nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #80

A large enterprise utilizes Palo Alto Networks security infrastructure, including NGFWs, Cortex XSOAR for security orchestration, automation, and response, and a centralized SIEM. An analyst discovers

The correct answer is C. The primary risk is a False Negative. XSOAR should be leveraged to ingest the new threat. The most significant risk here is a False Negative. If the vulnerability is being actively exploited and the current security controls (detection rules) don't cover it, any successful exploit will go undetected. Cortex XSOAR is crucial for proactive mitigation in this scenario (O

Security Orchestration Automation and Response

Question

A large enterprise utilizes Palo Alto Networks security infrastructure, including NGFWs, Cortex XSOAR for security orchestration, automation, and response, and a centralized SIEM. An analyst discovers a critical vulnerability (CVE-2023-XXXX) affecting a widely used internal application. Threat intelligence indicates this vulnerability is being actively exploited by a known APT group. The SOC'S current detection rules and playbooks within XSOAR do not explicitly cover this specific CVE. What is the most significant risk associated with this gap from a detection classification standpoint, and how should Cortex XSOAR be leveraged to mitigate it proactively?

Options

  • AThe risk is a True Positive overload, as all scans for the vulnerability will generate alerts. XSOAR
  • BThe risk is primarily a False Positive from misconfigured rules. XSOAR should be used to create
  • CThe primary risk is a False Negative. XSOAR should be leveraged to ingest the new threat
  • DThe risk is a True Negative. XSOAR should be used to ensure the vulnerability is not present on
  • EThe risk is an 'unknown' state. XSOAR can only be used reactively after an incident has occurred.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    82% (32)
  • E
    10% (4)

Explanation

The most significant risk here is a False Negative. If the vulnerability is being actively exploited and the current security controls (detection rules) don't cover it, any successful exploit will go undetected. Cortex XSOAR is crucial for proactive mitigation in this scenario (Option C). It can ingest the new threat intelligence (e.g., IOCs, TTPs related to CVE-2023-XXXX), automatically push these as new detection rules to the SIEM and NGFWs, and update incident response playbooks to include specific steps for this vulnerability (e.g., host isolation, patch management, forensic collection, communication protocols) upon detection. This proactive approach aims to turn potential False Negatives into True Positives when an actual attack occurs. Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.

Topics

#false negative#XSOAR playbooks#CVE coverage gap#threat intelligence ingestion

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice