Cybersecurity Practitioner Free Sample Questions

12 free sample questions120 in the full practice test

Try simulator

CyberSec-Practitioner Sample Questions

  1. Question 1

    A security architect is designing a Zero Trust architecture for a financial institution. The organization requires that all internal east-west traffic between the 'HR-VLAN' and 'Finance-VLAN' be inspected for threats, specifically looking for lateral movement and exploit attempts. Currently, these VLANs are routed via a core switch with ACLs. Which deployment mode should the architect implement on a Palo Alto Networks NGFW to achieve deep packet inspection without re-architecting the entire Layer 3 routing topology?

    Answer and explanation

    Correct answer: B

    Virtual Wire (VWire) mode allows the firewall to be inserted transparently into an existing network segment. It bridges two interfaces without requiring IP address changes or routing table modifications on adjacent devices, making it ideal for inspecting east-west traffic without disrupting the existing L3 topology.

  2. Question 2

    During a security audit, an administrator notices that a specific Security Policy rule is effectively allowing traffic that should be blocked. The rule is configured with 'Application: any' and 'Service: application-default'. The traffic in question is SSH traffic running on port 8022. Why is this traffic being blocked by the default deny rule instead of matching the allow rule, or vice versa, based on the configuration provided?

    Answer and explanation

    Correct answer: B

    The 'application-default' setting enforces that the application must run on its standard IANA assigned port (e.g., SSH on port 22). Since the traffic is SSH on port 8022, it fails the service check for this rule and falls through to subsequent rules (likely the default deny).

  3. Question 3

    A manufacturing company uses Cortex XDR to protect its industrial control systems (ICS). The SOC team observes a series of alerts indicating a 'Generic.Malware' verdict from the Local Analysis engine on an isolated endpoint that has no internet connectivity. Which component of the Cortex XDR agent is primarily responsible for this detection in the absence of cloud connectivity?

    Answer and explanation

    Correct answer: B

    The Cortex XDR agent includes a Local Analysis engine powered by machine learning models trained in the cloud but deployed locally. This allows the agent to detect and block known and unknown malware variants based on file characteristics (static analysis) even when the endpoint is offline.

  4. Question 4

    An organization is deploying Prisma Access to secure its mobile workforce. They need to ensure that internet-bound traffic from mobile users in Germany exits to the internet from a German IP address to comply with data residency regulations, while users in France exit from France. Which Prisma Access configuration object must be defined to achieve this localized internet breakout?

    Answer and explanation

    Correct answer: B

    Prisma Access for Mobile Users utilizes Gateways deployed in specific regions. By configuring gateways in Germany and France and ensuring users connect to the gateway nearest them (or enforcing it via region settings), traffic destined for the internet is NATed to the public IP of that specific gateway, satisfying data residency egress requirements.

  5. Question 5

    Multiple answers

    Which TWO actions are required to successfully configure an Active/Passive High Availability (HA) pair of Palo Alto Networks firewalls? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    HA1 is used for control plane communication (config sync, heartbeats), and HA2 is used for data plane synchronization (sessions, forwarding tables). Both are essential for a functional Active/Passive setup.

    For HA to function correctly and be supported, both peers must run the same major PAN-OS version and have matching licenses (e.g., Threat Prevention, WildFire) to ensure capability parity.

  6. Question 6

    A security analyst is reviewing the Automated Correlation Engine (ACE) logs in Panorama. They notice a 'Correlated Event' that groups together a port scan, a brute force attempt, and a subsequent data exfiltration event from the same source IP. What is the primary function of the Correlation Object in this context?

    Answer and explanation

    Correct answer: B

    Correlation Objects define the criteria (patterns) that the correlation engine looks for across various logs (Traffic, Threat, etc.) to identify complex attacks that single-event signatures might miss. It synthesizes these into a single Correlated Event.

Register free to unlock 6 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 120 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon