Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks SecOps-Pro Palo Alto Networks Security Operations Professional Exam Practice Test

Demo: 17 questions
Total 60 questions

Palo Alto Networks Security Operations Professional Questions and Answers

Question 1

What is required to enable ingestion of on-premises firewall logs into Cortex XDR?

Options:

A.

Broker VM

B.

API

C.

PAN-OS content pack

D.

Cloud Identity Engine

Question 2

An administrator needs to prevent users from connecting unauthorized USB flash drives to their corporate workstations to reduce the risk of data exfiltration. Which Cortex XDR feature should be configured?

Options:

A.

Device Control

B.

Host Insights

C.

Behavioral Threat Protection

D.

Malware Profile

Question 3

Which action should an administrator take to create automated response actions when a user account is compromised? (Choose one answer)

Options:

A.

Map the events as a type of Cortex XSOAR incident, then run a playbook.

B.

Run a custom script from the Cortex XDR script library.

C.

Create a script in Cortex XSOAR that will run a playbook based on the scenario.

D.

Create playbook triggers in Cortex XSIAM and run playbooks for each alert.

Question 4

In the MITRE ATT & CK framework, which term describes the specific high-level "Why" or goal of an attacker, such as "Initial Access" or "Exfiltration"?

Options:

A.

Technique

B.

Tactic

C.

Procedure

D.

Mitigation

Question 5

Which two types of tasks are supported in Cortex XSIAM playbooks? (Choose two.)

Options:

A.

Sub-playbook

B.

Script creation

C.

Conditional

D.

Data collection

Question 6

Which process in Cortex XSIAM ensures that raw logs from different vendors (e.g., Check Point, Cisco, and Microsoft) are converted into a standardized format for unified analysis?

Options:

A.

Data Stitching

B.

XDM Mapping

C.

Entity Profiling

D.

Log Ingestion

Question 7

How does the "Unit 42 Intel" integration directly assist a SOC analyst within the Cortex XDR or XSIAM Incident view?

Options:

A.

It automatically resets the user's password in Active Directory.

B.

It provides a "threat card" with actor profiles, known aliases, and related MITRE ATT & CK techniques.

C.

It opens a 24/7 chat window with a dedicated Unit 42 forensic investigator.

D.

It provides the source code of the malware identified in the incident.

Question 8

What is the Cortex XSOAR Marketplace?

Options:

A.

Searchable collection of third-party playbooks and data models

B.

Development environment for creating and sharing third-party integrations

C.

Digital storefront where Cortex XSOAR training credits can be purchased and used

D.

Built-in repository of installable content, including integrations and automations

Question 9

Which two types of content can be installed or upgraded through a Cortex XSIAM content pack? (Choose two.)

Options:

A.

Analytics alerts

B.

Playbook triggers

C.

Data Model rules

D.

Behavioral Threat Protection (BTP)

Question 10

What can be used to triage and determine if an artifact in Cortex XDR is malicious? (Choose one answer)

Options:

A.

Alert severity

B.

MITRE tactic

C.

SmartScore

D.

WildFire report

Question 11

Which Cortex XSIAM component uses machine learning to automatically build a baseline of "normal" behavior for every user and host in the network, and then provides a searchable profile of their historical activity and risk level?

Options:

A.

XQL Engine

B.

Entity Profiling

C.

Broker VM

D.

Data Ingestion Service

Question 12

Which dashboard or module in Cortex XSIAM provides visibility into unmanaged devices, unauthorized shadow IT, and cloud assets that do not currently have a Cortex agent installed?

Options:

A.

Host Insights

B.

Asset Inventory

C.

Cloud Discovery & Exposure

D.

Identity Analytics

Question 13

Where in Cortex XSOAR are analysts able to collaborate and converse with others for joint real-time investigations?

Options:

A.

Investigations tab

B.

War Room

C.

Evidence Board

D.

Work plan

Question 14

What is the primary objective of a "Tier 1" analyst during the triage process?

Options:

A.

Performing deep-dive memory forensics on a compromised server.

B.

Negotiating with ransomware actors to recover encrypted data.

C.

Determining the validity of an alert and its urgency for escalation.

D.

Rewriting the company's information security policy.

Question 15

A company has a highly segmented network where the Cortex XSOAR server cannot directly communicate with an on-premises mail server. Which component should be deployed in the mail server's segment to facilitate integration?

Options:

A.

Broker VM

B.

XSOAR Engine

C.

Cortex Gateway

D.

XSOAR Proxy

Question 16

Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?

Options:

A.

File search and destroy

B.

Live Terminal session initiation

C.

Running a script

D.

Halting network access

Question 17

Which two statements are relevant to reports in Cortex XDR? (Choose two.)

Options:

A.

They can be sent in a password protected PDF version.

B.

They can be automatically pushed to the corporate intranet.

C.

They can use mock data for visualization.

D.

They can have an attached screenshot of an XQL query widget.

Demo: 17 questions
Total 60 questions