Step2Study
IT & TechnologyPCNSA100% Free

Palo Alto Networks Certified Network Security Administrator (PCNSA)

Practice bank
205 Qs
Real exam
50 Qs
Time limit
90 min
Passing
Pass/Fail

Exam blueprint

Cybersecurity Fundamentals
15%
Palo Alto Networks Security Platform
20%
Initial Configuration and Management
25%
Security Policy Configuration
25%
Monitoring and Reporting
15%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 162 min · pass 70% · 205 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Palo Alto Networks Certified Network Security Administrator (PCNSA) practice test questions

Sample questions from the 205-question bank, with answers and explanations.

All questions
  1. 1. A security engineer needs to configure a Palo Alto Networks firewall to ensure that the device's clock is accurately synchronized with an external time source. Which protocol should be used to achieve this, and where is it typically configured on the firewall?

    Initial Configuration and Management

    • A. DNS; Network > DNS Proxies
    • B. NTP; Device > Setup > Services
    • C. SSH; Device > Setup > Management
    • D. SNMP; Device > Setup > Management
    Show answer

    B. NTP; Device > Setup > Services

    Network Time Protocol (NTP) is used to synchronize device clocks. On Palo Alto Networks firewalls, NTP server settings are configured under Device > Setup > Services.

  2. 2. A network administrator needs to update the PAN-OS software on a Palo Alto Networks firewall. Before initiating the upgrade, which critical step must be performed to ensure a rollback option is available in case of unforeseen issues?

    Initial Configuration and Management

    • A. Restart the management server process to clear its cache.
    • B. Disable all security policies to prevent traffic disruption.
    • C. Commit the running configuration to non-volatile memory.
    • D. Create a configuration backup and export it off the device.
    Show answer

    D. Create a configuration backup and export it off the device.

    Before any major software upgrade, it is crucial to create a configuration backup and export it off the device. This ensures that if the upgrade fails or causes unexpected problems, a known good configuration can be restored to the firewall.

  3. 3. A network engineer wants to configure a virtual wire deployment on a Palo Alto Networks firewall. They have two physical interfaces, ethernet1/1 and ethernet1/2, that need to be part of the virtual wire. Which configuration object must be created and applied to these interfaces?

    Initial Configuration and Management

    • A. A Tap interface for passive monitoring.
    • B. A VLAN interface with an associated VLAN ID.
    • C. A Virtual Wire interface with a Virtual Wire object.
    • D. A Layer 3 interface with a static IP address.
    Show answer

    C. A Virtual Wire interface with a Virtual Wire object.

    For a virtual wire deployment, you must configure the physical interfaces as 'Virtual Wire' type interfaces and then assign them to a 'Virtual Wire' object. This object logically binds the two interfaces together, allowing the firewall to function as a bump-in-the-wire without requiring IP addresses on the interfaces.

  4. 4. A network administrator is performing the initial setup of a new Palo Alto Networks firewall. After connecting to the management port, they attempt to access the web interface but receive a connection refused error. Which of the following is the MOST likely cause for this issue if no other configuration has been performed?

    Initial Configuration and Management

    • A. The administrator's workstation is on a different subnet than the firewall's default management IP.
    • B. The firewall's management interface is configured for DHCP, but no DHCP server is available.
    • C. The administrative access type (HTTP/HTTPS) is not enabled on the management interface.
    • D. The firewall's default factory configuration requires a console cable for initial web interface enablement.
    Show answer

    A. The administrator's workstation is on a different subnet than the firewall's default management IP.

    By default, Palo Alto Networks firewalls have a static management IP address (192.168.1.1/24). If the administrator's workstation is not on the same subnet, they will not be able to reach the firewall's web interface.

  5. 5. A company is deploying a Palo Alto Networks firewall and needs to ensure that only authorized administrators can access the device's management interface. They want to restrict access based on the source IP address of the administrative workstation. Where would this restriction be configured?

