Courseiva

Cybersecurity-Apprentice · topic practice

Cybersecurity Fundamentals practice questions

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Cybersecurity Fundamentals practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Cybersecurity Fundamentals

What the exam tests

What to know about Cybersecurity Fundamentals

Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Cybersecurity Fundamentals exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Cybersecurity Fundamentals questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Open the full VLAN trunking answer →

An organization wants to enforce zero trust principles by inspecting all internal east-west traffic between different VLANs terminating on a Palo Alto Networks Next-Generation Firewall. The firewall is currently running in Layer 3 mode. Which configuration step is essential to ensure that inter-VLAN traffic passes through the security inspection engine rather than routing directly through an upstream core switch?

An administrator is configuring SSL Decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. Users in the Finance department must be excluded from decryption when accessing banking websites due to strict privacy regulations. How should the administrator configure the Decryption policy to achieve this securely?

A security analyst is reviewing a high-severity threat alert on a Palo Alto Networks firewall indicating a potential credential theft attempt. The security profile attached to the rule is configured with a custom URL Filtering profile. Which specific action must be enabled within the URL Filtering profile to proactively block users from submitting their enterprise credentials to phishing sites?

Question 4mediummultiple choice
Read the full NAT/PAT explanation →

A security operations engineer is troubleshooting a firewall policy issue where internal users cannot reach a newly deployed public web server hosted in the DMZ. The administrator verifies that the destination NAT rule is translating the public IP to the private server IP correctly. What is the most likely reason the traffic is still being blocked?

An administrator notices that a newly installed application is being categorized as 'unknown-tcp' by the firewall. What is the recommended next step to safely manage and identify this traffic using Palo Alto Networks best practices?

An administrator is reviewing firewall logs and notices a security rule using the application 'ssl' is matching significant traffic. However, organization policy mandates that all applications must be precisely identified. Why is the firewall classifying traffic simply as 'ssl' instead of specific applications like 'office365-base'?

An organization has deployed a multi-tenant Palo Alto Networks firewall using virtual systems (vsys). An administrator in vsys1 needs to reference a security object (such as an address object) created by the root administrator. How can this address object be made available to vsys1 without recreating it?

An architect is designing a high-availability (HA) pair of Palo Alto Networks firewalls in Active/Passive mode. During a link failure on the active firewall's primary internal interface, the firewalls fail over successfully, but sessions are immediately dropped on the new active firewall. What configuration setting should be verified to ensure seamless session failover?

Question 9hardmultiple choice
Read the full VPN explanation →

An organization is implementing a Zero Trust Network Access (ZTNA) model using GlobalProtect and Palo Alto Networks firewalls. A security auditor notes that authenticated users can access any internal server once connected to the VPN gateway. Which configuration change is required to enforce strict Zero Trust segmentation for remote users?

An administrator is troubleshooting high CPU utilization on the management plane of a Palo Alto Networks firewall. Which command executed via the CLI can help identify which processes are consuming management plane resources?

Question 11hardmultiple choice
Review the full routing breakdown →

An auditor is reviewing an organization's network segmentation and points out that management traffic (SSH, HTTPS to the firewall) traverses the same physical interface and routing table as untrusted user traffic. Which Palo Alto Networks best practice should be implemented to secure management access?

An administrator is configuring a Panorama template stack to manage multiple firewalls. A specific setting must be configured differently on one firewall compared to the rest of the stack. How should the administrator handle this requirement without breaking template inheritance?

Question 13hardmultiple choice
Open the full BGP breakdown →

An enterprise security architect is designing a high-security network architecture where firewalls are deployed in a cluster to inspect traffic between AWS VPCs. The architecture requires dynamic routing support for thousands of routes without maintaining traditional BGP peering complexity on every firewall. Which Palo Alto Networks feature supports dynamic cloud route updates and integration with cloud orchestrators?

An organization is utilizing Palo Alto Networks Prisma Access for secure remote network and user access. An administrator needs to ensure that branch offices connecting via Prisma Access Remote Networks can communicate securely with each other without backhauling traffic through a central hub. Which Prisma Access feature enables this direct communication?

A security engineer is configuring User-ID on a Palo Alto Networks firewall to ensure granular security policies can be enforced based on Active Directory group membership. Which TWO methods can the firewall use to map IP addresses to usernames? (Choose two)

An administrator is troubleshooting an issue where specific applications are failing to pass through a Palo Alto Networks firewall. Panorama and firewall logs show 'nolog' or dropped packets due to security policy denials. Which THREE CLI commands are most useful for diagnosing policy evaluation and traffic flow issues? (Choose three)

An administrator is managing firewall configurations across a large enterprise using Panorama. Which TWO configuration components are typically managed at the Panorama template level rather than the device group level? (Choose two)

An enterprise security architect is reviewing the network design for a multi-tenant cloud environment protected by VM-Series firewalls. Which THREE design considerations are critical for maintaining high availability and resilience in a cloud deployment? (Choose three)

A security architect is designing a multi-tenant cloud environment protected by VM-Series firewalls. To enforce strict segmentation between tenant zones that share the same physical interface, which core Palo Alto Networks feature must be configured first?

An administrator is troubleshooting an issue where internal users cannot access an external website utilizing a newly issued SSL certificate signed by an internal enterprise Certificate Authority (CA). The firewall's Forward Trust Certificate is not trusted by the client endpoint. What is the root cause of this browser warning?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cybersecurity Fundamentals sessions

Start a Cybersecurity Fundamentals only practice session

Every question in these sessions is drawn from the Cybersecurity Fundamentals domain — nothing else.

Related practice questions

Related Cybersecurity-Apprentice topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Cybersecurity-Apprentice exam test about Cybersecurity Fundamentals?
Cybersecurity Fundamentals questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cybersecurity Fundamentals questions in a focused session?
Yes — the session launcher on this page draws every question from the Cybersecurity Fundamentals domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Cybersecurity-Apprentice topics?
Use the topic links above to move to related areas, or go back to the Cybersecurity-Apprentice question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Cybersecurity-Apprentice exam covers. They are not copied from any real exam or dump site.