Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) practice questions
209 free questions with answers and explanations.
- 201.A security architect is designing a new system that needs to ensure that when a user submits a critical transaction, like a financial transfer, they cannot later deny having initiated that specific transaction. Which cybersecurity principle is primarily addressed by implementing mechanisms such as digital signatures for this requirement?Cybersecurity Fundamentals
- 202.A network administrator is configuring a new firewall for a data center. The policy explicitly states that all traffic originating from the internal network destined for any external IP address on port 80 (HTTP) should be allowed, while all other outbound traffic is blocked by default. Which type of firewall rule is primarily being implemented to block the 'other outbound traffic'?Cybersecurity Fundamentals
- 203.A security operations center (SOC) analyst is investigating an incident where an external attacker successfully gained initial access to a company's network by exploiting a known vulnerability in an outdated web server. The attacker then used this access to map the internal network and identify other vulnerable systems. According to the Cyber Kill Chain model, which stage does the act of identifying other vulnerable systems fall under?Cybersecurity Fundamentals
- 204.A network security administrator is reviewing firewall logs and notices a high volume of outbound traffic on TCP port 25 from an internal server that typically does not send email. What type of activity is most likely indicated by this observation?Network Security
- 205.A Security Operations Center (SOC) team is continuously collecting logs from firewalls, servers, and applications across their enterprise network. They use a system that aggregates these logs, correlates events from different sources, and generates alerts based on predefined rules. Which type of security tool are they primarily utilizing for this function?Security Operations
- 206.A company is implementing a new security policy that requires all internal network traffic between different departments (e.g., Finance and HR) to be isolated from each other, even though they reside on the same physical network infrastructure. This isolation should prevent direct communication unless explicitly allowed by specific security rules. Which network security concept is being applied here?Network Security
- 207.A cybersecurity analyst is investigating a suspected malware infection that is attempting to communicate with an external command-and-control (C2) server. The analyst observes encrypted traffic leaving the network on non-standard ports. Which network security technology is BEST suited to detect and potentially block this type of anomalous, encrypted communication based on its content or behavior, even if the port is unusual?Network Security
- 208.A network technician is configuring a new switch in a data center. To enhance security and prevent unauthorized devices from connecting to the network, the technician wants to ensure that only specific, known MAC addresses are allowed on certain switch ports. If an unknown MAC address attempts to connect, the port should automatically shut down. Which switch security feature should the technician configure?Network Security
- 209.A Security Operations Center (SOC) analyst is reviewing network traffic logs and observes a sudden, significant increase in outbound data from an internal server that typically has low outbound traffic. The destination IP addresses are varied and appear to be external. Which phase of the incident response process is the analyst currently engaged in?Security Operations