Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
1. When is it impossible to secure SaaS data?
When a user uses an unmanaged device to access an unsanctioned SaaS
instance.
When a user uses a managed device to access an unsanctioned SaaS instance.
When a user uses an unmanaged device to access a sanctioned SaaS instance.
When a user uses a managed device to access a sanctioned SaaS instance.: When
a user uses an unmanaged device to access an unsanctioned SaaS instance.
2. Which group is primarily motivated by money?
hacktivists
cybercriminals
cyberterrorists
state-affiliated groups: Cybercriminals
3. Which two malware types are self-replicating? (Choose two.)
logic bomb
back door
virus
trojan horse
worm: Virus
Worm
4. Which type of attack includes an email advertisement for a dry cleaning
service?
spamming
phishing
spear phishing
whaling: Spamming
5. Who is the most likely target of social engineering?
Executive management, because it has the most permissions.
, Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
Senior IT engineers, because the attacker hopes to get them to disable the
security infrastructure.
Junior people, because they are easier to stress and probably not as well
trained.
The accounting department, because it can wire money directly to the attack-
er's account.: Junior people, because they are easier to stress and probably not as well trained.
6. Which two attacks typically use a botnet? (Choose two.)
Ssocial engineering
DoS
DDoS
Sending spam to a lengthy mailing list
Spear phishing: DDoS
Sending spam to a lengthy mailing list.
7. What is the name of the attack in which the attacker gets the victim to connect
to an access point the attack controls?
Person in the middle
Man in the middle
Access point in the middle
Access point masquerading: Man in the middle
8. Which Palo Alto Networks product suite is used to manage alerts, obtain
additional information, and orchestrate responses?
Strata
Prisma
Cortex
WildFire: Cortex
9. On which device do you configure VLANs?
wireless repeater
hub
, Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
switch
router: Switch
10. Which DNS record type do you use to find the IPv4 address of a host?
A
AAAA
PTR
MX: A
11. Which device is M2M (machine to machine)?
Internet-connected TV
home alarm that dials the police for response
car GPS
temperature sensor connected to a fire suppression system: Temperature sensor
connected to a fire suppression system.
12. How many bytes are in an IPv6 address?
4
8
16
32: 16
13. Which three security functions are integrated with a UTM device? (Choose
three.)
cloud access security broker (CASB)
firewall
Remote Browser Isolation (RBI)
Intrusion Detection System (IDS)
anti-spam
DevOps automation: firewall
Intrusion Detection System (IDS)
anti-spam
, Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
14. Which type of malware protection requires in-depth knowledge of applica-
tions and how they communicate?
signature-based
container-based
application allow lists
anomaly detection: Container-based
15. Which Panorama object is used to manage the security policy?
template
device group
virtual system
Decryption Profile: Device group
16. Which feature of the NGFW can distinguish between reading Facebook and
commenting?
App-ID
Content-ID
User-ID
Global Protect: App-ID
17. Question 17 of 70
What is the collective term for software versions, OS settings, and configuration
file settings?
configuration items
configurable values
computer settings
the configuration: Configuration items
18. Question 18 of 70
A provider's applications run on a cloud infrastructure. The consumer does
not manage or control the underlying infrastructure. Which cloud computing
service model is this?
Study online at https://quizlet.com/_hr8e2e
1. When is it impossible to secure SaaS data?
When a user uses an unmanaged device to access an unsanctioned SaaS
instance.
When a user uses a managed device to access an unsanctioned SaaS instance.
When a user uses an unmanaged device to access a sanctioned SaaS instance.
When a user uses a managed device to access a sanctioned SaaS instance.: When
a user uses an unmanaged device to access an unsanctioned SaaS instance.
2. Which group is primarily motivated by money?
hacktivists
cybercriminals
cyberterrorists
state-affiliated groups: Cybercriminals
3. Which two malware types are self-replicating? (Choose two.)
logic bomb
back door
virus
trojan horse
worm: Virus
Worm
4. Which type of attack includes an email advertisement for a dry cleaning
service?
spamming
phishing
spear phishing
whaling: Spamming
5. Who is the most likely target of social engineering?
Executive management, because it has the most permissions.
, Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
Senior IT engineers, because the attacker hopes to get them to disable the
security infrastructure.
Junior people, because they are easier to stress and probably not as well
trained.
The accounting department, because it can wire money directly to the attack-
er's account.: Junior people, because they are easier to stress and probably not as well trained.
6. Which two attacks typically use a botnet? (Choose two.)
Ssocial engineering
DoS
DDoS
Sending spam to a lengthy mailing list
Spear phishing: DDoS
Sending spam to a lengthy mailing list.
7. What is the name of the attack in which the attacker gets the victim to connect
to an access point the attack controls?
Person in the middle
Man in the middle
Access point in the middle
Access point masquerading: Man in the middle
8. Which Palo Alto Networks product suite is used to manage alerts, obtain
additional information, and orchestrate responses?
Strata
Prisma
Cortex
WildFire: Cortex
9. On which device do you configure VLANs?
wireless repeater
hub
, Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
switch
router: Switch
10. Which DNS record type do you use to find the IPv4 address of a host?
A
AAAA
PTR
MX: A
11. Which device is M2M (machine to machine)?
Internet-connected TV
home alarm that dials the police for response
car GPS
temperature sensor connected to a fire suppression system: Temperature sensor
connected to a fire suppression system.
12. How many bytes are in an IPv6 address?
4
8
16
32: 16
13. Which three security functions are integrated with a UTM device? (Choose
three.)
cloud access security broker (CASB)
firewall
Remote Browser Isolation (RBI)
Intrusion Detection System (IDS)
anti-spam
DevOps automation: firewall
Intrusion Detection System (IDS)
anti-spam
, Palo Alto PCCET
Study online at https://quizlet.com/_hr8e2e
14. Which type of malware protection requires in-depth knowledge of applica-
tions and how they communicate?
signature-based
container-based
application allow lists
anomaly detection: Container-based
15. Which Panorama object is used to manage the security policy?
template
device group
virtual system
Decryption Profile: Device group
16. Which feature of the NGFW can distinguish between reading Facebook and
commenting?
App-ID
Content-ID
User-ID
Global Protect: App-ID
17. Question 17 of 70
What is the collective term for software versions, OS settings, and configuration
file settings?
configuration items
configurable values
computer settings
the configuration: Configuration items
18. Question 18 of 70
A provider's applications run on a cloud infrastructure. The consumer does
not manage or control the underlying infrastructure. Which cloud computing
service model is this?