    Initial Configuration and Management

    • A. Network > Interfaces > Management Interface Settings
    • B. Device > Setup > Management > Permitted IP Addresses
    • C. Policies > Security > Management Access Rule
    • D. Network > Zones > Management Zone Settings
    Show answer

    B. Device > Setup > Management > Permitted IP Addresses

    To restrict administrative access to the firewall's management interface based on source IP address, you configure 'Permitted IP Addresses' under Device > Setup > Management. This explicitly defines which IP addresses are allowed to connect to the MGT interface.

  6. 6. A network engineer is configuring a Palo Alto Networks firewall to forward logs to an external syslog server. After configuring the syslog server profile, they notice that no logs are being sent. Which of the following is a common reason for this issue related to initial configuration?

    Initial Configuration and Management

    • A. The management interface has not been assigned a default gateway.
    • B. The syslog server's IP address is configured with an incorrect port number.
    • C. The syslog server profile is not associated with a log forwarding profile.
    • D. The firewall clock is not synchronized with an NTP server.
    Show answer

    C. The syslog server profile is not associated with a log forwarding profile.

    Even after creating a syslog server profile, logs will not be forwarded unless that profile is referenced and applied within a Log Forwarding Profile, which is then attached to security policies or other logging-enabled features.

  7. 7. A network security team is implementing a new Palo Alto Networks firewall and requires a highly available solution to minimize downtime. They choose to deploy two firewalls in an Active/Passive HA configuration. Which of the following statements accurately describes a key characteristic or requirement of this setup?

    Initial Configuration and Management

    • A. A dedicated HA link is used for heartbeats and state synchronization.
    • B. Session synchronization is not supported in Active/Passive mode.
    • C. Both firewalls actively process traffic, sharing the load equally.
    • D. Each firewall must have a unique virtual router ID for proper failover.
    Show answer

    A. A dedicated HA link is used for heartbeats and state synchronization.

    In an Active/Passive HA configuration, a dedicated HA link (often an Ethernet cable between two interfaces) is crucial for exchanging heartbeats to monitor peer status and synchronizing session and configuration state between the active and passive devices.

  8. 8. A network security administrator encounters an issue where the Palo Alto Networks firewall is unable to resolve external domain names, impacting features like URL filtering and cloud-based threat intelligence updates. The internal DNS servers are functioning correctly. Which basic network configuration step was MOST likely overlooked on the firewall itself?

    Initial Configuration and Management

    • A. The default gateway for the management interface is not configured or is incorrect.
    • B. The firewall is not subscribed to the Threat Prevention license.
    • C. The DNS proxy settings are misconfigured or disabled.
    • D. The firewall's management interface is configured with a static IP address.
    Show answer

    A. The default gateway for the management interface is not configured or is incorrect.

    If the firewall cannot resolve external domain names, it indicates an issue with its own ability to reach external DNS servers. The most common reason for this, assuming internal DNS works, is that the firewall's management interface (which it uses for its own DNS queries, updates, etc.) cannot reach the internet because its default gateway is missing or incorrect.

  9. 9. A company has purchased a new Palo Alto Networks firewall and needs to enable advanced security features such as Threat Prevention, URL Filtering, and WildFire. Which of the following is the correct order of operations after the base PAN-OS software is installed and the firewall has internet connectivity?

    Initial Configuration and Management

    • A. Install content updates, activate licenses, download and install software updates.
    • B. Download and install software updates, activate licenses, install content updates.
    • C. Activate licenses, download and install software updates, install content updates.
    • D. Install content updates, download and install software updates, activate licenses.
    Show answer

    C. Activate licenses, download and install software updates, install content updates.

    To enable advanced features, the correct sequence is: first, activate the purchased licenses on the firewall, as these subscriptions enable the features. Then, download and install any available PAN-OS software updates to ensure the firewall is running the latest stable version. Finally, install content updates (applications, threats, URL categories) which are often dependent on active licenses and a compatible PAN-OS version.

