Palo Alto Networks built this certification for people who are not security professionals yet. Students, career changers and people arriving from non-technical roles are the intended audience. That shapes the exam more than the domain list suggests, because it asks you to recognise and place ideas rather than to configure anything. The Palo Alto Networks Cybersecurity Apprentice exam questions below come from the practice bank our candidates use before test day, written against the May 2026 datasheet. If your exam is booked, work a set now and check yourself against the seven domain weightings further down. If you are still deciding, the domain map shows what an entry-level security exam actually asks of you.
| Exam name | Palo Alto Networks Certified Cybersecurity Apprentice |
| Exam code | CYBERSECURITY-APPRENTICE |
| Certification | Palo Alto Networks Cybersecurity Apprentice |
| Certification level | Foundational |
| Time allowed | 90 minutes total seat time |
| Passing score | Palo Alto Networks does not publicly disclose an exact passing score. |
| Exam cost | USD 150 (Foundational tier; taxes and fees vary by country) |
| Retake policy | 15 days after a first fail, 30 days after a second, 90 days after a third |
| Certification validity | 2 years; the exam is retaken to renew |
| Delivery | In person at Pearson VUE test centres. There is no remote option. |
| Practice questions in our bank | 115 |
| Questions on the real exam | 0 |
Free to answer here, drawn from the same bank our candidates work through before test day.
Which component is secured by the cloud provider in a shared responsibility model?
Correct Answer: D
In the cloud shared responsibility model, the provider is responsible for securing the underlying infrastructure that delivers the cloud service. This includes physical data centers, facilities, power, cooling, physical networking, storage hardware, and host servers that support customer workloads. Therefore, the host server is the correct answer. A customer is generally responsible for securing what they configure or deploy in the cloud, such as virtual machines, operating systems, applications, identities, and data, depending on the service model. Website authentication is an application or identity-layer responsibility and usually belongs to the customer or application owner. On-premises connectivity to hosts is also customer-controlled because it involves the organization's network design, VPN, routing, and access policies. The exact boundary shifts across SaaS, PaaS, and IaaS, but the provider consistently secures the cloud infrastructure itself. Palo Alto Networks explicitly includes the cloud shared responsibility model as a Cloud Security objective for Apprentice candidates. Reference: Cybersecurity Apprentice Datasheet, Cloud Security 5.3.
Why would an organization implement a demilitarized zone (DMZ)?
Correct Answer: D
A DMZ is implemented to host public-facing services while reducing direct exposure to the internal trusted network. Web servers, mail gateways, VPN portals, or other externally accessible systems may be placed in a DMZ so internet users can reach required services without being allowed directly into internal resources. The DMZ acts as a controlled buffer zone between untrusted external networks and trusted internal networks. Destination NAT may be used with DMZ services, but provisioning external zones for NAT is not the core reason. SD-WAN departments is not a valid DMZ purpose. Communication with other organizations may occur through public services, but the security purpose is controlled exposure and internal protection. DMZ design supports segmentation, firewall policy, logging, and containment. If a public-facing server is compromised, proper DMZ controls reduce the attacker's ability to pivot into sensitive internal systems. Reference/topics: Network Security 3.1, zone segmentation; Network Security 3.2, firewall policy enforcement.
Which two technologies will secure a data center's infrastructure from network-based threats? (Choose two.)
Correct Answer: A, C
A next-generation firewall and an intrusion prevention system are the strongest choices for securing a data center against network-based threats. An NGFW provides application-aware policy enforcement, traffic inspection, segmentation support, and threat prevention capabilities at network control points. An IPS is designed to inspect traffic inline and block malicious packets before they reach protected systems. IDS technology is useful for monitoring and alerting, but a traditional IDS is normally passive and does not directly prevent traffic from reaching a target. A proxy can mediate certain types of traffic, especially web traffic, but it is not the broadest or most direct answer for data center infrastructure protection against network-based threats. Data centers require controls that can inspect both north-south and east-west traffic, enforce policy, and stop exploit attempts or known malicious patterns. NGFW and IPS capabilities are therefore aligned with preventive infrastructure security. Reference/topics: Network Security 3.2, NGFWs; Cybersecurity 1.5, intrusion prevention systems and firewalls.
