Skip to content

Cybersecurity Practitioner Practice Questions

Prepare for CyberSec-Practitioner with more than an answer.

120 questions in the full set12 sample questionsUpdated Mar 12, 2026
  1. 1

    When configuring a URL Filtering Profile, an administrator wants to ensure that users are warned when visiting a 'Newly Registered Domain' but are allowed to proceed if they explicitly acknowledge the risk. Which action should be assigned to the 'newly-registered-domain' category?

    Show answer details

    Correct answer: A

    The 'continue' action presents a response page to the user warning them about the site. The user must click 'Continue' to proceed to the website. This satisfies the requirement of warning and acknowledgment.

  2. 2

    Review the diagram below showing a User-ID flow.

    Which component is missing in the flow that is responsible for monitoring the Domain Controller security logs and forwarding the user-IP mappings to the firewall?

    Show answer details

    Correct answer: B

    The User-ID Agent (either standalone Windows-based or the Integrated User-ID Agent on the firewall) is responsible for querying or receiving security logs from the Domain Controller to create User-IP mappings.

  3. 3

    A Cortex XSOAR playbook has failed during execution. The error log indicates that the integration instance 'ActiveDirectory_1' timed out while querying a user account. Which troubleshooting step should be performed FIRST to isolate the issue?

    Show answer details

    Correct answer: C

    Testing the command manually in the War Room allows the analyst to distinguish between a playbook logic error and an underlying integration/network connectivity issue. If the manual command also fails, the issue is with the integration configuration or network.

  4. 4

    A security architect is designing a Zero Trust architecture for a financial institution. The organization requires that all internal east-west traffic between the 'HR-VLAN' and 'Finance-VLAN' be inspected for threats, specifically looking for lateral movement and exploit attempts. Currently, these VLANs are routed via a core switch with ACLs. Which deployment mode should the architect implement on a Palo Alto Networks NGFW to achieve deep packet inspection without re-architecting the entire Layer 3 routing topology?

    Show answer details

    Correct answer: D

    Virtual Wire (VWire) mode allows the firewall to be inserted transparently into an existing network segment. It bridges two interfaces without requiring IP address changes or routing table modifications on adjacent devices, making it ideal for inspecting east-west traffic without disrupting the existing L3 topology.

  5. 5

    During a security audit, an administrator notices that a specific Security Policy rule is effectively allowing traffic that should be blocked. The rule is configured with 'Application: any' and 'Service: application-default'. The traffic in question is SSH traffic running on port 8022. Why is this traffic being blocked by the default deny rule instead of matching the allow rule, or vice versa, based on the configuration provided?

    Show answer details

    Correct answer: D

    The 'application-default' setting enforces that the application must run on its standard IANA assigned port (e.g., SSH on port 22). Since the traffic is SSH on port 8022, it fails the service check for this rule and falls through to subsequent rules (likely the default deny).

  6. 6

    A manufacturing company uses Cortex XDR to protect its industrial control systems (ICS). The SOC team observes a series of alerts indicating a 'Generic.Malware' verdict from the Local Analysis engine on an isolated endpoint that has no internet connectivity. Which component of the Cortex XDR agent is primarily responsible for this detection in the absence of cloud connectivity?

    Show answer details

    Correct answer: B

    The Cortex XDR agent includes a Local Analysis engine powered by machine learning models trained in the cloud but deployed locally. This allows the agent to detect and block known and unknown malware variants based on file characteristics (static analysis) even when the endpoint is offline.

Create an account to continue.