nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #77

During a routine security audit, it's discovered that a critical server was successfully breached weeks ago by an advanced persistent threat (APT) group. The breach involved sophisticated lateral move

The correct answer is C. False Negative; The security controls failed to detect an actual breach. The challenge is. This is a classic False Negative. The security controls (Cortex XDR, WildFire) failed to detect an actual malicious event (the breach). The primary challenge is to enhance the detection capabilities, which often involves integrating more comprehensive threat intelligence, tuning

Security Monitoring and Alert Triage

Question

During a routine security audit, it's discovered that a critical server was successfully breached weeks ago by an advanced persistent threat (APT) group. The breach involved sophisticated lateral movement and data exfiltration, yet no alerts were generated by the existing security infrastructure, which includes a Palo Alto Networks Cortex XDR endpoint protection platform and a WildFire cloud- based threat analysis service. How would you classify this scenario from the perspective of the security controls, and what is the primary challenge it presents for a SOC?

Options

  • ATrue Positive; The controls successfully identified a threat but the SOC failed to respond. The
  • BFalse Positive; The controls over-alerted, desensitizing the SOC to the actual threat. The
  • CFalse Negative; The security controls failed to detect an actual breach. The challenge is
  • DTrue Negative; The controls correctly determined there was no threat. The challenge is validating
  • EThis is an unknown state, requiring further investigation to classify. The challenge is lack of

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    82% (27)
  • D
    9% (3)
  • E
    3% (1)

Explanation

This is a classic False Negative. The security controls (Cortex XDR, WildFire) failed to detect an actual malicious event (the breach). The primary challenge is to enhance the detection capabilities, which often involves integrating more comprehensive threat intelligence, tuning existing detection rules, deploying additional monitoring tools, or improving behavioral analytics to identify sophisticated, stealthy attacks that bypass signature-based or basic anomaly detection.

Topics

#false negative#APT lateral movement#Cortex XDR#WildFire

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice