Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Cybersecurity Practitioner

Domain 5Objective 1

5.1 Identify and Explain Indicators of Compromise (IOCs) CYBERSECURITY-PRACTITIONER Practice Questions (Page 5)

Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.

36questions here
8free pages
9concepts
15%of the exam

Questions 21–25

  1. 21foundation · easy

    Which of the following is a common source for obtaining Indicators of Compromise (IOCs)?

    Select an answer first
  2. 22foundation · easy

    What is the most accurate definition of an Indicator of Compromise (IOC)?

    Select an answer first
  3. 23foundation · easy

    Which of the following best describes the purpose of an Indicator of Compromise (IOC)?

    Select an answer first
  4. 24expert · hard

    A security team has implemented an EDR solution that relies on file hash IOCs and known malicious domains. A new malware campaign is observed in the wild, but the EDR does not detect it. The malware uses a unique domain per victim and modifies its code to change its hash. Which limitation of IOC-based detection is most evident?

    Select an answer first
  5. 25application · medium

    A network analyst observes a workstation sending a large volume of data to an external domain that is not on any allowlist. The domain was registered only two days ago. Which network-based IOC is most indicative of malicious activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.