  10. 10. A network administrator is configuring network interfaces on a Palo Alto Networks firewall. They want to create a subinterface on ethernet1/1 to handle traffic for VLAN 100. Which of the following statements is true regarding this configuration?

    Initial Configuration and Management

    • A. The subinterface for VLAN 100 will have an interface name like ethernet1/1.100.
    • B. The subinterface will be configured as a Layer 2 interface and assigned to a VLAN object.
    • C. A separate virtual router must be created for each VLAN subinterface.
    • D. The physical interface ethernet1/1 must be configured as a Layer 3 interface type.
    Show answer

    A. The subinterface for VLAN 100 will have an interface name like ethernet1/1.100.

    When creating a subinterface for a specific VLAN on a Palo Alto Networks firewall, the naming convention typically appends the VLAN ID to the physical interface name. For example, a subinterface for VLAN 100 on ethernet1/1 would be named ethernet1/1.100.

  11. 11. A security analyst is reviewing the administrative accounts configured on a Palo Alto Networks firewall. They notice that the 'admin' account still uses its default password. What is the MOST immediate security risk associated with this configuration?

    Initial Configuration and Management

    • A. The firewall will not be able to receive software updates.
    • B. The firewall's performance will be degraded due to weak encryption.
    • C. The default password is susceptible to brute-force attacks.
    • D. Unauthorized access to the firewall's configuration and control.
    Show answer

    D. Unauthorized access to the firewall's configuration and control.

    Leaving the default 'admin' password unchanged on a Palo Alto Networks firewall poses a significant security risk because it allows anyone with knowledge of the default credentials to gain unauthorized, full administrative access to the device, potentially leading to compromise of the entire network.

  12. 12. A network architect is designing a high-availability solution for a critical data center using Palo Alto Networks firewalls. They have chosen an Active/Active HA configuration. Which of the following is a primary benefit of choosing Active/Active over Active/Passive HA?

    Initial Configuration and Management

    • A. Simplified configuration and management.
    • B. Higher throughput and resource utilization.
    • C. Automatic software updates without downtime.
    • D. Reduced licensing costs due to shared resources.
    Show answer

    B. Higher throughput and resource utilization.

    Active/Active HA allows both firewalls to actively process traffic, effectively doubling the potential throughput and utilizing the resources of both devices simultaneously, unlike Active/Passive where one device is idle.

  13. 13. A network administrator needs to register a new Palo Alto Networks firewall with their support portal to download software updates and content definitions. Which unique identifier is required for this registration process?

    Initial Configuration and Management

    • A. PAN-OS Software Version currently installed.
    • B. Model Number of the firewall device.
    • C. MAC Address of the management interface.
    • D. Serial Number of the firewall device.
    Show answer

    D. Serial Number of the firewall device.

    Palo Alto Networks firewalls are registered and managed on the support portal using their unique Serial Number. This number identifies the specific hardware device for licensing, support, and content updates.

  14. 14. A security team is implementing a new policy to ensure that all network devices, including firewalls, routers, and switches, are hardened against common vulnerabilities. Which of the following is a primary security best practice for hardening network devices?

    Cybersecurity Fundamentals

    • A. Using default credentials for administrative access.
    • B. Keeping all unnecessary services and ports open for future use.
    • C. Disabling all logging to reduce performance overhead.
    • D. Implementing strong, unique passwords and multi-factor authentication (MFA).
    Show answer

    D. Implementing strong, unique passwords and multi-factor authentication (MFA).

    Implementing strong, unique passwords and multi-factor authentication (MFA) is a fundamental security best practice for hardening network devices, as it significantly reduces the risk of unauthorized access through credential compromise.

  15. 15. A financial institution is implementing stringent security controls to protect customer transaction data. They require that data be encrypted both when stored on servers (at rest) and when being transmitted between systems (in transit). Which security principle is being directly addressed by this dual encryption requirement?

