Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Paloalto Networks Apprentice Dumps Questions Answers

Page: 1 / 9
Total 115 questions

Palo Alto Networks Cybersecurity Apprentice Questions and Answers

Question 1

What is the primary responsibility of the cloud provider in the cloud shared responsibility model?

Options:

A.

Configuring application-level security settings

B.

Securing underlying physical servers and network infrastructure

C.

Providing end-user training on application usage

D.

Monitoring and managing user access and permissions

Buy Now
Question 2

Which OSI layer is used to determine how long communications are open between two devices?

Options:

A.

Transport

B.

Application

C.

Session

D.

Network

Question 3

What are two endpoint security implementation methods? (Choose two.)

Options:

A.

Installing an anti-malware agent onto a user device

B.

Deploying a firewall to prevent traffic from reaching an end user

C.

Enforcing security policies on north-south traffic between users and the internet

D.

Downloading software onto a laptop to prevent spyware

Question 4

Which security control is best suited to block traffic based on the actual application being used rather than only the port number?

Options:

A.

Hub

B.

Next-generation firewall

C.

DHCP server

D.

Layer 2 switch

Question 5

A data center needs to secure its infrastructure from network-based threats. Which two technologies will address this need? (Choose two.)

Options:

A.

Next-generation firewall

B.

Intrusion prevention system (IPS)

C.

Intrusion detection system (IDS)

D.

Proxy

Question 6

Which Identity and Access Management principle reduces the impact of a compromised user account?

Options:

A.

Single sign-on

B.

Least privilege

C.

DNS filtering

D.

Static routing

Question 7

Which technique is used by attackers during the Installation phase of the cyber attack lifecycle to maintain persistent and undetected access to a compromised system?

Options:

A.

Using rootkits to hide malicious activity in the operating system

B.

Exploiting known vulnerabilities in web applications

C.

Launching brute force attacks on user accounts

D.

Sending spear phishing emails to gain additional credentials

Question 8

Which segmentation method will limit the number of devices that can be granted a private IP address in a network?

Options:

A.

NAT

B.

Static routing

C.

IP subnetting

D.

VLAN

Question 9

A hub operates on which OSI layer?

Options:

A.

Layer 1

B.

Layer 2

C.

Layer 3

D.

Layer 4

Question 10

In which cloud service model does a company use hardware resources from a cloud service provider?

Options:

A.

Platform as a service (PaaS)

B.

Software as a service (SaaS)

C.

Network as a service (NaaS)

D.

Infrastructure as a service (IaaS)

Question 11

Why is it important to have a clear and well documented incident response plan?

Options:

A.

It increases storage for logs and incident events.

B.

It provides additional methods to identify users.

C.

It increases code deployment efficiency.

D.

It reduces the time required to contain and identify a breach.

Question 12

Which type of segmentation divides traffic based on the interface on which a packet is received or sent?

Options:

A.

Zone

B.

Port

C.

Application

D.

Role

Question 13

Which two sets of actions are examples of multi-factor authentication (MFA)? (Choose two.)

Options:

A.

Answering a security question and providing a thumbprint

B.

Entering a PIN and scanning a smart card

C.

Scanning the palm of one hand followed by the other hand

D.

Answering three sequential security questions

Question 14

What is an example of an exploit?

Options:

A.

Misconfigured access control

B.

Unpatched software

C.

Buffer overflow attack

D.

Exposed password

Question 15

In infrastructure as a service (IaaS), which cloud component is the cloud service provider responsible for securing in the shared responsibility model?

Options:

A.

Physical wires and switches in the provider’s infrastructure

B.

API requests between microservices, such as back-end business logic traffic

C.

Database queries between cloud application services and external-facing web services

D.

Traffic from workloads to third-party services on the internet, such as authentication providers

Question 16

Which two technologies will secure a data center’s infrastructure from network-based threats? (Choose two.)

Options:

A.

Next-generation firewall

B.

Intrusion Detection System (IDS)

C.

Intrusion Prevention System (IPS)

D.

Proxy

Question 17

What is a function of a Network-Based Intrusion Detection System (NIDS)?

Options:

A.

Scanning and quarantining infected files on a host machine

B.

Proxying traffic before reaching an internal network

C.

Blocking malicious traffic from entering a network in real time

D.

