Courseiva

Cybersecurity-Apprentice · topic practice

Endpoint Security practice questions

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Endpoint Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Endpoint Security

What the exam tests

What to know about Endpoint Security

IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.

IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).

SLAAC vs DHCPv6 vs stateful assignment.

Neighbor Discovery Protocol replacing ARP.

IPv6 routing differences and dual-stack coexistence.

Watch out for

Common Endpoint Security exam traps

  • Link-local addresses are not routable beyond the local link.
  • SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
  • NDP uses ICMPv6, not ARP.
  • An IPv6 prefix is /64 for most host subnets, not /24.

Practice set

Endpoint Security questions

20 questions · select your answer, then reveal the explanation

An endpoint has been isolated via the Cortex XDR console due to a suspected ransomware outbreak. The incident responder needs to allow one specific management server to communicate with this isolated endpoint for forensics collection. What is the correct procedure?

An administrator is deploying Cortex XDR agent to corporate Windows endpoints and needs to ensure that the agent runs in full prevention mode without user intervention. Which configuration setting in the installation profile must be verified?

A security analyst is investigating a polymorphic malware sample that attempts to inject code into legitimate Windows processes (Process Injection). Which Cortex XDR protection module is primarily responsible for detecting and blocking this technique?

A security analyst notices that a specific PowerShell script is being blocked on an endpoint by Cortex XDR behavioral threat protection. However, the development team confirms the script is legitimate. Where should the analyst create an exception to allow this specific script execution while maintaining behavioral monitoring?

An organization wants to verify that the Cortex XDR agent is actively communicating with the Cortex XDR cloud tenant. Which status indicator should the administrator look for in the Endpoint Management view?

An endpoint generates an alert indicating that a known malicious file was detected and quarantined by the Cortex XDR agent. Where can the administrator review details about this quarantine action?

An administrator needs to deploy Cortex XDR agents across a large enterprise using an Active Directory Group Policy Object (GPO). The installation fails on Windows endpoints with an error indicating missing prerequisites. What must be verified first?

An endpoint user reports that a legitimate internal application is failing to run because the Cortex XDR agent flags its behavior as suspicious. The administrator wants to collect forensic data specifically for this application to analyze its behavior. Which Cortex XDR feature should be enabled?

An administrator is troubleshooting a Cortex XDR agent that has stopped reporting to the management console. The local agent service is running, but network traces show TLS handshake failures with the Cortex XDR server. What is the most likely cause?

What is the primary function of WildFire integration within the Cortex XDR ecosystem?

Question 11mediummultiple choice
Read the full Endpoint Security explanation →

An endpoint running macOS encounters a kernel extension loading blockage when installing the Cortex XDR agent. What action must the administrator take to resolve this?

An organization's security policy requires all endpoint security logs to be forwarded to a centralized SIEM in real time. How does Cortex XDR support this requirement?

Which component of the Cortex XDR architecture provides continuous endpoint data collection and threat prevention directly on the host operating system?

Question 14mediummultiple choice
Read the full Endpoint Security explanation →

An administrator wants to prevent users from tampering with or uninstalling the Cortex XDR agent on Windows workstations. Which feature must be configured in the agent settings?

An endpoint experiences a zero-day fileless attack where shellcode is executed directly in memory via a vulnerable service. Which Cortex XDR protection feature is specifically designed to detect and block this type of attack prior to file drop?

An administrator needs to upgrade Cortex XDR agents across all enterprise endpoints. What is the recommended method in the Cortex XDR management console?

An endpoint has been compromised by an advanced persistent threat (APT). The incident response team needs to reconstruct the entire attack lifecycle, showing how the initial access led to lateral movement and persistence. Which Cortex XDR feature provides this visualization?

Question 18mediummultiple choice
Read the full Endpoint Security explanation →

A security analyst is reviewing a BIOC (Behavioral Indicator of Compromise) alert in the Cortex XDR incident view. What distinguishes a BIOC alert from a standard malware alert?

Which TWO actions can an administrator perform from the Cortex XDR management console when responding to an active endpoint security incident? (Choose two)

An enterprise environment contains legacy Windows servers that cannot support the latest Cortex XDR agent version due to OS limitations. How does Cortex XDR handle protection for these older operating systems?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Endpoint Security sessions

Start a Endpoint Security only practice session

Every question in these sessions is drawn from the Endpoint Security domain — nothing else.

Related practice questions

Related Cybersecurity-Apprentice topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Cybersecurity-Apprentice exam test about Endpoint Security?
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Endpoint Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Endpoint Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Cybersecurity-Apprentice topics?
Use the topic links above to move to related areas, or go back to the Cybersecurity-Apprentice question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Cybersecurity-Apprentice exam covers. They are not copied from any real exam or dump site.