
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 5
5.5 Explain Behavioral Threat Prevention CYBERSECURITY-PRACTITIONER Practice Questions (Page 4)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
30questions here
6free pages
6concepts
15%of the exam
Questions 16–20
- 16
A security analyst is reviewing an alert from the behavioral threat prevention system. The alert was triggered because a process attempted to modify the Windows registry and create a new service. The process is signed by a reputable software vendor, and its hash matches a known-good file. The analyst must decide whether to allow or block the process. What is the most appropriate course of action?
Select an answer first - 17
A security analyst is comparing two detection methods for a new malware strain. Method A uses a list of known malicious file hashes. Method B uses a machine learning model that analyzes the sequence of system calls a process makes. The malware is polymorphic and changes its hash each time it infects a new system. Which method will be more effective, and why?
Select an answer first - 18
A security analyst is comparing two detection methods. Method A flags a file because its hash matches a known malware sample. Method B flags a process because it attempts to access the Security Account Manager (SAM) database and then injects code into another process. Which statement best describes the difference?
Select an answer first - 19
A user's endpoint is flagged by behavioral threat prevention after it detects a process repeatedly encrypting files and attempting to contact a command-and-control server. The endpoint protection platform automatically contains the threat. Which remediation action is most likely to be taken first?
Select an answer first - 20
A security analyst notices that a known-good application has been modified to include a new module that attempts to enumerate local user accounts and then write to the Windows registry. The file's hash matches a known-good signature, and no network indicators are present. Which behavioral detection mechanism would most likely flag this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.