
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 2
5.2 Explain the Limitations of Signature-Based Anti-Malware Software CYBERSECURITY-PRACTITIONER Practice Questions (Page 1)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
19questions here
4free pages
4concepts
15%of the exam
Questions 1–5
- 1
A malware analyst is examining a suspicious file that was flagged by a sandbox but not by the signature-based anti-malware. The analyst finds the file contains a known malicious payload, but it is encrypted with a random key and decrypted only at runtime. Which evasion technique is being used?
Select an answer first - 2
What is a 'signature' in the context of signature-based anti-malware?
Select an answer first - 3
Why does signature-based anti-malware require frequent updates?
Select an answer first - 4
A security analyst is investigating a malware infection that was not detected by the signature-based anti-malware. The analyst discovers the malware uses a technique where it changes its code each time it infects a new system, but the core functionality remains the same. Which limitation of signature-based detection is most directly exploited by this technique?
Select an answer first - 5
A security architect is reviewing the endpoint protection strategy for a large enterprise. The current solution is signature-based and has a low false-positive rate, but it has missed several zero-day attacks. The architect is considering adding a behavioral-based detection layer. Which trade-off should the architect consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.