper with or uninstall the Cortex XDR agent from their workstations. Which feature provides this protection?
Easy29An organization requires that Cortex XDR agents verify their connection to the Cortex XDR server through a corporate HTTP proxy. Where is the proxy configuration defined for the Cortex XDR agent?
Medium30An administrator needs to upgrade Cortex XDR agents across a large enterprise environment. To minimize network congestion and control the rollout, how should the administrator manage the upgrade process?
Hard31An administrator needs to verify that the Cortex XDR agent services are running properly on a macOS endpoint. Which command-line utility should be used to check the agent status?
Easy32Which TWO tasks are required when preparing to deploy Cortex XDR agents using an installation token? (Choose two)
Medium33An administrator observes that several Cortex XDR agents are showing a 'Disconnected' status in the management console. After verifying network connectivity, the administrator suspects that communication is blocked by an intermediate firewall. Which TCP port must be open outbound from the endpoints to the Cortex XDR server?
Medium34Which TWO actions can be performed directly from the Cortex XDR management console on a compromised endpoint? (Choose two)
Easy35An endpoint running the Cortex XDR Agent is experiencing aggressive behavior isolation triggered by a confirmed ransomware attack. The administrator successfully remediates the threat and verifies the endpoint is clean. How should the administrator restore network connectivity to the isolated endpoint from the Cortex XDR management console?
Hard36An administrator is troubleshooting an issue where Cortex XDR agent logs need to be gathered and submitted to Palo Alto Networks Support. Which command generates a complete support file package (often referred to as 'collector') containing all necessary logs and debug data?
HardOther domains
All Cybersecurity-Practitioner exam domains
Frequently asked questions
- What does the Endpoint Security domain cover on the Cybersecurity-Practitioner exam?
- IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
- How many questions are in this domain?
- This page lists all 36 Endpoint Security questions in the Cybersecurity-Practitioner question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Endpoint Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.