Monitoring network traffic and reporting results to an administrator

Question 18

What is an advantage of using dynamic routing protocols over using static routing protocols in a network?

Options:

A.

They provide only a default route for the network.

B.

They enable scalability for larger networks.

C.

They increase network latency.

D.

They enable network configuration through predefined templates.

Question 19

What is a function of a default gateway?

Options:

A.

Increasing signal strength of mesh wireless networks

B.

Acting as a buffer for reducing traffic overhead on a link

C.

Eliminating packet errors for traffic traversing a network

D.

Allowing communication between two networks

Question 20

What is a benefit of SD-WAN versus traditional WANs?

Options:

A.

Reliance on multiple different WAN connection types and licenses is removed.

B.

All physical WAN components can be easily removed and replaced without network disruption.

C.

Administrators can deploy WAN connection policies across an entire network at once.

D.

WANs are physically connected and strengthened against electromagnetic interference.

Question 21

What is an effective use case of URL filtering?

Options:

A.

Monitoring threat logs and traffic logs

B.

Restricting access to phishing websites

C.

Acting as a sandbox for potentially malicious files

D.

Discovering internet of things (IoT) devices

Question 22

Which concept is a strategic approach to cybersecurity that continuously validates every stage of a digital interaction?

Options:

A.

Incident response plan implementation

B.

Zero Trust adoption

C.

Compliance planning

D.

Operations playbook development

Question 23

Which packets are considered east-west traffic in a data center?

Options:

A.

Those originating from the internet destined to the public IP address of a virtual server

B.

Those sent from a virtual desktop to a cloud-based proxy

C.

Those sent from a cloud-based server to a virtual desktop

D.

Those that move between virtual servers across a virtual switch

Question 24

What is the fundamental role of a proxy server in internet communication?

Options:

A.

Enhancing the processing power of a user device when accessing internet.

B.

Managing and securing email communications.

C.

Acting as an intermediary, routing traffic between users and online resources.

D.

Directly connecting endpoint agents to web servers.

Question 25

Which stage of the cyber attack lifecycle is characterized by an attacker passing instructions back and forth between infected devices and their own infrastructure?

Options:

A.

Command-and-control (C2)

B.

Exploitation

C.

Reconnaissance

D.

Weaponization and Delivery

Question 26

What will cause an unusually high number of false positive alerts?

Options:

A.

Post-breach recovery plan is well defined.

B.

User privilege is configured to be strict.

C.

Device is unable to receive an IP address.

D.

Traffic match criteria is too generalized.

Question 27

Which cloud service model allows a third-party provider to host an application that is readily available for customer use?

Options:

A.

Software as a service (SaaS)

B.

Platform as a service (PaaS)

C.

Desktop as a service (DaaS)

D.

Infrastructure as a service (IaaS)

Question 28

What are two of the four Cs of cloud-native security? (Choose two.)

Options:

A.

Configurations

B.

Code

C.

Connections

D.

Clusters

Question 29

Where does network traffic go when it does not have a specific route for a destination address?

Options:

A.

VPN gateway

B.

Hub

C.

Internet

D.

Default gateway

Question 30

Which cloud computing model allows a single organization to keep its data in a private environment but also access the scalability and cost-effectiveness of public resources?

Options:

A.

Hybrid

B.

Public

C.

Community

D.

Private

Question 31

How is Zero Trust implemented on a network?

Options:

A.

By assigning all security to a proxy solution

B.

By designating failover paths

C.

By inspecting and validating traffic continuously

D.

By removing excess network devices

Question 32

What is a documented strategy outlining how an organization will detect, respond to, and recover from cybersecurity attacks or other disruptions?

Options:

A.

Security framework alignment

B.

MTTR

C.

MTTD

D.

Incident response plan

Question 33

Which components are secured by the cloud provider in a shared responsibility model?

Options:

A.

Virtual machines

B.

On-premises connectivity to hosts

C.

Website authentication

D.

Host servers

Question 34

Which scenario is an example of a DDoS attack?

Options:

A.

Information is extracted without host knowledge.

B.

A target overwhelmed by a flood of traffic.

C.

A malicious payload is concealed in a file.

D.

An email with a malicious attachment is sent.

Page: 1 / 9
Total 115 questions