PCCP Exam Questions
80 real PCCP exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Which technology helps Security Operations Center (SOC) teams identify heap spray attacks on company-owned laptops?
- Question #2
What are two common lifecycle stages for an advanced persistent threat (APT) that is infiltrating a network? (Choose two.)
- Question #3
A high-profile company executive receives an urgent email containing a malicious link. The sender appears to be from the IT department of the company, and the email requests an upd...
- Question #4
Which next-generation firewall (NGFW) deployment option provides full application visibility into Kubernetes environments?
- Question #5
Which type of firewall should be implemented when a company headquarters is required to have redundant power and high processing power?
- Question #6
Which statement describes the process of application allow listing?
- Question #7
Which component of the AAA framework verifies user identities so they may access the network?
- Question #8
Which capability does Cloud Security Posture Management (CSPM) provide for threat detection within Prisma Cloud?
- Question #9
Which type of system collects data and uses correlation rules to trigger alarms?
- Question #10
What is the purpose of host-based architectures?
- Question #11
What is the function of an endpoint detection and response (EDR) tool?
- Question #12
What type of attack redirects the traffic of a legitimate website to a fake website?
- Question #13
Which two processes are critical to a security information and event management (SIEM) platform? (Choose two.)
- Question #14
Which Palo Alto Networks solution has replaced legacy IPS solutions?
- Question #15
Which type of system is a user entity behavior analysis (UEBA) tool?
- Question #16
What is a function of SSL/TLS decryption?
- Question #17
Which feature is part of an intrusion prevention system (IPS)?
- Question #18
What are two capabilities of identity threat detection and response (ITDR)? (Choose two.)
- Question #19
Which type of attack involves sending data packets disguised as queries to a remote server, which then sends the data back to the attacker?
- Question #20
Which service is encompassed by serverless architecture?
- Question #21
Which architecture model uses virtual machines (VMs) in a public cloud environment?
- Question #22
Which two statements apply to SaaS financial botnets? (Choose two.)
- Question #23
What is an event-driven snippet of code that runs on managed infrastructure?
- Question #24
Which type of attack obscures its presence while attempting to spread to multiple hosts in a network?
- Question #25
What is a dependency for the functionality of signature-based malware detection?
- Question #26
When does a TLS handshake occur?
- Question #27
Which characteristic of advanced malware makes it difficult to detect?
- Question #28
Which type of attack includes exfiltration of data as a primary objective?
- Question #29
What is an operation of an Attack Surface Management (ASM) platform?
- Question #30
What are two advantages of security orchestration, automation, and response (SOAR)? (Choose two.)
- Question #31
Which component of cloud security uses automated testing with static application security testing (SAST) to identify potential threats?
- Question #32
Which technology secures software-as-a-service (SaaS) applications and network data, and also enforces compliance policies for application access?
- Question #33
Which feature of cloud-native security platforms (CNSPs) focuses on protecting virtual machine (VM), container, and serverless deployments against application-level attacks during...
- Question #34
Which component of cloud security is used to identify misconfigurations during the development process?
- Question #35
What is a purpose of workload security on a Cloud Native Security Platform (CNSP)?
- Question #36
What is required for an effective Attack Surface Management (ASM) process?
- Question #37
Which component of the AAA framework regulates user access and permissions to resources?
- Question #38
What are two limitations of signature-based anti-malware software? (Choose two.)
- Question #39
What would allow a security team to inspect TLS encapsulated traffic?
- Question #40
What is an advantage of virtual firewalls over physical firewalls for internal segmentation when placed in a data center?
- Question #41
What is a reason IoT devices are more susceptible to command-and-control (C2) attacks?
- Question #42
Which tool's analysis data gives security operations teams insight into their environment's risks from exposed services?
- Question #43
Why is compliance management important in cloud security?
- Question #44
What differentiates a SIEM from a SOAR platform?
- Question #45
Which of the following best describes a DDoS botnet?
- Question #46
How does DNS Security prevent cyber threats?
- Question #47
Which methodology does Identity Threat Detection and Response (ITDR) use?
- Question #48
Which technology grants enhanced visibility and threat prevention locally on a device?
- Question #49
What are two examples of an attacker using social engineering? (Choose two.)
- Question #50
Which two services does a managed detection and response (MDR) solution provide? (Choose two.)