
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 6
5.6 Identify and Describe Cybersecurity Threats Mitigated by the Following Endpoint Security Technologies CYBERSECURITY-PRACTITIONER Practice Questions (Page 4)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
30questions here
6free pages
7concepts
15%of the exam
Questions 16–20
- 16
A security analyst is investigating a server that is running a custom in-house application. The application is critical to operations and cannot be stopped. The analyst notices that the application is making unexpected system calls and writing to files outside its designated directory. The behavior is not matched by any known signature. The analyst wants to block this malicious behavior without disrupting the application's normal functions. Which approach is most appropriate?
Select an answer first - 17
A research lab handles highly sensitive intellectual property. The lab manager is concerned about employees copying data to personal external hard drives. They want to prevent any data from being written to external storage devices while still allowing the use of USB mice and keyboards. Which control should be configured?
Select an answer first - 18
What is the primary function of a host-based firewall on an endpoint?
Select an answer first - 19
A security administrator is configuring a new endpoint for a remote worker who handles sensitive customer data. The administrator wants to ensure that the endpoint is protected against network-based attacks, data theft if the device is lost, and malicious software that might attempt to modify system files. Which set of controls should be implemented to address all three concerns?
Select an answer first - 20
A security analyst is troubleshooting a server that is running a web application. The server's HIPS is generating alerts about the web application process making unusual system calls and attempting to write to the system directory. The analyst is unsure if this is a false positive or a real attack. The web application is critical and cannot be stopped. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.