Palo Alto Networks PCCP cybersecurity practitioner certification banner

Palo Alto Cybersecurity Practitioner Certification: What Replaced PCCET

The Palo Alto Cybersecurity Practitioner exam, listed by Palo Alto Networks under the exam number CyberSec-Practitioner and known to most candidates as PCCP, is the credential that now occupies the entry point of the vendor’s certification programme. It matters because the door it replaced has closed. PCCET, the entry-level technician exam that thousands of people used as their first Palo Alto credential, was retired along with PCNSE and PCNSA when the vendor rebuilt its programme around job roles rather than products. Anyone searching for the old exam today lands on a certification map that looks nothing like the one they remember. This article sets out what the Palo Alto cybersecurity practitioner certification tests, how its six domains are weighted, what it costs, how it differs from the Cybersecurity Apprentice credential that sits alongside it, and which candidates genuinely benefit from holding it.

What Is the Palo Alto Cybersecurity Practitioner Certification?

The Palo Alto cybersecurity practitioner certification validates that a candidate understands core cybersecurity concepts and can apply the Palo Alto Networks product portfolio at a basic level. It carries the exam number CyberSec-Practitioner, runs 75 questions in 90 minutes, costs $150 USD, and is scored on a 300 to 1000 scale with a pass mark of 860.

Palo Alto Networks places the credential at the foundational level of its programme. That word is doing real work. This is not a configuration exam. You are not asked to build a security policy on a live firewall or tune a correlation rule in a SIEM. You are asked whether you can recognise what a technology is for, where it sits in a defence, and which product in the vendor’s catalogue addresses it.

Who the credential is built for

The vendor describes the audience as people moving into a cybersecurity career, and people already inside the Palo Alto ecosystem who want a recognised starting point before specialising. In practice that covers three groups: students and career changers with theory but no production exposure, IT generalists whose employer has just bought Prisma or Cortex, and pre-sales or support staff who need vocabulary rather than console time.

If you already run a next-generation firewall day to day, this exam will feel shallow. That is a design choice, not a flaw. The programme has professional, specialist and architect tiers above it for exactly that reason.

Why Did Palo Alto Retire PCCET and Replace It With PCCP?

Palo Alto Networks retired PCCET, PCNSE and PCNSA in 2025 and rebuilt the programme around job roles instead of products. PCCP is the foundational credential in that new structure. The change was not cosmetic: the old exams were named after platforms, while the new ones are named after the work a person does.

The rebuilt programme runs across four levels and three tracks. Levels move from foundational through professional and specialist to architect. Tracks split into network security, security operations and cloud security. A candidate now picks a direction first and an exam second, which is the reverse of how the old catalogue worked.

What this means if you were studying PCCET

Most of what you learned still counts. The conceptual spine of PCCET, covering attack lifecycles, network fundamentals, cloud models and endpoint protection, survives inside PCCP. What changed is the emphasis. The new blueprint gives a fifth of the paper to cloud security and pulls in current portfolio names such as Prisma Access, Cortex Cloud and Prisma AIRS that simply did not exist in the older syllabus.

Anyone comparing the two should treat old PCCET study material as background reading rather than a preparation plan. The official certification programme page is the reference for which credentials remain live.

What Is on the PCCP Exam?

PCCP presents 75 questions in 90 minutes, which allows roughly 72 seconds per item, and is delivered through Pearson VUE. Scoring runs on a scaled 300 to 1000 range with 860 required to pass. Six domains make up the blueprint, and their weights are far from even: cloud security takes 20% while security operations takes only 13%.

Exam detailValue
Exam namePalo Alto Cybersecurity Practitioner
Exam numberCyberSec-Practitioner
Questions75
Duration90 minutes
Passing score860 on a scale of 300 to 1000
Price$150 USD
RegistrationPearson VUE

The domain split is where preparation planning actually happens. Study time should follow these weights rather than personal comfort, because the three largest domains together account for well over half the paper.

DomainWeightRepresentative content
Cloud Security20%Cloud architectures and topologies, posture and runtime security, CSPM, CWPP, CNAPP, Cortex Cloud
Cybersecurity19%AAA framework, MITRE ATT&CK categorisation, Zero Trust principles, advanced persistent threats, IdP, IAM and MFA
Network Security19%ZTNA, stateless firewalls versus NGFWs, microsegmentation, IPS, URL filtering, DNS Security, SSL and TLS decryption
Endpoint Security15%Indicators of compromise, UEBA, EDR and XDR, behavioural threat prevention, device and application control, Cortex XDR
Secure Access14%SASE versus SSE, secure web gateway, remote browser isolation, DLP, CASB, SD-WAN, Prisma Access
Security Operations13%Threat hunting, incident response, SIEM, SOAR, attack surface management, XSOAR, Xpanse, XSIAM, Unit 42

Registration runs through Pearson VUE for Palo Alto, and candidates who want a sense of the phrasing before booking can work through the PCCP practice exam to calibrate pace against the 72 second budget.

