SECOPS-PRO Exam Questions
80 real SECOPS-PRO exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Logging and Monitoring
Which component of Cortex XDR is designed to detect insider threats?
Cortex XDRIdentity Analyticsinsider threatthreat detection - Question #2Incident Response
A new incident in Cortex XSIAM contains WildFire malware and Behavioral Threat Protection (BTP) alertsout an unsigned process attempting to dump the memory of Isass.exe. Which init...
Cortex XSIAMWildFireBTPincident triage - Question #3Incident Response
A file hash is evaluated a Cortex XSOAR by using two unique threat feeds: - VirusTotal feed (rating of B- usually reliable) and the file verdict is malicious - AlienVault feed (rat...
Cortex XSOARthreat intelligence feedsfile verdictindicator scoring - Question #4Logging and Monitoring
A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assis...
Cortex XDRlog stitchingfirewall logsendpoint correlation - Question #5Identity and Access Management (IAM)
Where can an administrator begin to grant a new non-SSO user access to a Cortex XDR tenant?
Cortex XDRuser managementaccess controltenant administration - Question #6Incident Response
Where can the actions taken to stitch alerts together in Cortex XSIAM be viewed?
Cortex XSIAMalert stitchingcausality chainincident investigation - Question #7Incident Response
What determines the indicator layout displayed and the scripts that will run on an indicator of compromise (IOC) in Cortex XSIAM?
Cortex XSIAMIOC typeindicator layoutplaybook automation - Question #8Incident Response
Which action is performed as the final step of the NIST incident response plan?
NISTincident response lifecyclepost-incident activitylessons learned - Question #9Incident Response
What is the purpose of incident types in Cortex XSOAR?
Cortex XSOARincident typesplaybook automationalert classification - Question #10Incident Response
Which activities are facilitated through the War Room in Cortex XSOAR?
Cortex XSOARWar Roomplaybook executionincident collaboration - Question #11Cortex XDR Detection and Response
What are the primary functions of the Causality Analysis Engine in Cortex XDR?
Causality Analysis EngineCortex XDRforensic timelinealert investigation - Question #12Threat Intelligence and Indicator Management
How do indicator verdicts in Cortex XSOAR assist analysts in threat detection and response efforts?
indicator verdictsCortex XSOARthreat classificationmalicious indicators - Question #13Cortex XDR Detection and Response
What is the function of a Causality View?
Causality ViewCortex XDRprocess execution chainalert correlation - Question #14SOC Operations and Roles
What is a primary responsibility of an incident responder in a SOC?
SOC rolesincident responderescalation handlingincident response - Question #15Cortex XSIAM Architecture and Data Collection
How do sensors function in Cortex XSIAM?
Cortex XSIAMsensorslog collectiontelemetry data - Question #16Security Operations Platform Selection
In which scenario would an organization benefit from Cortex XDR compared to an EDR solution?
Cortex XDREDR comparisonmulti-source integrationextended detection - Question #17Cortex XDR and XSIAM Analytics
What does the analytics engine use to compare an entity to itself across different time periods using statistical methods?
analytics enginetemporal profilebehavioral analysisstatistical methods - Question #18SOC Operations and Roles
Which action is the responsibility of the SOC manager?
SOC managercrisis communicationSOC rolesincident management - Question #19Incident Response Fundamentals
What role does incident response play in handling cybersecurity incidents?
incident responsecontainmenteradicationcyber threat handling - Question #20Endpoint Security and Response
What is the expected behavior when an endpoint is isolated in Cortex XSIAM?
endpoint isolationCortex XSIAMnetwork access controlcontainment - Question #21Cortex XSOAR Automation and Scripting
Which two statements apply to creating scripts in Cortex XSOAR? (Choose two.)
Cortex XSOARscriptsautomationelevated permissions - Question #22Cortex XSIAM Administration and Configuration
Which two roles can access data model rules in Cortex XSIAM? (Choose two.)
Cortex XSIAMdata model rulesRBACaccess control - Question #23SOAR Automation and Playbooks
Which two types of tasks are supported in Cortex XSIAM playbooks? (Choose two.)
Cortex XSIAMplaybookssub-playbookconditional tasks - Question #24Cortex XDR Customization and Reporting
Which scripting language would create a custom widget in Cortex XDR that shows the top five accounts with failed Windows logons in the past 24 hours?
Cortex XDRcustom widgetsJavaScriptXQL - Question #25Incident Response and Remediation
Which solution will minimize mean time to resolution (MTTR) when, as a result of previous malware infection, a company's Windows endpoint is suffering a small amount of file corrup...
MTTRremediation suggestionsfile restorationregistry repair - Question #26Cortex XDR Administration and Configuration
With a Windows endpoint, what is required to remove the Cortex XDR agent when the endpoint is no longer online and cannot be managed directly from the management console?
