Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Palo Alto Networks Certified Cybersecurity Apprentice Cybersecurity-Apprentice Exam Questions

Page: 1 / 12 Total 115 questions

Want more questions? Get Premium Access.

Question 1

Why would you create a VPN?

Correct Answer: C. To encrypt data for secure transport
Explanation:

A VPN is created to encrypt data for secure transport across an untrusted or shared network. It establishes a protected tunnel between endpoints, users, sites, or networks so that traffic is less exposed to interception or tampering. Blocking malicious traffic is primarily the role of firewalls, IPS, secure web gateways, or other enforcement controls. Reducing traffic overhead is not the purpose of VPN; encryption can actually add overhead. Automating and correlating incidents is a SOAR or SIEM function, not VPN. VPNs are commonly used for remote user access and site-to-site connectivity. They can protect sensitive business communication between branch offices, cloud networks, and corporate resources. However, VPNs are not a complete security architecture by themselves. Strong authentication, access control, logging, least privilege, device posture validation, and segmentation are still necessary to ensure that encrypted access is also authorized and monitored. Reference/topics: Network Security 3.3, VPNs; Network Security 3.4, tunneling protocols.


Question 2

A data center needs to secure its infrastructure from network-based threats. Which two technologies will address this need? (Choose two.)

Correct Answer: A. Next-generation firewall; B. Intrusion prevention system (IPS)
Explanation:

A next-generation firewall and an intrusion prevention system are appropriate technologies for securing data center infrastructure from network-based threats. The NGFW enforces application-aware security policy and can inspect traffic for threats. An IPS inspects traffic inline and blocks malicious packets or exploit attempts before they reach protected systems. An IDS is valuable for detection and alerting, but because it is generally passive, it does not provide the same preventive control as IPS. A proxy can secure certain traffic flows, especially web traffic, but it is not the broadest answer for protecting general data center infrastructure. Data centers require preventive controls because attacks may target public-facing services, internal applications, management interfaces, or east-west workload traffic. NGFW and IPS technologies help reduce exposure by enforcing policy, blocking known threats, and supporting segmentation. Reference/topics: Network Security 3.2, NGFWs; Cybersecurity 1.5, intrusion prevention systems and firewalls.


Question 3

How can a meddler-in-the-middle (MITM) gain access to a mobile device?

Correct Answer: C. By masquerading as an access point
Explanation:

A meddler-in-the-middle attack can gain access to mobile traffic by masquerading as a legitimate wireless access point. If a user's mobile device connects to the rogue access point, the attacker can position themselves between the device and the intended network or internet service. This allows the attacker to observe, redirect, manipulate, or attempt to downgrade communications, especially when applications do not properly validate encryption or certificates. Modifying a target's IP address alone does not describe the usual MITM setup. Forcing licensing updates is not a standard MITM method. Flooding packets describes denial-of-service behavior rather than interception. Rogue access points are effective because users often trust familiar network names or automatically join previously known SSIDs. Defenses include avoiding unknown Wi-Fi, using VPNs where appropriate, validating certificates, disabling auto-join, using enterprise Wi-Fi authentication, and enforcing mobile device security policies. Reference/topics: Cybersecurity 1.3, common attack types; Network Security 3.3, VPNs and proxies.


Question 4

Which protocol uses encryption to secure its communications?

Correct Answer: B. SSH
Explanation:

SSH, or Secure Shell, uses encryption to protect remote administrative sessions and related communications. It is commonly used to securely access command-line interfaces on servers, network devices, and cloud systems. SSH protects confidentiality and integrity by encrypting the session, making it far safer than Telnet. Telnet sends traffic in plaintext and should not be used for secure administration. NAT translates IP addresses but is not a secure communication protocol. DHCP assigns IP configuration information to clients and does not provide encrypted administrative access. SSH is a tunneling and secure communication protocol because it can authenticate endpoints, protect credentials, and prevent eavesdropping on management traffic. In operational environments, replacing Telnet with SSH is a basic hardening step because management protocols often carry powerful credentials. Encryption alone is not the whole control; secure key management, strong authentication, and access restrictions are also required. Reference/topics: Network Security 3.4, tunneling protocols including SSH; Network Fundamentals 2.4, DHCP and NAT.


Question 5

What is the function of an antivirus solution?

Correct Answer: D. Detecting malicious files using malware signatures
Explanation:

The function of an antivirus solution is to detect malicious files using malware signatures and related detection methods. Signature-based detection compares files or code patterns against known malware indicators. Antivirus may also include heuristic, reputation-based, or behavioral detection, but known malware signature scanning is the classic function. Regulating traffic based on security rules is a firewall function. Protecting against DNS poisoning is handled through DNS security, secure resolver behavior, validation mechanisms, and network protections. Protecting user credentials is primarily an identity security function involving MFA, password management, phishing resistance, and access controls. Antivirus is a core endpoint security component because malicious files commonly reach users through downloads, attachments, removable media, compromised websites, or unauthorized software. It helps prevent execution, quarantine malicious content, and alert administrators. While modern endpoint platforms go beyond antivirus, the foundational antivirus role remains malware file detection and prevention on the device. Reference/topics: Endpoint Security 4.3, antivirus; Cybersecurity 1.5, threat prevention practices.