Why Does Cloud Security Outweigh Security Operations?

Cloud security carries 20% of the PCCP blueprint and security operations carries 13%, a seven point gap that surprises most candidates. The reason is positional: this is a foundational exam, and the vendor treats cloud architecture as knowledge everyone entering security now needs, while deep operations work belongs to the security operations track further up the programme.

Read the objectives and the logic holds. The cloud domain asks you to recognise major cloud architectures and topologies, name the categories of cloud risk, and distinguish posture management from workload protection and from a full cloud native application protection platform. None of that requires operating a console. All of it requires vocabulary that a new analyst uses in their first week.

Security operations, by contrast, is compressed into recognition-level content: what threat hunting is, what a SIEM does, what SOAR automates, what attack surface management covers. The portfolio names attached to it, XSOAR, Xpanse and XSIAM, are introduced rather than examined in depth.

How to use the imbalance

  • Give cloud security the largest single block of study time, even if your background is network based.
  • Treat cybersecurity and network security as a combined 38% block, because their objectives overlap heavily around Zero Trust and access control.
  • Do not over invest in security operations tooling detail. Knowing what each product category does is enough at this level.

Which Zero Trust and Network Security Ideas Does PCCP Test?

PCCP tests Zero Trust by name. The syllabus asks candidates to explain the concept and define its key principles, listing continuous monitoring and validation, least privilege access enforcement, and breach assumption. Those three ideas then reappear across the network security and secure access domains, which is why they repay early study.

The definitional anchor most examiners and vendors work from is NIST Special Publication 800-207, the standards text on the subject.

“Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location.”

Scott Rose, Oliver Borchert, Stu Mitchell and Sean Connelly, authors of NIST Special Publication 800-207

That single sentence explains why so much of the network security domain is about verification rather than boundaries. The objectives cover Zero Trust Network Access, the difference between stateless firewalls and next-generation firewalls, and the purpose of microsegmentation, all of which are answers to the same question: how do you enforce policy when location proves nothing?

The technologies named in the blueprint

Beyond Zero Trust, the network security domain names intrusion prevention, URL filtering, DNS Security, VPN, and outbound SSL and TLS decryption, and asks candidates to explain the limits of signature-based protection. It also pulls in operational technology and internet of things concerns, which is unusual for a foundational exam and reflects how often those devices now sit inside enterprise networks.

The cybersecurity domain adds attacker-side knowledge. Candidates categorise techniques using the MITRE ATT&CK framework and describe the characteristics of an advanced persistent threat, which is the closest the exam comes to threat intelligence work.

The secure access domain is smaller at 14% but conceptually dense. It hinges on telling secure access service edge apart from security service edge, then mapping the vendor’s Prisma family onto that distinction.

Apprentice or Practitioner: Which Entry Credential Fits You?

Palo Alto Networks offers two foundational credentials, Cybersecurity Apprentice and Cybersecurity Practitioner, and candidates regularly book the wrong one. The Practitioner exam is the higher of the two and the one employers recognise as a genuine entry-level qualification; the Apprentice credential sits below it as a first step for people with no security background at all.

The decision comes down to honest self-assessment rather than ambition. If you can already explain what a firewall rule does, what a SIEM collects, and why cloud workloads need different controls from servers in a rack, start at Practitioner. If those sentences are unfamiliar, the Apprentice route builds the vocabulary first and costs less time.

Detail on the lower tier is covered in this Cybersecurity Apprentice guide, which is worth reading before you book either exam.

Signals that you are ready for Practitioner

  1. You can name the three Zero Trust principles without looking them up.
  2. You know the difference between EDR and XDR and can say why the second exists.
  3. You can describe at least two cloud deployment models and one cloud-specific risk.
  4. You recognise the Palo Alto product families by function, not just by name.

How Should You Prepare for the Cybersecurity Practitioner Exam?

A realistic PCCP preparation plan runs four to six weeks for a candidate with some IT background, and follows the blueprint weights rather than a textbook order. The sequence below moves from the heaviest domains to the lightest, then closes with timed practice against the 90 minute limit.

