Skip to content

Endpoint Security Questions

Practice questions for Endpoint Security topic in Palo Alto Networks Certified Cybersecurity Practitioner. 30 questions covering this domain.

30 questions8 easy16 medium6 hard
Q1
medium

An endpoint policy should restrict which applications can run. Which control fits?

Q2
easy

Which term describes evidence that a system or account may have been compromised?

Q3
medium

A team wants to reduce malware introduction and data loss through removable USB media. Which control fits?

Q4
medium

A laptop needs host-local prevention against suspicious activity. Which control fits?

Q5
medium

A company wants to regulate peripheral devices connected to endpoints. Which control fits?

Q6
easy

Which endpoint approach detects known malicious patterns but can miss new or changed threats?

Q7
hard

A new malware variant has no known signature but behaves like credential theft malware. Which prevention approach is most useful?

Q8
hard

An attack spans endpoint, identity, email, and cloud signals, and analysts need a prioritized cross-vector view. Which Palo Alto Networks product fits...

Q9
medium

A practitioner wants to reduce endpoint risk by keeping software updated against known weaknesses. Which practice fits?

Q10
medium

A responder needs to understand how an endpoint alert began and what execution path followed. Which activity fits?

Q11
hard

A SOC sees a detection but must identify the first process and path that led to the alert. Which investigation activity should they perform?

Q12
easy

Which concept looks for abnormal behavior by users and entities?

Q13
medium

A SOC wants endpoint protection that connects endpoint, network, cloud, identity, and email data. Which Palo Alto Networks product fits?

Q14
medium

An analyst needs endpoint activity data to investigate a suspicious process chain. Which data type is needed?

Q15
easy

Which technology monitors endpoint activity and supports investigation and response?

Q16
medium

An attack uses a vulnerability before broad signatures or patches are available. Which threat type fits?

Q17
medium

A host begins encrypting files and demanding payment. Which threat type fits?

Q18
easy

Which technology correlates endpoint data with signals from other security layers?

Q19
medium

A compromised endpoint must be contained while investigation continues. Which response action fits?

Q20
hard

A workstation is actively communicating with suspicious infrastructure, and responders need to stop spread without wiping it immediately. Which action...

Sign in to see all 30 questions

Create a free account to browse all questions — completely free during our launch phase.