Question 6

What does continuous integration and continuous delivery/deployment (CI/CD) improve for an organization?

Correct Answer: C. Secure development pipeline
Explanation:

CI/CD improves the secure development pipeline by making software build, test, delivery, and deployment processes more automated, repeatable, and controlled. Continuous integration encourages developers to merge code frequently into a shared repository where automated tests and checks can run. Continuous delivery keeps software in a deployable state, while continuous deployment can automatically release changes that pass required tests. Security can be embedded into this pipeline through static analysis, dependency scanning, container image scanning, secrets detection, infrastructure-as-code checks, and policy gates. The goal is not merely faster software delivery, but safer and more reliable delivery. Network threat alert potential is a SOC concern, not the primary CI/CD outcome. API interaction optimization may occur in development, but it is too narrow. Storage quotas for code are repository management settings. Secure CI/CD reduces late-stage security surprises and helps organizations detect weaknesses earlier when they are cheaper and easier to fix. Reference/topics: Cloud Security 5.6, CI/CD; Identity Security 7.4.2, CI/CD pipeline secrets.


Question 7

Which security control is best suited to block traffic based on the actual application being used rather than only the port number?

Correct Answer: B. Next-generation firewall
Explanation:

A next-generation firewall is best suited to block or allow traffic based on the actual application being used rather than only the port number. Traditional firewalls commonly rely on IP addresses, protocols, and ports, which is insufficient when many applications use common ports such as TCP 80 or TCP 443. A next-generation firewall adds application awareness, allowing it to identify traffic based on application behavior and enforce more precise security policy. A hub operates at OSI Layer 1 and simply repeats signals; it cannot inspect applications. A DHCP server assigns IP configuration information to clients and does not enforce application-based security policy. A Layer 2 switch forwards frames based on MAC addresses and does not determine whether a specific application should be allowed. Application-aware policy is important because attackers and risky applications often hide within allowed ports. NGFWs help security teams control traffic according to business intent, application risk, user identity, and threat context. Reference/topics: Network Security, stateful firewalls, next-generation firewalls, application awareness.


Question 8

Which type of attack occurs when malware is hidden within an application and infects the host without being detected?

Correct Answer: C. Trojan
Explanation:

A trojan is malware disguised as legitimate or useful software. It tricks the user or system into running it, then performs malicious actions such as installing backdoors, stealing data, downloading additional payloads, or giving attackers remote access. The key characteristic is deception: the malware is hidden inside or presented as a trusted application. A botnet is a network of compromised devices controlled by an attacker, often through command-and-control infrastructure. Ransomware encrypts or locks systems and demands payment. A virus is malware that attaches to files or programs and replicates when executed, but the scenario specifically describes malicious code hidden within an application to avoid detection, which fits a trojan. Trojans are common because they exploit user trust and can bypass purely technical controls if users install unauthorized software. Endpoint protection, application control, user training, and least privilege help reduce trojan risk. Reference/topics: Cybersecurity 1.3, malware types; Endpoint Security 4.3, antivirus.


Question 9

What is a cluster in relation to cloud-native security?

Correct Answer: C. Collection of nodes (bare-metal or virtualized machines) that will host application pods
Explanation:

In cloud-native security, a cluster is a collection of compute nodes that run containerized workloads. These nodes may be physical bare-metal systems or virtualized machines, and together they provide the execution environment for application pods. In Kubernetes-style architectures, a pod is the smallest deployable unit, and the cluster provides scheduling, networking, scaling, and orchestration capabilities. Answer A describes a container, not a cluster, because a container packages application code with the runtime and dependencies needed to execute consistently across environments. Answer B describes code or policy logic, not infrastructure. Answer D is a broad description of cloud-hosted services but lacks the specific cloud-native meaning of nodes hosting pods. Palo Alto Networks includes common cloud terms such as virtualization, virtual machine, container, microservice, and API in the Cloud Security domain, and also includes cloud-native security platform concepts. Understanding clusters is essential because cloud-native security must protect the orchestration layer, workload runtime, identities, configurations, and network paths between services. Reference: Cybersecurity Apprentice Datasheet, Cloud Security 5.4 and 5.5.


Question 10

Which Identity and Access Management principle reduces the impact of a compromised user account?

Correct Answer: B. Least privilege
Explanation:

Least privilege reduces the impact of a compromised user account by ensuring that each user, service, or application has only the permissions necessary to perform its required function. If an attacker steals credentials for an account with excessive privileges, the attacker may access sensitive systems, modify configurations, exfiltrate data, or move laterally through the environment. When least privilege is properly implemented, the blast radius is smaller because the compromised identity cannot access resources outside its assigned role. Single sign-on improves user access experience and centralizes authentication, but it does not by itself limit what the user can access. DNS filtering controls access to domains and is a network security function. Static routing controls packet forwarding paths and is unrelated to identity permissions. In IAM, least privilege is commonly enforced through role-based access control, access reviews, privileged access management, and conditional access policies. Reference/topics: Identity Security, IAM, RBAC, MFA, least privilege.