Batch 3 --- Questions 26--40
Which function is a component of a data loss prevention (DLP) solution?
Correct Answer: C
A core function of DLP is protecting against sensitive information exposure. DLP solutions identify, monitor, and control sensitive data such as personal information, payment card data, intellectual property, credentials, source code, or regulated records. DLP may inspect content, file types, labels, patterns, user context, and destination risk to determine whether data should be allowed, blocked, encrypted, quarantined, or logged. Encrypting all transmissions is not the general definition of DLP; encryption may be one enforcement action, but DLP decisions are content-aware and policy-based. System backups support recovery and resilience, not data loss prevention. Enhancing network speed is a performance function. DLP is important because data can leave through email, web uploads, cloud storage, removable media, or compromised accounts. Effective DLP helps reduce both accidental leakage and intentional exfiltration. Reference/topics: Network Security 3.5, DLP; Identity Security 7.2.3, least privilege.
Which stage of the cyber attack lifecycle is characterized by attackers passing instructions back and forth between infected devices and their own infrastructure?
Correct Answer: A
Command and Control, or C2, is the phase in which compromised systems communicate with attacker-controlled infrastructure to receive instructions, send status updates, download additional payloads, or coordinate malicious activity. This back-and-forth communication allows attackers to operate the compromised device remotely and adapt their actions after initial compromise. Weaponization and Delivery involve preparing and transmitting the malicious payload, not managing an already infected host. Exploitation is the act of using a vulnerability or weakness to gain unauthorized access. Reconnaissance is information gathering before compromise. C2 is especially important in detection engineering because outbound traffic patterns, unusual domains, beaconing intervals, and connections to suspicious infrastructure can reveal that an endpoint is under external control. Blocking C2 can disrupt an attacker's ability to move laterally, exfiltrate data, or complete actions on objectives. Reference/topics: Cybersecurity 1.2, cyber attack lifecycle; Cybersecurity 1.3, command and control as a common attack type.
Each domain below shows how much of the exam it accounts for, what it expects you to understand, and the way its questions tend to be put. The weightings come from Palo Alto Networks' official certification datasheet.
Identity Security
18%The heaviest domain on the exam, which catches out anyone expecting it to be mostly firewalls. Identity is about proving someone is who they claim to be, and then limiting what they can reach once you believe them. Questions describe an organisation whose access has quietly grown too loose, and ask what would tighten it.
Cybersecurity
16%This is the domain that gives you the language for all the others. It covers how an attack unfolds, what the common types look like, and the systems built to spot or stop them. Questions describe something happening and ask you to name it, so the difficulty lies in telling neighbouring terms apart rather than in meeting them for the first time.
Network Fundamentals
16%None of this is security yet, and every domain after it assumes you already have it. How machines find each other, how traffic travels between them, and what the pieces along the route are called. Career changers underestimate this one most often, usually because it feels like something they ought to know already.
Network Security
14%Here the fundamentals turn into defences. The recurring question is where a control sits and what it can actually see, which is what separates a right answer from a merely plausible one. Expect scenarios where traffic reached somewhere it should not have, and you decide what would have stopped it.
Cloud Security
13%Almost everything here leads back to one idea. When you run something in the cloud, part of the security is yours and part belongs to the provider. Questions place a failure somewhere in that arrangement and ask which side of the line it fell on. Getting the line right earns more than knowing product names.
Security Operations
13%This is the working day of a security team rather than a body of theory. It covers watching for trouble, noticing it, and deciding what to do about it. Questions tend to drop you into the middle of an incident and ask what happens next, so the order of things is more useful to carry into the exam than any single definition.
Endpoint Security
10%The smallest domain and the easiest to picture, because it is about the laptops and servers people actually use. It covers how they get compromised, and what would have stopped it. Questions usually describe a machine that is already infected and ask what should have been in place beforehand, rather than what to do now.
May 2026 — : Current version of the certification datasheet, carrying the seven domains and the weightings shown here. Prerequisites confirmed as none, with the certification positioned at the Foundational level.
August 2024 — :Cybersecurity Apprentice certification launched in August 2024,This exam are tailored for anyone looking to enter the cybersecurity field.
