Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Cybersecurity Practitioner

Domain 5Objective 5

5.5 Explain Behavioral Threat Prevention CYBERSECURITY-PRACTITIONER Practice Questions (Page 4)

Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.

30questions here
6free pages
6concepts
15%of the exam

Questions 16–20

  1. 16expert · hard

    A security analyst is reviewing an alert from the behavioral threat prevention system. The alert was triggered because a process attempted to modify the Windows registry and create a new service. The process is signed by a reputable software vendor, and its hash matches a known-good file. The analyst must decide whether to allow or block the process. What is the most appropriate course of action?

    Select an answer first
  2. 17expert · hard

    A security analyst is comparing two detection methods for a new malware strain. Method A uses a list of known malicious file hashes. Method B uses a machine learning model that analyzes the sequence of system calls a process makes. The malware is polymorphic and changes its hash each time it infects a new system. Which method will be more effective, and why?

    Select an answer first
  3. 18application · medium

    A security analyst is comparing two detection methods. Method A flags a file because its hash matches a known malware sample. Method B flags a process because it attempts to access the Security Account Manager (SAM) database and then injects code into another process. Which statement best describes the difference?

    Select an answer first
  4. 19application · medium

    A user's endpoint is flagged by behavioral threat prevention after it detects a process repeatedly encrypting files and attempting to contact a command-and-control server. The endpoint protection platform automatically contains the threat. Which remediation action is most likely to be taken first?

    Select an answer first
  5. 20application · medium

    A security analyst notices that a known-good application has been modified to include a new module that attempts to enumerate local user accounts and then write to the Windows registry. The file's hash matches a known-good signature, and no network indicators are present. Which behavioral detection mechanism would most likely flag this activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.