nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #61

A Security Operations Center (SOC) using Palo Alto Networks XSOAR for incident management receives a high volume of alerts daily. An analyst is tasked with prioritizing incidents related to potential

The correct answer is B. Threat Intelligence Feed Match (e.g., C2 IP from Unit 42) and Affected Asset Criticality (e.g.,. Effective incident prioritization for data exfiltration requires a combination of strong technical indicators and an understanding of the business impact. Matching an IP to a known Command and Control (C2) server from a reputable threat intelligence source like Unit 42 (Palo Alto

Incident Prioritization and Triage

Question

A Security Operations Center (SOC) using Palo Alto Networks XSOAR for incident management receives a high volume of alerts daily. An analyst is tasked with prioritizing incidents related to potential data exfiltration. Which of the following incident categorization criteria, when combined, would MOST effectively facilitate accurate prioritization for data exfiltration incidents, considering both technical indicators and business impact?

Options

  • ASource IP Geolocation and Destination Port. While useful, these alone may not capture the full
  • BThreat Intelligence Feed Match (e.g., C2 IP from Unit 42) and Affected Asset Criticality (e.g.,
  • CTime of Day and User Department. These are primarily contextual and less indicative of
  • DAlert Volume from a specific sensor and Protocol Used. Alert volume can be misleading, and
  • EFile Hash Reputation (WildFire) and Endpoint OS Version. File hash is good for malware, but OS

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    80% (24)
  • C
    3% (1)
  • D
    10% (3)

Explanation

Effective incident prioritization for data exfiltration requires a combination of strong technical indicators and an understanding of the business impact. Matching an IP to a known Command and Control (C2) server from a reputable threat intelligence source like Unit 42 (Palo Alto Networks' threat research team) provides a high-fidelity technical indicator of a potential breach. Coupling this with the criticality of the affected asset (e.g., a server hosting sensitive customer data, classified as a 'Crown Jewel') directly informs the business risk, enabling accurate prioritization. Other options either lack sufficient technical specificity for exfiltration or don't adequately account for business impact.

Topics

#incident categorization#data exfiltration#asset criticality#threat intelligence feed

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice