Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

PPAN01 Certified Threat Protection Analyst Exam Questions and Answers

Questions 4

An analyst is reviewing the Threats page in the TAP Dashboard.

PPAN01 Question 4

Which of the top four threats seen in the exhibit should be prioritised for investigation?

Options:

A.

The Malware Delivery threat

B.

The TOAD (Telephone-Oriented Attack Delivery) threat

C.

The Credential Phishing threat

D.

The BEC (Business Email Compromise) threat

Buy Now
Questions 5

The Attack Index is a calculation of the overall threat burden for a particular user. Which listed factor contributes to this calculation?

Options:

A.

VIP status

B.

The number of potential attack pathways

C.

The user’s group membership in Active Directory

D.

The severity and diversity of threats

Buy Now
Questions 6

Exhibit:

PPAN01 Question 6

What can be determined by the threat information shown in the exhibit?

Options:

A.

Five messages containing this threat were pulled from mailboxes after delivery.

B.

The URLs related to the threat were rewritten after the threat was discovered.

C.

More than 150 messages containing this threat were unclicked or were deleted.

D.

The VIP user clicked on the non-rewritten URL in the threat message.

Buy Now
Questions 7

Which of the following is an item that should be included in an incident report as part of the post-incident debrief?

Options:

A.

Network diagrams

B.

Incident response plan

C.

Adversary tactics and techniques

D.

Proofpoint threat landscape reporting

Buy Now
Questions 8

Refer to Exhibit:

X-Proofpoint-Banner-Trigger: inbound

MIM-version: 1.0

Content-Type: multipart/mixed; boundary="boundary-1698346305"

X-CLX-Shades: MLX

X-Proofpoint-Virus-Version: vendor=baseguard

engine=ICAP:2.0.272,Aquarius:18.0.987,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2023-10-26_22,2023-10-26_01,2023-05-22_02

X-Proofpoint-Spam-Details: rule=spam policy=default score=89 bulkscore=0 phishscore=0 mlxlogscore=-91 suspectscore=0 malwarescore=0 adultscore=0 spamscore=89 classifier=spam adjust=0 reason=mlx scancount=l engine=8.12.0-2310240000 definitions=main-2310260209

In the process of reviewing a false positive, you see the following email header. What was the reason the message was quarantined by the Proofpoint Protection Server?

Options:

A.

A custom spam rule caused the message to be quarantined.

B.

An anti-virus rule forced the message to be quarantined.

C.

The recipient's personal block list forced quarantine of the message.

D.

A content policy rule (DLP/compliance) forced quarantine of the message.

Buy Now
Questions 9

Exhibit:

PPAN01 Question 9

What is indicated by the icon shown in the “Highlighted” column?

Options:

A.

The threat has been added to a custom blocklist.

B.

The threat has been reported as a false negative.

C.

The threat has been reported as a false positive.

D.

The threat has been cleared and considered safe.

Buy Now
Questions 10

What does a notification of “Cleared” mean when shown in the header of an individual threat tab?

Options:

A.

The threat has been detected but hasn’t been resolved yet.

B.

The threat has been successfully neutralized and no longer poses a risk.

C.

The threat has been identified but is not considered a priority for investigation.

D.

The threat has been temporarily contained but may still pose a risk.

Buy Now
Questions 11

What type of threat does the Cloud Security Report help identify in connected environments?

Options:

A.

Ransomware

B.

Account Takeover

C.

Malicious Insider

D.

Business Email Compromise

Buy Now
Questions 12

An analyst has been tasked with providing a report that can be used to prioritise investigations based on a user's Attack Index score. Which report would be most suitable for this purpose?

Options:

A.

VIP Activity

B.

Top 10 Recipients

C.

Very Attacked People

D.

Top 10 Clickers

Buy Now
Questions 13

An analyst is reviewing the Threat Response Quarantines card for a message in TAP Dashboard, as shown in the exhibit.

PPAN01 Question 13

Why might a message be flagged with status “unavailable”?

Options:

A.

The message was deleted from the mailbox before it could be quarantined.

B.

The message was automatically moved into a user-created folder for archiving.

C.

The message was delayed in delivery because of large attachment size.

D.

The message was marked as read by the user before it could be quarantined.

Buy Now
Questions 14

Which activity is part of the Preparation phase in the NIST lifecycle?

Options:

A.

Restoring systems from backups.

B.

Documenting postmortem reports.

C.

Identifying compromised accounts.

D.

Conducting response drill scenarios.

Buy Now
Questions 15

An attacker registers a domain like “great-company.com” to impersonate “greatcompany.com.” What tactic is being used?

Options:

A.

Domain Hijacking

B.

Display Name Spoofing

C.

Lookalike Domain

D.

Subdomain Takeover

Buy Now
Exam Code: PPAN01
Exam Name: Certified Threat Protection Analyst Exam
Last Update: May 22, 2026
Questions: 52

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11