Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) flashcards
136 free flashcards. Tap a card to flip it.
Post-Incident Lessons Learned
Flip cardThe final stage of incident response, where the team analyzes the incident, identifies what went well and what didn't, and implements improvements to processes, tools, and training.
- Aims to prevent recurrence and improve future response.
- Involves root cause analysis and action item creation.
- Success is measured by actual implementation of changes.
Memory trick: Learning isn't just knowing, it's doing!
App-ID
Flip cardPalo Alto Networks' patented technology that accurately identifies applications regardless of port, protocol, encryption, or evasive tactics.
- Identifies applications based on multiple techniques (signatures, heuristics, decryption).
- Enables granular policy enforcement on applications.
- Fundamental to the NGFW's 'application-centric' approach.
Memory trick: Applications Identified by Port and Protocol are an App-ID's prime directive.
NGFW & Zero Trust
Flip cardThe Palo Alto Networks Next-Generation Firewall is a core component of a zero-trust architecture, enforcing the 'never trust, always verify' principle by providing granular control over all network traffic based on identity, application, and content.
- Enforces policies based on App-ID, User-ID, and Content-ID.
- Inspects all traffic, including internal (east-west) traffic.
- Authenticates and authorizes every connection before granting access.
- Moves security enforcement closer to the resource.
Memory trick: To trust no one, the Firewall must see everyone.
URL Filtering Profile
Flip cardA security profile in Palo Alto Networks NGFWs that allows administrators to control access to websites based on their category, reputation, and custom URL lists.
- Categorizes millions of URLs in real-time.
- Enables granular control over web access.
- Can block access to malicious, objectionable, or unproductive sites.
Memory trick: URL Filtering is like a bouncer at the web's door, checking IDs (URLs).
Cortex XSOAR
Flip cardPalo Alto Networks' Security Orchestration, Automation, and Response (SOAR) platform that unifies security operations, incident response, and threat intelligence management.
- Automates repetitive security tasks and workflows.
- Orchestrates responses across various security tools.
- Improves incident response times and analyst efficiency.
Memory trick: XSOAR makes your SOC a 'SOARing' success with automation.
WildFire
Flip cardPalo Alto Networks' cloud-based threat analysis service that identifies and prevents unknown malware and zero-day exploits through dynamic analysis (sandboxing) and machine learning.
- Analyzes suspicious files and links in a virtual sandbox environment.
- Generates new signatures and updates threat intelligence for NGFWs globally.
- Provides protection against zero-day threats and advanced persistent threats (APTs).
Memory trick: To catch a new fire, you need WildFire's eyes.
Panorama
Flip cardPalo Alto Networks' centralized security management platform that provides a single interface for managing multiple Next-Generation Firewalls (NGFWs), ensuring consistent security policies, updates, and visibility.
- Scales to manage hundreds or thousands of NGFW devices.
- Offers centralized policy creation, deployment, and monitoring.
- Provides consolidated logging, reporting, and software updates.
- Available as both a physical and virtual appliance.
Memory trick: For a 'panorama' view of all firewalls, use Panorama.
Prisma Cloud
Flip cardPalo Alto Networks' Cloud Native Application Protection Platform (CNAPP) that delivers comprehensive security across the entire application lifecycle for multi-cloud and hybrid cloud environments.
- Provides unified visibility and security for AWS, Azure, GCP, and Kubernetes.
- Covers cloud security posture management (CSPM), cloud workload protection (CWPP), and cloud network security.
- Enforces consistent security policies across diverse cloud infrastructure.
Memory trick: For all clouds, a single Prisma is the vision.
Data Filtering (DLP)
Flip cardA Next-Generation Firewall feature that inspects network traffic for sensitive information (e.g., credit card numbers, PII, intellectual property) and prevents its unauthorized transmission.
- Uses predefined or custom data patterns and profiles.
- Can block, alert, or log detected sensitive data.
- Crucial for preventing data exfiltration.
Memory trick: To stop data from leaking, you need a filter, not just an ID.
Prisma Access (SASE)
Flip cardPalo Alto Networks' cloud-delivered Secure Access Service Edge (SASE) platform that provides comprehensive security and secure access for all users, regardless of location or device, consolidating network and security functions.
- Combines network security (FWaaS, SWG, DLP) with WAN capabilities.
- Delivers security as a service from a global cloud infrastructure.
- Ensures consistent security policies for branch offices and mobile users.
Memory trick: For global access, Prisma is the key to the cloud castle.
User-ID
Flip cardA Palo Alto Networks technology that integrates with directory services (e.g., Active Directory) to map user identities to IP addresses, enabling user-based security policies.
- Provides visibility into who is using applications.
- Enables granular security policies based on users and groups.
- Fundamental for Zero Trust architectures.
Memory trick: User-ID is your ID badge for the Zero Trust club.
Prisma Access
Flip cardPalo Alto Networks' cloud-delivered Security Access Service Edge (SASE) platform that provides consistent security and secure access for remote users and branch offices.
- Combines network security (FWaaS) and secure access (ZTNA).
- Delivered as a global cloud service.
- Simplifies security for distributed workforces.
Memory trick: Prisma Access gives you a 'prism' of security for all your distributed 'access' needs.
VM-Series NGFW
Flip cardPalo Alto Networks' virtualized Next-Generation Firewall, designed to protect private and public cloud environments, offering advanced threat prevention and granular control.
- Runs as a virtual machine on hypervisors (e.g., VMware ESXi, KVM, Azure, AWS).
- Secures east-west traffic within virtualized data centers and clouds.
- Provides the same threat prevention capabilities as hardware NGFWs.
Memory trick: Virtual machines need a virtual shield, that's the VM-Series.
App-ID & User-ID
Flip cardTwo foundational Palo Alto Networks NGFW technologies. App-ID identifies applications regardless of port, and User-ID maps IP addresses to user identities from directories like Active Directory.
- App-ID enables application-level policy enforcement.
- User-ID enables user and group-level policy enforcement.
- Together, they provide granular, identity-based application control.
Memory trick: To know WHO is using WHAT app, you need User-ID and App-ID.
SSL Decryption (Inbound/Outbound)
Flip cardA Palo Alto Networks NGFW feature that decrypts SSL/TLS encrypted traffic, inspects it for threats and policy violations, and then re-encrypts it before forwarding, providing full visibility into encrypted communications.
- Crucial for detecting hidden threats in encrypted traffic (e.g., malware, data exfiltration).
- Can be configured as SSL Forward Proxy (outbound) or SSL Inbound Inspection (inbound).
- Requires proper certificate management and careful policy configuration to balance security and privacy.
Memory trick: To see into the SSL lockbox, you need Inbound Inspection.
Cyber Kill Chain: Reconnaissance
Flip cardThe first phase of the Cyber Kill Chain, where an attacker gathers information about a target before initiating an attack.
- Can be passive (OSINT) or active (scanning)
- Aims to identify vulnerabilities and potential entry points
- Occurs both pre-attack and post-compromise (internal reconnaissance)
Memory trick: RWCDEIC: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives – The attacker's journey.