Courseiva
Back to Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
Cybersecurity-Practitioner
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related Cybersecurity-Practitioner topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

An administrator is configuring security policies on a Palo Alto Networks firewall and wants to ensure best practices for rule organization and management. Which TWO practices are recommended when designing security rules? (Choose two)

Question 2mediummulti select
Read the full DNS explanation →

An administrator is troubleshooting a scenario where internal clients cannot resolve external domain names through the firewall configured as a DNS proxy. Which TWO settings should be verified on the firewall? (Choose two)

Question 3hardmulti select
Full question →

An administrator notices that the firewall's management plane CPU utilization is consistently at 99%. Which THREE factors or troubleshooting steps should the administrator investigate? (Choose three)

Question 4hardmulti select
Full question →

An administrator wants to configure Zone Protection Profiles to safeguard the internal network against common layer 2 and layer 3 attacks. Which THREE attack mitigation features are available within a Zone Protection Profile? (Choose three)

Question 5easymulti select
Full question →

An administrator wants to secure outbound web browsing traffic by inspecting HTTP/HTTPS traffic for malicious URLs, malware, and exploits. Which TWO security profiles should be attached to the Security policy rule to achieve comprehensive protection? (Choose two)

Question 6hardmulti select
Full question →

Which THREE actions are recommended best practices when securing the management plane of a Palo Alto Networks firewall? (Choose three)

Question 7mediummulti select
Full question →

A security analyst is investigating a suspected lateral movement attempt within an enterprise network protected by Palo Alto Networks firewalls. According to the MITRE ATT&CK framework, which TWO of the following techniques are commonly categorized under the Lateral Movement tactic? (Choose two)

Question 8hardmulti select
Full question →

An enterprise security team is reviewing its Zero Trust Architecture deployment to ensure compliance with modern identity and access management standards. Which TWO practices are fundamental requirements of a true Zero Trust identity strategy? (Choose two)

Question 9mediummulti select
Full question →

An administrator wants to configure User-ID mapping sources on a Palo Alto Networks Next-Generation Firewall to identify users behind IP addresses. Which TWO of the following are valid methods supported by PAN-OS for gathering User-ID mappings? (Choose two)

Question 10hardmulti select
Full question →

A security operations team is reviewing MITRE ATT&CK Tactic classifications for an incident involving credential theft and subsequent unauthorized actions on a Palo Alto Networks protected network. Which THREE of the following Tactics fall under the 'Post-Compromise' or later stages of the attack lifecycle? (Choose three)

Question 11mediummulti select
Full question →

A SOC analyst is investigating a suspected Advanced Persistent Threat (APT) group that exhibits classic characteristics during its operation lifecycle. Which THREE traits are typically associated with advanced persistent threat campaigns? (Choose three)

Question 12hardmulti select
Full question →

When mapping adversary behaviors to the MITRE ATT&CK framework within a Cortex XDR incident investigation, an analyst identifies techniques associated with the 'Credential Access' tactic. Which TWO techniques fall under the Credential Access tactic category? (Choose two)

Question 13hardmulti select
Full question →

An organization is analyzing the Cyber Kill Chain framework to improve their defensive posture against advanced persistent threats (APTs). Which THREE phases of the Cyber Kill Chain involve active interaction between the attacker's infrastructure and the internal target enterprise network, where a Palo Alto Networks firewall can detect or disrupt the attack? (Choose three)

Question 14mediummulti select
Full question →

Which TWO methods can be used to authenticate remote users connecting to Prisma Access via GlobalProtect? (Choose two)

Question 15mediummulti select
Full question →

Which TWO metrics or features are provided by Prisma Autonomous DEM (ADEM) to troubleshoot remote user application performance issues? (Choose two)

Question 16hardmulti select
Full question →

An administrator is configuring Prisma Access to secure remote networks and mobile users. Which TWO cloud-delivered security services can be natively integrated into Prisma Access security policies to inspect traffic? (Choose two)

Question 17mediummulti select
Full question →

Which TWO actions can an administrator perform within the Prisma Cloud Cloud Security Posture Management (CSPM) console to remediate misconfigured cloud resources? (Choose two)

Question 18hardmulti select
Full question →

An enterprise security architect is designing a Zero Trust architecture using Palo Alto Networks products. Which THREE foundational principles must be enforced to achieve a true Zero Trust network posture? (Choose three)

Question 19mediummulti select
Full question →

A network security team is configuring URL Filtering profiles to protect users from malicious web content. Which THREE actions can be assigned to specific URL categories within a URL Filtering profile? (Choose three)

Question 20hardmulti select
Full question →

An enterprise is preparing for an external security audit and needs to ensure compliance with risk management frameworks regarding administrative accountability and change control. Which THREE features on a Palo Alto Networks firewall support these compliance requirements? (Choose three)

These Cybersecurity-Practitioner practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style Cybersecurity-Practitioner questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.