PCCP Practice Questions
Prepare for PCCP with more than an answer.
- Exam fee
- $150 USD
- Level
- Foundational
- Valid for
- 2 years
Domains covered on the exam 6
- Cybersecurity19%
- Network Security19%
- Secure Access14%
- Cloud Security20%
- Endpoint Security15%
- Security Operations13%
- 1
Which statement accurately describes the relationship between Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR)?
Show answer details
Correct answer: C
XDR expands upon the capabilities of EDR. While EDR is focused on collecting and analyzing data from endpoints, XDR extends this visibility by ingesting and correlating data from additional sources like network, cloud, email, and identity. This provides a more comprehensive view of an attack chain and enables a more unified response.
- 2
A network administrator is configuring an NGFW to inspect encrypted web traffic for threats. What technology must be implemented on the firewall to achieve this?
sequenceDiagram participant Client participant NGFW as Next-Gen Firewall participant WebServer as Malicious Web Server Client->>NGFW: TLS Handshake (ClientHello) NGFW->>WebServer: TLS Handshake (forwarding ClientHello) WebServer-->>NGFW: TLS Handshake (ServerHello, Certificate) Note over NGFW: Intercept & Re-sign Certificate NGFW-->>Client: TLS Handshake (ServerHello, Re-signed Cert) Client->>NGFW: Encrypted HTTPS Traffic Note over NGFW: Decrypt, Inspect, Re-encrypt NGFW->>WebServer: Encrypted HTTPS TrafficShow answer details
Correct answer: B
To inspect the contents of encrypted traffic, the firewall must be able to decrypt it. SSL/TLS Decryption (also known as a forward proxy or man-in-the-middle decryption) allows the NGFW to intercept the TLS handshake, decrypt the traffic, inspect it for threats using services like IPS and threat prevention, and then re-encrypt it before forwarding it to the destination.
- 3
A healthcare provider is required by HIPAA to protect patient data (ePHI) stored in their public cloud environment. An audit reveals that several cloud storage buckets are publicly accessible and unencrypted. Which two specific cloud security challenges does this situation represent? (Select TWO)
Show answer details
Correct answer: C, D
Cloud Posture Security deals with the configuration and compliance of cloud resources. Publicly accessible and unencrypted storage buckets are classic examples of misconfigurations that weaken the security posture and lead to compliance violations.
The core issue is the potential exposure of sensitive patient data (ePHI). This falls directly under the challenge of Data Security, which encompasses ensuring the confidentiality, integrity, and availability of data stored in the cloud through measures like access control and encryption.
- 4
Which Cortex solution provides a proactive approach to security by continuously discovering, mapping, and monitoring an organization's external internet-facing assets?
Show answer details
Correct answer: D
Cortex Xpanse is Palo Alto Networks' Attack Surface Management (ASM) solution. It is designed to provide an outside-in view of an organization's internet presence, discovering all known and unknown assets to identify potential exposures and security risks before attackers can exploit them.
- 5
What is the primary function of an Identity Provider (IdP) within an authentication, authorization, and accounting (AAA) framework?
Show answer details
Correct answer: B
An Identity Provider (IdP) is the system of record that manages digital identities and credentials. Its core function is to authenticate users, verifying that they are who they claim to be, before passing that authentication assertion to a service provider (SP) that will then handle authorization.
- 6
A SOC analyst is investigating an alert from Cortex XDR that suggests a fileless malware attack on a critical server. The initial investigation reveals a suspicious PowerShell process that was spawned by a legitimate application. Which Zero Trust principle is most directly challenged by this type of attack?
Show answer details
Correct answer: B
Fileless malware operates by using legitimate, trusted processes (living-off-the-land techniques). While least privilege is important, the core issue is that a seemingly valid process is performing malicious actions. Continuous monitoring and validation is the principle designed to detect such anomalous behavior from otherwise trusted entities, making it the most directly challenged principle.
- 7
A manufacturing company is implementing network security for its Operational Technology (OT) environment. The primary concern is preventing malware from spreading from the corporate IT network to the sensitive industrial control systems (ICS). Which network security technology is specifically designed to control traffic flow and enforce granular policies between different network segments like IT and OT?
Show answer details
Correct answer: C
Microsegmentation is the practice of dividing a network into smaller, isolated segments to limit the lateral movement of threats. In an IT/OT environment, it is crucial for creating a secure boundary and applying strict access controls to traffic moving between the corporate network and the sensitive OT network, thereby containing potential breaches.
- 8
A cloud security architect is designing a security strategy for a multi-cloud environment. The organization uses a mix of IaaS, PaaS, and SaaS services. A primary requirement is to gain consistent visibility into misconfigurations and compliance violations across all cloud providers. Which technology is best suited for this purpose?
Show answer details
Correct answer: C
Cloud Security Posture Management (CSPM) is specifically designed to identify and remediate misconfigurations and compliance risks in cloud environments. It continuously monitors cloud infrastructure against a set of security and compliance best practices, making it the ideal solution for maintaining a secure posture across multiple cloud providers.
- 9
A security team is implementing Cortex XDR. They want to proactively search for signs of compromise that might not have triggered a formal alert, based on hypotheses about attacker techniques. What is this security practice called?
Show answer details
Correct answer: B
Threat hunting is the proactive and iterative process of searching through networks and datasets to detect and isolate advanced threats that evade existing security solutions. It is hypothesis-driven, where analysts actively look for evidence of malicious activity rather than passively waiting for alerts.
- 10
An organization is looking to replace its legacy anti-malware solution, which frequently fails to detect polymorphic malware and zero-day threats. Which two endpoint security capabilities are essential for addressing this limitation? (Select TWO)
Show answer details
Correct answer: B, D
Behavioral Threat Prevention analyzes the actions and techniques used by processes, rather than relying on static signatures. This allows it to detect and block malicious activities characteristic of zero-day and polymorphic threats, even if the specific file has never been seen before.
UEBA establishes a baseline of normal user and device behavior and then identifies deviations. This is highly effective at spotting the anomalous activities that are hallmarks of advanced threats which evade signature-based detection, such as lateral movement or unusual data access.
