Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Cybersecurity Practitioner

Domain 2Objective 5

2.5 Explain the Limitations of Signature-Based Network Protection CYBERSECURITY-PRACTITIONER Practice Questions (Page 3)

Part of the Network Security domain, which accounts for 19% of the CYBERSECURITY-PRACTITIONER exam.

29questions here
6free pages
5concepts
19%of the exam

Questions 11–15

  1. 11application · medium

    A security analyst is investigating a malware infection. The analyst finds that the malware is using a technique where the malicious code is encoded and then decoded at runtime. The signature-based IPS did not detect the malware because the encoded version did not match any known signature. Which evasion technique is being used?

    Select an answer first
  2. 12application · medium

    A security analyst at a mid-sized company notices that a known malware variant, which was widely reported in threat feeds two weeks ago, has been successfully executing on several endpoints. The company's next-generation firewall (NGFW) has signature-based IPS enabled with automatic updates. The malware uses a simple encoding scheme to alter its byte pattern on each infection. Which limitation of signature-based detection best explains why the IPS failed to block this threat?

    Select an answer first
  3. 13application · medium

    A security team is testing their IPS. They send a known exploit to a test server, but the IPS does not block it. Upon investigation, they find that the exploit payload has been modified by inserting benign characters between the command and its arguments. The overall functionality of the exploit is unchanged. Which evasion technique is being used?

    Select an answer first
  4. 14expert · hard

    A security manager is reviewing the company's network security posture. The company relies on a signature-based IPS. Recently, a zero-day attack bypassed the IPS, and the IPS also generated a high volume of false positives for a new internal application. The manager wants to improve detection without replacing the IPS. Which combination of complementary measures would best address both the zero-day gap and the false positive issue?

    Select an answer first
  5. 15application · medium

    A network administrator is explaining to a junior analyst how their signature-based IPS works. The administrator wants to clarify why the IPS can detect a known exploit but not a slightly modified version of it. Which statement best describes the underlying mechanism?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.