PCCP Sample Questions

PCCP Sample Questions & Answers

Spans cloud architectures and their security challenges, the single biggest weight, plus Zero Trust and MITRE ATT&CK ideas, the AAA model, firewall and microsegmentation technology, SASE and SSE secure access, endpoint protection against malware, and incident response.

Launch the full PCCP simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Secure Access · 3.3.4 Data loss prevention (DLP)

    A retail company is adopting a SASE architecture to secure its distributed workforce and branch offices. A key business requirement is to prevent the exfiltration of sensitive customer data, such as credit card numbers, from both corporate-managed devices and SaaS applications. Which SASE component is specifically designed to address this requirement?

    Show answer & explanation

    Correct answer: C

    Data Loss Prevention (DLP) is the technology responsible for identifying, monitoring, and protecting sensitive data in use, in motion, and at rest. Within a SASE framework, an integrated DLP solution can enforce policies across the web, cloud applications, and private applications to prevent the unauthorized transmission of confidential information like credit card numbers.

  2. Question 2Intermediate

    Cloud Security · Identify and describe the functions of a Cloud Native Application Protection Platform (CNAPP)

    True or False: The primary function of a Cloud Native Application Protection Platform (CNAPP) is to replace the need for a Security Information and Event Management (SIEM) system.

    Show answer & explanation

    Correct answer: B

    False. A CNAPP integrates various cloud security capabilities (like CSPM and CWPP) to provide unified protection for cloud-native applications throughout their lifecycle. A SIEM aggregates, correlates, and analyzes log data from across the entire enterprise (including on-premises, cloud, endpoints, etc.). While a CNAPP provides critical security data, it complements a SIEM rather than replacing it.

  3. Question 3Beginner

    Security Operations · Explain the functions of security orchestration, automation, and response (SOAR)

    A security operations team is overwhelmed with the volume of alerts from various security tools. They want to implement a solution that can automate the initial triage and response actions for common, low-risk alerts by following predefined workflows. Which technology is best suited for this purpose?

    Show answer & explanation

    Correct answer: B

    SOAR platforms are specifically designed to address alert fatigue by automating and orchestrating incident response workflows. They use 'playbooks' to execute a series of predefined actions, such as enriching alerts with threat intelligence, quarantining an endpoint, or creating a ticket, thereby freeing up analysts to focus on more complex threats.

  4. Question 4Intermediate

    Network Security · Identify and describe cybersecurity concerns unique to Operation Technology (OT) and internet of things (IoT) devices

    During a security audit, an administrator discovers several unauthorized IoT devices (e.g., smart speakers, IP cameras) connected to the corporate wireless network. What is the most significant risk associated with these unmanaged devices?

    Show answer & explanation

    Correct answer: B

    Unmanaged IoT devices often have default credentials, unpatched vulnerabilities, and lack security controls. This makes them easy targets for compromise. Once an attacker gains control of an IoT device, they can use it as a beachhead to launch further attacks, move laterally, and access more sensitive parts of the corporate network.

  5. Question 5AdvancedSelect 2

    Network Security · Identify and describe Palo Alto Networks Cloud-Delivered Security Services (CDSS)

    A financial services company is using Prisma Access to provide secure remote access for its employees. To comply with regulations, the company must prevent employees from uploading sensitive financial documents to personal cloud storage accounts. Which two Palo Alto Networks Cloud-Delivered Security Services (CDSS) should be enabled and configured on the NGFW to enforce this policy? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Advanced URL Filtering is needed to identify and categorize the SaaS applications being accessed (e.g., distinguishing between corporate and personal cloud storage). It allows the administrator to create policies that can block or control access to specific categories of websites, such as personal cloud storage.

    Enterprise DLP is the service that inspects data in motion to identify sensitive information based on predefined patterns (like financial data formats). A DLP policy can be created to specifically block the upload of files containing this sensitive data to the web, enforcing the company's compliance requirements.

  6. Question 6Beginner

    Endpoint Security · 5.6.1 Host-based Firewall and Host-based Intrusion Preventions Systems (HIPS)

    A company has deployed host-based firewalls on all corporate laptops. An employee working from home connects to an unsecured public Wi-Fi network and is targeted by a network scan from another device on the same network. Which endpoint security technology is responsible for blocking this unsolicited inbound traffic?

    Show answer & explanation

    Correct answer: C

    A host-based firewall runs on an individual computer or device and controls network traffic to and from that device. Its primary function is to filter incoming and outgoing traffic based on a set of rules, blocking unauthorized access attempts like network scans from other devices on an untrusted network.

  7. Question 7Beginner

    Secure Access · Define and explain Secure Access Service Edge (SASE) and differentiate from Secure Service Edge (SSE)

    A key difference between Secure Access Service Edge (SASE) and Secure Service Edge (SSE) is that SASE includes ______.

    Show answer & explanation

    Correct answer: C

    SSE (Secure Service Edge) represents the security-focused components of the SASE framework, including SWG, CASB, ZTNA, and FWaaS. SASE is the broader architecture that converges these SSE security services with networking services, most notably SD-WAN, into a single, cloud-delivered model.

  8. Question 8Beginner

    Security Operations · Explain the process and outcomes of incident response

    What is the primary goal of the 'Containment' phase in the incident response lifecycle?

    Show answer & explanation

    Correct answer: D

    The Containment phase focuses on limiting the scope and magnitude of the incident. The primary goal is to stop the bleeding by isolating affected systems, blocking malicious traffic, or taking other actions to prevent the threat from spreading further while a more permanent solution is developed in the Eradication phase.

  9. Question 9Intermediate

    Cybersecurity · Categorize techniques used by malicious actors as defined by the MITRE ATT&CK framework

    A threat actor gains initial access to a network and then uses legitimate administrative tools like PowerShell and WMI to move laterally and escalate privileges. According to the MITRE ATT&CK framework, which tactic does this behavior primarily fall under?

    Show answer & explanation

    Correct answer: C

    The MITRE ATT&CK framework categorizes attacker actions into tactics. The act of moving from one system to another within a compromised network is defined as the 'Lateral Movement' tactic. While PowerShell is used for 'Execution', the objective described in the scenario—moving between systems—is the key indicator of Lateral Movement.

  10. Question 10Intermediate

    Cloud Security · 4.2.1 Application Security

    A DevOps team is building a CI/CD pipeline for a new cloud-native application. They need to integrate security checks throughout the development lifecycle, from code commit to deployment. Which cloud security concept best describes this integrated approach?

    Show answer & explanation

    Correct answer: C

    DevSecOps is a cultural and technical approach that integrates security practices into the DevOps process. It emphasizes automating security checks and balances throughout the entire software development lifecycle (SDLC), from initial design through integration, testing, deployment, and delivery. This 'shift-left' approach ensures security is a shared responsibility and is built into the application from the start.

Ready for the real thing?

The full PCCP simulator has every exam-style question, timed mode, and instant scoring.

Go to the PCCP simulator →