Source: Palo Alto Networks' official Cybersecurity Apprentice certification page and datasheet. Our question bank is updated to match each revision.
Beneath the seven domains sit a handful of things that decide answers. Among them are privileged access and the identity lifecycle in the heaviest domain, the cyber attack lifecycle, the OSI layers, and the line between what a cloud provider secures and what you do. None asks you to configure anything. Each asks that you recognise it on sight, which is narrower than it sounds and where the questions keep returning.
Attack anatomy and the defences aimed at it
Tested via: expected to be short multiple-choice questions naming what is describedCybersecurity and Endpoint Security carry this between them, about a quarter of the exam, with the prevention side reaching into Network Security. The lifecycle comes first, because most attack questions place you somewhere along it and ask what stage you are seeing. Beneath it sit the types, where malware, insider threat, command and control and social engineering have to be separable from a short description. The defences pair off against them, and an intrusion detection system reports where an intrusion prevention system intervenes.
How traffic finds its way, and where it can be intercepted
Tested via: expected to be scenario-based multiple-choice questionsAddressing and defence are one body of knowledge here, and Network Fundamentals plus Network Security are 30% of the paper between them. NAT, DNS and DHCP each do one job, so questions turn on which has failed when something cannot be reached. Routed protocols carry traffic while routing protocols choose its path, a single word apart. Once the route is clear, segmentation by subnet, VLAN or zone decides how far anything travels, and proxies, VPNs and tunnelling intercept at different points.
Who someone is, and what they may reach
Tested via: expected to be scenario-based multiple-choice questionsIdentity Security is the single heaviest domain at 18%, and it holds four families that questions rarely confuse by accident. Identity and access management is the everyday layer, covering the lifecycle, multi-factor authentication, single sign-on, directory services and role-based access control. Privileged access management sits above it for accounts that can do real damage, adding credential vaulting, session monitoring and just-in-time access. Public key infrastructure handles trust between machines, and secrets management covers the keys and tokens applications use.
Where your responsibility ends
Tested via: expected to be scenario-based multiple-choice questionsAlmost everything in Cloud Security's 13% turns on shared responsibility. The service model sets where the line falls, so software as a service leaves you far less to secure than infrastructure as a service does, and the four deployment models move it again. The vocabulary carries weight too, because virtualisation, containers, microservices and APIs each mean something exact and a question will assume the exact one. Recognising which side of the line a task falls on earns more than any product name.
Noticing and responding
Tested via: expected to be multiple-choice questions on order and next stepWhat happens after something is spotted is Security Operations, another 13%. Its functions run in order, from identify and detect through investigate, mitigate and improve, and questions drop you partway along. Underneath them syslog carries the raw record, SIEM collects and correlates it, and SOAR acts on what it finds. A false positive and a false negative are opposite failures of the same system, and saying which you are looking at is a recurring ask.
A first failure costs 15 days before you can sit again, which for most people is the real price rather than the USD 150. Four steps, in this order.
and Why Prefer Pass4Success Practice Material
This certification is new, which means most of the material circulating for it was written quickly and against nothing in particular. For a foundational exam that matters more than usual, because a beginner has no way to tell a wrong answer from a right one. Here is what separates material worth your time.
Written against the current datasheet
Palo Alto Networks published the current Cybersecurity Apprentice datasheet in May 2026. Material assembled before a certification's own documentation settles tends to guess at the weightings, and a guess that puts Endpoint Security level with Identity Security sends you to study the wrong half.
✓ Ours: the bank is updated on a regular cycle to reflect how Palo Alto Networks actually tests, not only when the datasheet changes. When it does change, the affected questions are re-checked as well. The last update date is shown at the top of this page.
Something you can read before paying
Question quality is invisible from a product description, and a candidate new to security is the least equipped person to judge it after the fact. Any provider confident in its material can show you some of it first.
✓ Ours: free demo of both formats before any purchase, the PDF and the practice test, which runs browser-based or as a Windows desktop version. The free questions on this page are from the same bank.
Distractors that behave like the real ones
This exam leans on pairs that sound alike, such as authentication against authorisation, prevention against detection, or the customer's responsibility against the provider's. Practice questions with obviously wrong options train you to eliminate, which is not the skill being tested.