    Cybersecurity Fundamentals

    • A. Confidentiality
    • B. Non-repudiation
    • C. Integrity
    • D. Availability
    Show answer

    A. Confidentiality

    Confidentiality ensures that sensitive information is accessible only to authorized individuals. Encrypting data both at rest and in transit directly protects against unauthorized disclosure, thereby upholding the principle of confidentiality.

  16. 16. A security analyst is investigating a series of targeted attacks against a government agency. The attacks demonstrate a high degree of sophistication, involve custom malware, and appear to be funded and directed by a well-resourced entity with specific geopolitical objectives. Which type of threat actor is most likely responsible for these attacks?

    Cybersecurity Fundamentals

    • A. Insider threat
    • B. Cyber criminal
    • C. Nation-state actor
    • D. Script kiddie
    Show answer

    C. Nation-state actor

    Nation-state actors are characterized by their high sophistication, custom tools, and resources, often driven by political or economic espionage, which aligns with the scenario's description of targeted attacks on a government agency with geopolitical objectives.

  17. 17. A large enterprise is experiencing a significant increase in phishing attempts targeting its employees. These emails often contain malicious links or attachments. The company has already implemented email filtering and user awareness training. To further strengthen its defenses against this specific attack vector, which additional security control would provide the most immediate and effective improvement?

    Cybersecurity Fundamentals

    • A. Utilizing a Security Orchestration, Automation, and Response (SOAR) platform.
    • B. Implementing a robust Data Loss Prevention (DLP) solution.
    • C. Enabling Multi-Factor Authentication (MFA) for all user accounts.
    • D. Deploying a Network Access Control (NAC) system.
    Show answer

    C. Enabling Multi-Factor Authentication (MFA) for all user accounts.

    While email filtering and training reduce phishing attempts, MFA directly counters the most common outcome of successful phishing: credential compromise. Even if a user falls for a phishing scam and enters their password, MFA prevents an attacker from logging in without the second factor.

  18. 18. A cybersecurity team is evaluating different methods for authenticating users to a critical internal application. They want to implement a solution that provides a very high level of assurance by requiring users to present something they know (e.g., password), something they have (e.g., security token), and something they are (e.g., fingerprint). Which authentication method are they planning to deploy?

    Cybersecurity Fundamentals

    • A. Single Sign-On (SSO)
    • B. Biometric Authentication
    • C. Multi-Factor Authentication (MFA)
    • D. Knowledge-Based Authentication (KBA)
    Show answer

    C. Multi-Factor Authentication (MFA)

    The scenario describes requiring factors from three distinct categories: knowledge (password), possession (token), and inherence (fingerprint). This combination is known as Multi-Factor Authentication (MFA), specifically requiring three factors.

  19. 19. A company is reviewing its security posture after a competitor suffered a data breach due to a compromised third-party vendor. The company wants to evaluate the potential risks associated with its own suppliers, partners, and cloud service providers. Which cybersecurity concept are they focusing on?

    Cybersecurity Fundamentals

    • A. Insider Threat
    • B. Supply Chain Attack
    • C. Denial of Service (DoS)
    • D. Social Engineering
    Show answer

    B. Supply Chain Attack

    The scenario describes a concern related to third-party vendors and their potential to introduce vulnerabilities or serve as an attack vector, which is precisely the definition of a supply chain attack.

  20. 20. A company is experiencing slow network performance and intermittent service outages. A preliminary investigation reveals unusual outbound traffic to various external IP addresses, as well as a significant increase in DNS queries originating from internal workstations. The security team suspects a large number of internal machines might be infected and participating in a botnet. Which security control is primarily designed to detect and prevent such command-and-control (C2) communications?

    Cybersecurity Fundamentals

    • A. Data Loss Prevention (DLP)
    • B. Web Application Firewall (WAF)
    • C. Endpoint Detection and Response (EDR)
    • D. Intrusion Prevention System (IPS)
    Show answer

    D. Intrusion Prevention System (IPS)

    An Intrusion Prevention System (IPS) is designed to monitor network traffic for malicious activity and can actively block suspicious C2 communications based on signatures, behavioral analysis, or known bad IP addresses, thus preventing botnet control.

