Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks Apprentice Palo Alto Networks Cybersecurity Apprentice Exam Practice Test

Demo: 34 questions
Total 115 questions

Palo Alto Networks Cybersecurity Apprentice Questions and Answers

Question 1

What are two components of a cloud-native security platform (CNSP)? (Choose two.)

Options:

A.

Asset inventory

B.

VPN

C.

Endpoint security

D.

Identity and access management (IAM)

Question 2

Which segmentation method will limit the number of devices that can be granted a private IP address in a network?

Options:

A.

NAT

B.

Static routing

C.

IP subnetting

D.

VLAN

Question 3

Which statement best distinguishes a Host-Based Intrusion Detection System (HIDS) from a Network-Based Intrusion Detection System (NIDS)?

Options:

A.

Network-Based is installed on an individual endpoint to monitor all inbound/outbound traffic of that device.

B.

Host-Based is installed on an individual endpoint to monitor all inbound/outbound traffic of that traffic.

C.

Host-Based directly integrates with the endpoint and is known as the last line of defense.

D.

Network-Based directly integrates with the endpoint and is known as the last line of defense.

Question 4

Which activity increases the ability of endpoint protection to successfully identify threats?

Options:

A.

Creating honeypots

B.

Implementing virtualization

C.

Encoding null routes

D.

Applying security updates

Question 5

Which two sets of actions are examples of multi-factor authentication (MFA)? (Choose two.)

Options:

A.

Answering a security question and providing a thumbprint

B.

Entering a PIN and scanning a smart card

C.

Scanning the palm of one hand followed by the other hand

D.

Answering three sequential security questions

Question 6

In which use case would URL filtering be an appropriate solution?

Options:

A.

Redirecting malicious DNS traffic to a sinkhole

B.

Blocking large file transfers over a network

C.

Preventing employees from accessing social media sites during work hours

D.

Encrypting outgoing emails containing confidential information

Question 7

Which statement describes both stateful firewalls and stateless firewalls?

Options:

A.

Stateful firewalls encrypt all traffic they inspect; stateless firewalls only pass through unencrypted traffic.

B.

Stateful firewalls are primary hardware appliances; stateless firewalls are exclusively software-based.

C.

Stateful firewalls only allow access to internal applications; stateless firewalls allow connections only to the internet.

D.

Stateful firewalls track and secure ongoing connections; stateless firewalls inspect each packet individually.

Question 8

What will secure connections from a company’s remote employees when they want to access sensitive documents at a branch office?

Options:

A.

Public FTP servers using RADIUS authentication

B.

VPN clients on compatible devices

C.

Attachments transferred via unsecured email

D.

Websites using steganography

Question 9

A VPN is used for which purpose?

Options:

A.

Site-to-site connectivity being secured

B.

IP addressing being requested by a device

C.

Packets being arranged in the correct order

D.

Virtual machines (VMs) being created

Question 10

What will cause an unusually high number of false positive alerts?

Options:

A.

Post-breach recovery plan is well defined.

B.

User privilege is configured to be strict.

C.

Device is unable to receive an IP address.

D.

Traffic match criteria is too generalized.

Question 11

Which stage of the cyber attack lifecycle is characterized by attackers passing instructions back and forth between infected devices and their own infrastructure?

Options:

A.

Command and Control (C2)

B.

Weaponization and Delivery

C.

Exploitation

D.

Reconnaissance

Question 12

How does antivirus software contribute to endpoint security?

Options:

A.

By enforcing strong password security policies for user account access

B.

By filtering unsolicited commercial email from a user’s inbox

C.

By scanning files and programs for known malware signatures

D.

By creating secure, isolated environments for untested applications

Question 13

What is an example of an exploit?

Options:

A.

Misconfigured access control

B.

Unpatched software

C.

Buffer overflow attack

D.

Exposed password

Question 14

Which attack takes place in the Exploitation phase of the cyber attack lifecycle?

Options:

A.

Weaponized PDF file executing on a target

B.

Malicious phishing link sent to a target

C.

Polymorphic malware altering its structure on a target after gaining access

D.

Undisclosed software vulnerability used to gain remote access to a target

Question 15

What is the purpose of continuous deployment in the CI/CD lifecycle?

Options:

A.

Maintaining a state in which any version of the software can be deployed to a production environment.

B.

Merging code changes into a central repository

C.

Packaging code into a Docker container for deployment

D.

Automatically deploying every change that passes the automated tests to production, minimizing lead time

Question 16

Which device operates at OSI Layer 2?

Options:

A.

Hub

B.

Switch

C.

Router

D.