Five step PCCP preparation roadmap covering cloud first, zero trust, mapping products, SASE and SSE, and timed practice papers
  1. Start with cloud security, the heaviest domain at 20%, and learn the difference between posture management, workload protection and a cloud native application protection platform before touching any product name.
  2. Move to the cybersecurity and network security domains together, because both are 19% and both are built on the same Zero Trust foundation, so studying them as one block avoids relearning the same principles twice.
  3. Map the Palo Alto portfolio onto what you have learned, matching each product family to the problem it solves rather than memorising a catalogue, since the exam asks about function rather than configuration.
  4. Cover endpoint security and secure access next, giving particular attention to the SASE and SSE distinction, which is the single most commonly confused pair in the whole blueprint.
  5. Finish with security operations at recognition level, then sit full timed practice papers until you consistently finish inside 90 minutes with time left to review flagged questions.

Where candidates lose marks

Two patterns show up repeatedly. The first is treating the exam as a firewall test and neglecting cloud, which costs a fifth of the paper. The second is pace: 72 seconds per question sounds generous until scenario-style wording appears, and candidates who have never taken a timed paper often leave items unanswered.

Which Roles Does This Certification Actually Serve?

PCCP serves roles where security vocabulary matters more than console time. Security operations centre tier one analysts, junior network administrators moving toward security, IT support staff at Palo Alto customers, and pre-sales and technical account roles all draw directly on what the credential proves. It is a starting credential, and it reads that way on a CV.

Four career paths after the Palo Alto cybersecurity practitioner certification: SOC analyst, network admin, IT support and pre sales

The credential is most useful in two situations. The first is a career change, where it gives a hiring manager something concrete to check against a candidate with no security job history. The second is an internal move, where an employer running Prisma or Cortex wants staff who can speak about the platform accurately before they are trusted with it.

What it does not do

It does not substitute for hands-on experience, and it will not carry an application for a senior engineering role on its own. The professional and specialist tiers exist for that, and the article covering practitioner jobs and salary sets out where the credential sits in real hiring terms.

Used correctly, it is a foundation with a clear next step: pick a track, then move to the professional tier inside it.

Frequently Asked Questions

How many questions are on the PCCP exam?

The Palo Alto Cybersecurity Practitioner exam contains 75 questions and allows 90 minutes, which works out to about 72 seconds per item. Budget time for scenario-worded questions, which take longer than straight recall items and cause most of the overruns candidates report.

What score do you need to pass the Cybersecurity Practitioner exam?

The passing score is 860 on a scale that runs from 300 to 1000. Because the scale is not a percentage, you cannot convert it directly into a number of correct answers, so treat every domain as scoreable rather than writing one off.

How much does PCCP cost?

The exam fee is $150 USD, paid at registration through Pearson VUE. Training material and practice papers are priced separately, so budget for those on top if you plan to use a structured course.

Is PCCP the replacement for PCCET?

Yes in practical terms. PCCET was retired in 2025 alongside PCNSE and PCNSA when Palo Alto Networks moved to a role-based programme, and the Cybersecurity Practitioner credential now occupies the entry point that PCCET used to hold.

Are there prerequisites for the Cybersecurity Practitioner exam?

No formal prerequisites are published, so any candidate may register directly. The blueprint does assume working familiarity with networking and security vocabulary, which is a practical constraint even though it is not a booking requirement.

Which PCCP domain carries the most weight?

Cloud security, at 20% of the exam. Cybersecurity and network security follow at 19% each, and security operations is the lightest at 13%, so study time should start with cloud rather than with firewalls.

Should I take Cybersecurity Apprentice before Practitioner?

Only if you are starting from no security background at all. Candidates who can already explain firewall rules, SIEM collection and cloud workload risk should book Practitioner directly, since Apprentice will cover ground they have already crossed.

Does PCCP require hands-on Palo Alto product experience?

No. The exam tests recognition and basic application rather than configuration, so it asks what a product family does rather than how to build a policy in it. Hands-on skill becomes necessary at the professional tier and above.

How long does preparation usually take?

Four to six weeks is realistic for someone with general IT experience, working through the domains in weight order. Candidates with no technical background should expect longer, particularly for the cloud security material.

Where does PCCP lead next?

Into one of the three tracks: network security, security operations or cloud security. The programme runs from foundational through professional and specialist to architect, so the sensible next move is choosing a direction and taking the professional exam within it.

Conclusion

PCCP is not a harder PCCET. It is a differently shaped exam built for a programme that now organises itself around roles, and its blueprint says so plainly: a fifth of the paper is cloud security, and the operations tooling most people associate with Palo Alto is the lightest domain on the sheet.

That makes the preparation decision straightforward. Follow the weights, start with cloud, treat cybersecurity and network security as one Zero Trust block, and keep security operations at recognition level. Confirm you belong at Practitioner rather than Apprentice before booking, then spend the last stretch on timed papers so 72 seconds per question stops being a surprise. From there, choosing a track is the only decision left.

Rating: 5 / 5 (1 votes)