  21. 21. During a forensic investigation, a security analyst discovers that an attacker gained initial access to an internal network by exploiting a vulnerability in a publicly accessible web application. The attacker then used this foothold to scan internal systems, identify a misconfigured database, and exfiltrate sensitive customer data. This sequence of events best illustrates which phase of the cyber attack kill chain?

    Cybersecurity Fundamentals

    • A. Exploitation
    • B. Delivery
    • C. Actions on Objectives
    • D. Weaponization
    Show answer

    C. Actions on Objectives

    The cyber attack kill chain outlines the stages of a typical cyber attack. 'Actions on Objectives' is the final stage where the attacker achieves their ultimate goal, which in this scenario is 'exfiltrate sensitive customer data' after gaining access and reconnaissance. While exploitation occurred, the full scenario describes the successful completion of the attacker's ultimate goal.

  22. 22. A security audit reveals that several critical servers in an organization are running outdated operating systems with known unpatched vulnerabilities. Despite awareness, the updates have been consistently delayed due to concerns about application compatibility and downtime. This scenario primarily represents a failure in which security best practice?

    Cybersecurity Fundamentals

    • A. Vulnerability Management
    • B. Data Loss Prevention (DLP)
    • C. Security Awareness Training
    • D. Incident Response Planning
    Show answer

    A. Vulnerability Management

    Vulnerability management is the continuous process of identifying, assessing, and remediating security vulnerabilities in systems and software. The scenario explicitly describes a failure to remediate known vulnerabilities due to operational concerns, which is a breakdown in the vulnerability management process.

  23. 23. A small business owner is concerned about employees accidentally downloading malware from malicious websites. Which cybersecurity best practice should be implemented to prevent this common threat?

    Cybersecurity Fundamentals

    • A. Implement a strong web content filtering solution.
    • B. Regularly back up all company data to an offsite location.
    • C. Encrypt all sensitive data stored on company servers.
    • D. Conduct quarterly penetration testing on the network.
    Show answer

    A. Implement a strong web content filtering solution.

    Web content filtering directly addresses the risk of employees accessing malicious websites and downloading malware by blocking access to known dangerous sites or categories.

  24. 24. A cybersecurity team is performing a post-incident analysis after a successful data breach. They discover that the attackers gained initial access by exploiting a known vulnerability in an outdated web server, then moved laterally through the network to exfiltrate sensitive customer data. Which stage of the cyber attack kill chain was exploited for initial access?

    Cybersecurity Fundamentals

    • A. Weaponization
    • B. Delivery
    • C. Reconnaissance
    • D. Exploitation
    Show answer

    D. Exploitation

    The scenario explicitly states that attackers gained initial access by 'exploiting a known vulnerability'. In the cyber attack kill chain, exploitation is the stage where the attacker leverages a vulnerability to gain access to the target system.

  25. 25. A security auditor is reviewing an organization's network architecture and discovers that all internal network segments (e.g., HR, Finance, R&D) are directly connected to each other without any intermediary security devices or access controls. This allows any compromised device in one segment to potentially access resources in any other segment. Which security best practice is most notably absent in this architecture?

    Cybersecurity Fundamentals

    • A. Network Segmentation
    • B. Load Balancing
    • C. Network Address Translation (NAT)
    • D. Virtual Private Network (VPN)
    Show answer

    A. Network Segmentation

    Network segmentation involves dividing a network into smaller, isolated segments, often with security controls between them. The absence of such divisions, allowing direct access between sensitive segments, indicates a lack of network segmentation.

Palo Alto Networks Certified Network Security Administrator (PCNSA) flashcards

Tap a card to flip it. 166 flashcards in the full deck.