Modem

Question 17

What is a result of the Actions on the Objective phase in the cyber attack lifecycle?

Options:

A.

Host sweeps and port scans are performed.

B.

Outbound communication channels are established.

C.

Data is exfiltrated and web property is defaced.

D.

Exploits are launched against a vulnerable application.

Question 18

A data center needs to secure its infrastructure from network-based threats. Which two technologies will address this need? (Choose two.)

Options:

A.

Next-generation firewall

B.

Intrusion prevention system (IPS)

C.

Intrusion detection system (IDS)

D.

Proxy

Question 19

Which event would generate a false positive alert?

Options:

A.

A firewall categorizes a benign application as malicious.

B.

A network sensor is unable to identify a custom application.

C.

A network tunnel accidentally switches from one route to another.

D.

An employee attempts to access an unauthorized application.

Question 20

What are two endpoint security implementation methods? (Choose two.)

Options:

A.

Installing an anti-malware agent onto a user device

B.

Deploying a firewall to prevent traffic from reaching an end user

C.

Enforcing security policies on north-south traffic between users and the internet

D.

Downloading software onto a laptop to prevent spyware

Question 21

What occurs in the reconnaissance stage of the cyber attack lifecycle?

Options:

A.

File exfiltration

B.

SQL injection

C.

Host sweep

D.

Phishing campaign

Question 22

What is the primary goal of the Weaponization and Delivery stage in the cyber attack lifecycle?

Options:

A.

Developing and testing malware for bypassing defenses

B.

Ensuring compliance with Security policies

C.

Distributing compromised hardware to targets

D.

Creating a malicious payload by using vulnerabilities

Question 23

Which protocol uses encryption to secure its communications?

Options:

A.

Telnet

B.

SSH

C.

NAT

D.

DHCP

Question 24

What is the fundamental role of a proxy server in internet communication?

Options:

A.

Enhancing the processing power of a user device when accessing internet.

B.

Managing and securing email communications.

C.

Acting as an intermediary, routing traffic between users and online resources.

D.

Directly connecting endpoint agents to web servers.

Question 25

What are two functions of VPN gateways? (Choose two.)

Options:

A.

Certificate refresh

B.

Site-to-Site connectivity

C.

Remote access

D.

URL filtering

Question 26

Which cloud service model allows a third-party provider to host an application that is readily available for customer use?

Options:

A.

Software as a service (SaaS)

B.

Platform as a service (PaaS)

C.

Desktop as a service (DaaS)

D.

Infrastructure as a service (IaaS)

Question 27

Which function is a part of security operations?

Options:

A.

Migrate

B.

Eliminate

C.

Mitigate

D.

Orchestrate

Question 28

Which stage of the cyber attack lifecycle is characterized by an attacker passing instructions back and forth between infected devices and their own infrastructure?

Options:

A.

Command-and-control (C2)

B.

Exploitation

C.

Reconnaissance

D.

Weaponization and Delivery

Question 29

Which cloud computing model is appropriate for a company that requires an isolated environment which meets strict compliance requirements and maintains enhanced security?

Options:

A.

Hybrid

B.

Private

C.

Public

D.

Community

Question 30

Which cloud computing model allows a single organization to keep its data in a private environment but also access the scalability and cost-effectiveness of public resources?

Options:

A.

Hybrid

B.

Public

C.

Community

D.

Private

Question 31

What is an effective use case of URL filtering?

Options:

A.

Monitoring threat logs and traffic logs

B.

Restricting access to phishing websites

C.

Acting as a sandbox for potentially malicious files

D.

Discovering internet of things (IoT) devices

Question 32

Which duties are part of a triage analyst role in security operations?

Options:

A.

Proactively hunting for threats, vulnerabilities, and exploits

B.

Supporting only the most complex incident responses and reviewing forensic and telemetry data for threats

C.

Providing detailed threat intelligence reports and recommendations for remediation

D.

Identifying the source, scope, and impact of an incident

Question 33

Why would an organization implement a demilitarized zone (DMZ)?

Options:

A.

To provision multiple external zones that allow for destination NAT

B.

To facilitate the use of SD-WAN departments within an organization

C.

To allow effective communications with other organizations

D.

To protect internal resources while still allowing access to public-facing internet services

Question 34

What is a cluster in relation to cloud-native security?

Options:

A.

Portable and self-sufficient unit that packages an application with its dependencies

B.

Set of system rules written in a particular programming language

C.

Collection of nodes (bare-metal or virtualized machines) that will host application pods

D.

Distributed collection of servers that hosts software and is accessible over the internet

Demo: 34 questions
Total 115 questions