
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 1
5.1 Identify and Explain Indicators of Compromise (IOCs) CYBERSECURITY-PRACTITIONER Practice Questions (Page 1)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
36questions here
8free pages
9concepts
15%of the exam
Questions 1–5
- 1
An analyst is triaging a suspicious file found on an endpoint. The file has a known name and size, but the analyst needs to confirm it matches a known malware sample. Which file-based IOC provides the most reliable confirmation?
Select an answer first - 2
Which of the following is a host-based indicator of compromise (IOC)?
Select an answer first - 3
An incident responder is analyzing a malware sample. The sample's SHA-256 hash is not found in any threat intelligence feed. However, the file name matches a known malware family and the file size is identical to a known sample. What should the responder conclude?
Select an answer first - 4
A security analyst is reviewing a suspicious email attachment that was opened by a user. The analyst wants to determine if the file is known malware by checking its unique identifier against a threat intelligence feed. Which IOC type should the analyst extract from the file to perform this check?
Select an answer first - 5
A security analyst is managing an IOC list in their SIEM. They notice that a particular IP address has been flagged as malicious for over a year, but recent threat intelligence shows the IP is now used by a legitimate service. The analyst wants to reduce false positives. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.