  • NTP Configuration

    Flip card

    Network Time Protocol (NTP) is essential for accurate logging, certificate validation, and policy scheduling on a firewall.

    • Ensures accurate timestamps for logs.
    • Critical for certificate validity checks.
    • Configured under Device > Setup > Services.
    Study this card →
  • PAN-OS Upgrade Best Practice

    Flip card

    Always back up the firewall configuration before a PAN-OS upgrade to enable rollback and disaster recovery.

    • Export configuration to an external location.
    • Allows restoration to a known working state.
    • Prevents data loss during upgrade failures.
    Study this card →
  • Virtual Wire

    Flip card

    A deployment mode for Palo Alto Networks firewalls where two interfaces are logically bound to act as a 'bump-in-the-wire', inspecting traffic without requiring IP addresses on those interfaces.

    • Transparently inserts the firewall into a network segment.
    • Requires two physical interfaces.
    • Uses 'Virtual Wire' interface type and 'Virtual Wire' object.
    Study this card →
  • Default Management IP

    Flip card

    Palo Alto Networks firewalls come with a pre-configured static IP address on their management interface for initial setup.

    • Default IP is 192.168.1.1/24.
    • HTTPS is enabled by default for web UI access.
    • Requires connecting to the MGT port.
    Study this card →
  • Management Access Restriction

    Flip card

    The ability to limit which source IP addresses are permitted to access a Palo Alto Networks firewall's management interface (web UI, SSH, SNMP).

    • Enhances security by reducing attack surface.
    • Configured under Device > Setup > Management.
    • Allows specific IP addresses or subnets.
    Study this card →
  • Log Forwarding Profile

    Flip card

    A configuration object on Palo Alto Networks firewalls that specifies which logs (traffic, threat, system, etc.) to forward and to which external destinations (syslog, SNMP, email, HTTP).

    • Links log types to external server profiles.
    • Applied to security rules or other logging features.
    • Crucial for sending logs off the firewall.
    Study this card →
  • Active/Passive HA

    Flip card

    A high availability deployment where one firewall actively processes traffic while the other remains in a passive, synchronized standby state, ready to take over upon failure.

    • One firewall is active, one is passive.
    • Requires dedicated HA links for control and data plane synchronization.
    • Ensures session continuity during failover.
    Study this card →
  • Firewall DNS Resolution

    Flip card

    Palo Alto Networks firewalls rely on DNS for their own operations, including content updates, cloud services, and external name resolution, which requires proper network configuration.

    • Firewall uses its management interface for its own DNS queries.
    • Requires correct DNS server and default gateway configuration.
    • Impacts updates, cloud services, and URL filtering.
    Study this card →
  • Palo Alto Initial Feature Enablement

    Flip card

    The proper sequence for enabling advanced security features on a Palo Alto Networks firewall involves activating licenses, updating PAN-OS, and then installing content definitions.

    • Licenses enable feature functionality.
    • PAN-OS updates ensure platform stability and compatibility.
    • Content updates provide the latest threat intelligence.
    Study this card →
  • Palo Alto Subinterface Naming

    Flip card

    Palo Alto Networks subinterfaces are typically named by appending the VLAN ID to the physical interface name (e.g., ethernet1/1.100) and are used for VLAN tagging.

    • Used to handle tagged VLAN traffic.
    • Can be Layer 2 or Layer 3.
    • Commonly used with Virtual Routers for inter-VLAN routing.
    Study this card →
  • Default Admin Password Risk

    Flip card

    Using default credentials for administrative accounts on any network device, especially firewalls, creates a critical vulnerability for unauthorized access and system compromise.

    • Default admin/admin is widely known.
    • Allows full control of the firewall.
    • Changes should be made during initial setup.
    Study this card →
  • Active/Active HA Benefit

    Flip card

    Active/Active High Availability on Palo Alto Networks firewalls enables both devices to process traffic simultaneously, improving performance and resource utilization.