✓ Ours: Questions are written so the wrong options are plausible at this level, distractors are built from real, related concepts, never random or obviously wrong.
Enough spread across all seven domains
A twenty-question sample cannot tell you whether your weak area is cloud responsibility or incident sequence. You need enough items per domain for a pattern in your misses to become visible.
✓ Ours: 115 Cybersecurity Apprentice questions bank covers all seven domains.
Timed practice rather than a question list
Reading questions and answering them against a clock are different skills, and 90 minutes of seat time leaves less room than it sounds like for a first-time test taker.
✓ Ours: the practice test runs timed sessions; the PDF covers offline review. Both arrive in one purchase rather than as separate products.
A price that reads sensibly beside the exam fee
Set the cost of preparing properly against USD 150 plus a fifteen-day wait, and the comparison between one provider and another stops being the interesting question.
✓ Ours: the full question bank is $69 less than half of the $150 exam fee. A retake means paying that $150 again, on top of the time already spent preparing. Getting it right the first time costs a fraction of what a second attempt does.
Candidates below discuss which domains carried the most weight on the day, how the wording compared to the learning path, and what they would study differently. Add your own after you sit.
Seven domains, weighted as Identity Security 18%, Cybersecurity 16%, Network Fundamentals 16%, Network Security 14%, Cloud Security 13%, Security Operations 13%, and Endpoint Security 10%. The weightings come from Palo Alto Networks' May 2026 certification datasheet. Identity Security carrying the most weight surprises candidates who expect a network-heavy exam, and the domain map above sets out what each one asks of you.
No, Palo Alto Networks lists no prerequisites and describes the certification as entry-level, aimed at students, career changers and professionals arriving from non-technical roles. What it does assume is basic familiarity with networking, endpoint security, cloud, security operations and identity concepts, which the vendor's digital learning path is built to supply.
Hard in a specific way rather than a general one. The material is foundational, so nothing on it is deep. What makes it awkward is that the questions turn on distinctions which are easy to read past, such as authentication against authorisation, prevention against detection, or which side of shared responsibility a task falls on. Candidates who study definitions in isolation tend to find the scenario wording harder than expected.
USD 150, which is the Foundational tier price in Palo Alto Networks' certification programme. Taxes and additional fees vary by country. A failed attempt means paying again and waiting 15 days before the second sitting, so the effective cost of an unprepared attempt is higher than the headline figure.
No, Palo Alto Networks delivers its certification exams in person at Pearson VUE test centres and has withdrawn the remote testing option. Total seat time is 90 minutes. Candidates in non-English-speaking countries can request a 30-minute extension, as all exams are delivered in English.
Two years from the date you pass. Palo Alto Networks does not offer a continuing-education route for this credential, so renewal means sitting the exam again. Worth planning around if you intend to move up to the Cybersecurity Practitioner certification, since the timing of that decision affects whether renewal is worth doing at all.
You wait 15 days before a second attempt, 30 days before a third, and 90 days after a third failure. There is no limit on total attempts beyond those waiting periods. If you pass, you cannot retake the same exam for 18 months, which matters only if you were hoping to improve a score.
The recurring ones are pair confusions rather than knowledge gaps. Candidates treat authentication and authorisation as the same thing, choose a detection control where the scenario asked what would have prevented the incident, or hand the provider a cloud responsibility the customer still owns. Misreading the scenario costs more marks here than not knowing the term.
It is the Foundational entry point, below the Professional, Specialist and Architect tiers. The usual next step is the Cybersecurity Practitioner certification, which moves from recognising concepts to operating with them. Nothing is required before Apprentice, so it is a legitimate first certification for someone with no security background at all.
Full access to all 115 Cybersecurity Apprentice questions, in both the PDF and the practice test.
Get Premium AccessThe Cybersecurity Apprentice question bank is updated on a regular cycle to reflect how Palo Alto Networks actually tests, not only when the official datasheet changes. When Palo Alto Networks does revise the certification datasheet (most recently in May 2026), we additionally re-check the affected questions and answers against current Palo Alto Networks documentation. The current bank date is shown in the exam details at the top of this page.