Cortex XDR agentoffline removalCytoolendpoint management - Question #27Cortex XSIAM Architecture and Data Collection
Which sensor is used by Cortex XSIAM to identify and collect DNS queries, HTTP header, and DHCP information?
Cortex XSIAMPathfinderDNS queriesnetwork telemetry - Question #28Threat Intelligence and SOC Operations
What are two outcomes of threat intelligence in a SOC? (Choose two.)
threat intelligenceSOCrisk mitigationthreat verdict detection - Question #29Threat Analysis and MITRE ATT&CK Framework
Which MITRE enterprise tactic will provide more information on the technique used by a threat actor who has successfully used PsExec to upload files to an internal server from a co...
MITRE ATT&CKlateral movementPsExecthreat actor tactics - Question #30Security Technologies and Concepts
What is the main difference between artificial intelligence (AI) and machine learning (ML) in cybersecurity?
artificial intelligencemachine learningcybersecurity technologiescognitive functions - Question #31Threat Analysis and WildFire
What is the WildFire verdict on a sample that does not pose a direct security threat, but is shown to display obtrusive behavior?
WildFire verdictsgraywaremalware classificationthreat analysis - Question #32Security Orchestration Automation and Response (SOAR)
What is the Cortex XSOAR Marketplace?
Cortex XSOARMarketplacecontent repositoryintegrations - Question #33Cortex XDR Investigation and Response
Which two functions are allowed when stitching logs in Cortex XDR? (Choose two.)
Cortex XDRlog stitchingBIOC rulesinvestigation queries - Question #34Cortex XDR Reporting and Dashboards
Which two statements are relevant to reports in Cortex XDR? (Choose two.)
Cortex XDRreportsXQL widgetsPDF export - Question #35Identity and Access Management
What is enabled by Role Based Access Control (RBAC) in Cortex XDR?
RBACaccess controlpermissions managementCortex XDR - Question #36Incident Management
What are two ways a security team assigns priority to security incidents in Cortex XDR? (Choose two.)
incident prioritizationSmartScoreincident severityCortex XDR - Question #37Cortex XDR Incident Response
A custom PowerShell command is detected by Cortex XDR as a behavioral threat, and the administrator has confirmed it as a false positive. What is the most operationally efficient w...
alert exceptionsfalse positivesbehavioral threatsPowerShell - Question #38Incident Triage and Investigation
An analyst investigating an incident using Cortex XSIAM confirms that the files involved are not malware, but wants to determine if the incident is a genuine threat or a false posi...
Cortex XSIAMincident investigationfalse positive analysisinformation alerts - Question #39Security Operations Center (SOC) Roles and Responsibilities
What is involved in the day-to-day role of a triage specialist?
SOC rolestriage specialistsecurity operationsmonitoring tools - Question #40Security Orchestration Automation and Response (SOAR)
Which two steps belong in the Cortex XSOAR incident lifecycle? (Choose two.)
Cortex XSOARincident lifecycleincident creationincident notification - Question #41Threat Analysis and Triage
What can be used to triage and determine if an artifact in Cortex XDR is malicious?
WildFire reportartifact triagemalicious indicatorsCortex XDR - Question #42Threat Intelligence
What is a benefit of using Unit 42 threat intelligence during a ransomware attack?
Unit 42threat intelligenceransomwareincident response - Question #43Security Monitoring and Analysis
Which function eliminates the need for manual analysis in an organization with multiple data sensors?
log correlationautomated analysisdata sensorsSIEM - Question #44Security Orchestration Automation and Response (SOAR)
How can an administrator run a Cortex XSOAR playbook regularly at a specific time and day of the week?
Cortex XSOARplaybook schedulingjobsautomation - Question #45Identity and Access Management
Which predefined role in the Cortex XDR tenant can view and triage incidents?
Cortex XDRpredefined rolesRBACincident triage - Question #46Compliance and Regulatory Frameworks
A security auditor must ensure adherence to which two regulatory compliance frameworks when reviewing a financial institution's data protection policies? (Choose two.)
GDPRPCI DSScompliance frameworksfinancial data protection - Question #47Threat Analysis and WildFire
How is WildFire typically used by Cortex XDR?
WildFirecloud sandboxingmalware analysisCortex XDR - Question #48Security Operations Tools and Technologies
Which attribute is an advantage of SOAR over SIEM?
SOARSIEMautomationalert response - Question #49Security Operations Tools and Technologies
Which SOC tool allows an organization to aggregate logs from various sources for compliance, reporting, dashboarding, and threat hunting?
SIEMlog aggregationthreat huntingcompliance reporting - Question #50Threat Hunting and Incident Response
Which task should a threat hunter include in the investigation when a Cortex XDR incident contains alertsout a malicious process?
threat huntingSHA256 hashendpoint investigationmalicious process