    • Both firewalls are active traffic processors.
    • Increases total throughput capacity.
    • More complex to configure than Active/Passive.
    Study this card →
  • Firewall Registration ID

    Flip card

    The Serial Number is the unique identifier for a Palo Alto Networks firewall used for registration, licensing, and support portal access.

    • Found on the device label and in the web UI/CLI.
    • Required for all licensing and support interactions.
    • Distinguishes individual hardware units.
    Study this card →
  • Device Hardening

    Flip card

    The process of securing a system by reducing its attack surface and mitigating potential vulnerabilities.

    • Involves removing unnecessary software, services, and accounts.
    • Includes applying security patches and updates regularly.
    • Requires configuring strong authentication mechanisms and access controls.
    Study this card →
  • CIA Triad

    Flip card

    A fundamental model for cybersecurity, representing the three core security goals: Confidentiality, Integrity, and Availability.

    • Confidentiality: Protecting data from unauthorized access.
    • Integrity: Ensuring data accuracy and preventing unauthorized modification.
    • Availability: Guaranteeing access to legitimate users when needed.
    Study this card →
  • Nation-state actor

    Flip card

    A type of threat actor that is sponsored by a government to conduct cyber espionage, sabotage, or other cyber operations against other nations or entities.

    • Highly sophisticated and well-funded.
    • Often uses custom malware and zero-day exploits.
    • Motivated by geopolitical objectives, intelligence gathering, or economic advantage.
    Study this card →
  • Multi-Factor Authentication (MFA) against Phishing

    Flip card

    MFA significantly mitigates the risk of successful phishing attacks by requiring an additional verification factor beyond a password, making stolen credentials less useful to attackers.

    • Protects against credential stuffing and stolen passwords.
    • Adds a layer of security even if phishing is successful.
    • Considered a critical control for account security.
    Study this card →
  • Multi-Factor Authentication (MFA)

    Flip card

    An authentication method that requires a user to provide two or more verification factors to gain access to a resource, often categorized as something you know, something you have, and something you are.

    • Significantly improves security over single-factor authentication.
    • Combines different types of authentication factors.
    • Commonly used to protect sensitive accounts.
    Study this card →
  • Supply Chain Attack

    Flip card

    A cyberattack that targets an organization by compromising less secure elements in its supply chain, such as third-party vendors, software providers, or hardware manufacturers.

    • Exploits trust relationships.
    • Can affect many downstream customers.
    • Difficult to detect and prevent.
    Study this card →
  • Intrusion Prevention System (IPS)

    Flip card

    A network security device that monitors network and/or system activities for malicious or unwanted behavior and can react in real-time to block or prevent those activities.

    • Active prevention of attacks.
    • Operates inline with network traffic.
    • Detects and blocks known malicious patterns (signatures) and anomalies.
    Study this card →
  • Cyber Attack Kill Chain

    Flip card

    A model developed by Lockheed Martin that outlines the stages of a typical cyber attack, from reconnaissance to achieving the attacker's objective.

    • Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives.
    • Helps security teams understand and disrupt attack progression.
    • Focuses on preventing the attacker from achieving their goal.
    Study this card →
  • Vulnerability Management

    Flip card

    The cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities in systems and applications.

    • Continuous process.
    • Involves scanning, assessment, and patching.
    • Reduces attack surface and risk.
    Study this card →
  • Web Content Filtering

    Flip card

    A security measure that controls access to websites based on categories, reputation, or specific URLs, often used to block malicious or inappropriate content.

    • Prevents access to known malicious sites.
    • Can enforce acceptable use policies.
    • Reduces malware infection risk from web browsing.
    Study this card →
  • Exploitation (Cyber Kill Chain)

    Flip card

    The stage in the cyber kill chain where an attacker leverages a vulnerability in a system or application to gain access or control.

    • Occurs after delivery of a weaponized payload.
    • Aims to execute code or gain unauthorized access.
    • Often involves specific vulnerabilities like unpatched software or misconfigurations.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.