SECOPS-PRO Exam Questions
80 real SECOPS-PRO exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Incident Response and Triage
Which incident should a responder prioritize based on overall functional and informational impact to the company?
incident prioritizationdata exfiltrationfunctional impactinformational impact - Question #52Security Operations Platform Management
Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
Cortex XSIAMLinux endpointresponse actionsfile remediation - Question #53Security Orchestration Automation and Response
What is the role of content packs in Cortex XSOAR?
Cortex XSOARcontent packsSOAR platformsecurity orchestration - Question #54Security Operations Automation
Which action should an administrator take to create automated response actions when a user account is compromised, allowing attacker to upload data to an external IP address and in...
Cortex XSIAMplaybook automationautomated responseincident orchestration - Question #55Security Operations Platform Selection
During a sophisticated cyber attack, a company experiences a stealthy, multivector intrusion that evades detection by traditional security tools. The company requires a solution th...
XDRmulti-vector detectionthreat correlationautomated response - Question #56Data Management and Log Analysis
What is a difference between cold storage and hot storage in Cortex?
Cortex data storagecold storagehot storagelog query performance - Question #57Security Orchestration Automation and Response
Where in Cortex XSOAR are analystsle to collaborate and converse with others for joint real-time investigations?
Cortex XSOARWar Roomreal-time collaborationincident investigation - Question #58Threat Detection and Analytics
Which Cortex XDR component raises an alert when suspicious activity composed of multiple events is detected and deviates from established baseline behavior?
Cortex XDRAnalytics Enginebehavioral baselineanomaly detection - Question #59Security Operations Platform Management
Which two types of content can be installed or upgraded through a Cortex XSIAM content pack? (Choose two.)
Cortex XSIAMcontent packsanalytics alertsdata model rules - Question #60Data Integration and Log Management
What is required to enable ingestion of on-premises firewall logs into Cortex XDR?
Cortex XDRBroker VMlog ingestionon-premises integration - Question #61Incident Prioritization and Triage
A Security Operations Center (SOC) using Palo Alto Networks XSOAR for incident management receives a high volume of alerts daily. An analyst is tasked with prioritizing incidents r...
incident categorizationdata exfiltrationasset criticalitythreat intelligence feed - Question #62Incident Detection and Response Framework
During a post-incident review of a successful ransomware attack, the incident response team identifies that initial alerts were generated but deprioritized due to an 'Information'...
SIEM correlation rulesalert severity escalationransomware detectionincident framework - Question #63Threat Intelligence Operations
A threat intelligence team produces a report on a new APT group known for targeting specific industry sectors using novel obfuscation techniques. This report includes IOCs (Indicat...
threat intelligence integrationAPTIOCsTTPs - Question #64Cloud Security Operations
An organization is migrating its security operations to a cloud-native environment, leveraging Palo Alto Networks Prisma Cloud for security posture management and cloud workload pr...
cloud-native securityPrisma Cloudincident prioritizationcloud service impact - Question #65Vulnerability Management and Incident Response
An organization is using a bespoke vulnerability management system that integrates with Palo Alto Networks Panorama for firewall rule management and XSOAR for incident orchestratio...
vulnerability managementzero-day CVEthreat intelligenceactive exploitation context - Question #66Incident Investigation and Containment
A Security Operations Center (SOC) using Cortex XDR observes a high-severity alert indicating a potential ransomware attack. The alert details include a specific file hash (SHA256:...
Cortex XDRfile hash indicatorAutoFocusransomware containment - Question #67Threat Intelligence and Incident Response
During a forensic investigation using Cortex XDR, an analyst discovers a persistent backdoor communicating with an external IP address (192.0. 2.100). The analyst needs to quickly...
Cortex XSOARIP reputation lookupthreat intelligence orchestrationautomated blocking - Question #68Threat Intelligence Operations
A sophisticated APT group is observed using a custom, polymorphic malware variant. The only consistent indicator found across initial compromises is the use of a unique, newly regi...
Cortex XSOARcustom threat intelligence feedC2 domainindicator operationalization - Question #69Malware Analysis and Threat Detection
A Security Operations Center (SOC) analyst is investigating a surge of highly evasive malware samples targeting their organization. The current strategy involves submitting suspici...
WildFirezero-day malwaredynamic analysisbehavioral intelligence - Question #70Advanced Threat Intelligence and Incident Response
During an incident response engagement, a forensic investigator discovers a persistent threat actor using a custom command-and- control (C2) protocol over port 53 (DNS). The existi...
DNS C2Unit 42 threat intelligenceWildFireAPT TTP analysis - Question #71Threat Intelligence and Analysis
A sophisticated APT group is observed to be rapidly developing and deploying new malware variants. Your organization needs to not only identify these new variants but also understa...
WildFirethreat intelligence integrationNGFW signaturesmalware analysis - Question #72Threat Intelligence and Analysis
A Security Operations Center (SOC) is attempting to proactively identify and defend against an evolving spear-phishing campaign that uses novel techniques to deliver custom-built m...
WildFireUnit 42spear-phishing defensethreat intelligence - Question #73Incident Response
A critical zero-day vulnerability is publicly disclosed in a widely used web server. Your organization's incident response plan dictates immediate action to identify potential expl...
zero-day vulnerabilityUnit 42incident responseWildFire - Question #74Security Architecture and Design
You are a lead security engineer at a large enterprise, tasked with optimizing the organization's threat intelligence pipeline for maximum effectiveness against polymorphic malware...
threat intelligence pipelineWildFireNGFWAPT defense architecture - Question #75Threat Intelligence and Analysis
An incident response team is investigating a potential breach involving an internal server communicating with a suspicious external IP address. Initial checks on VirusTotal for the...
C2 detectionWildFire behavioral analysisUnit 42 TTPsVirusTotal - Question #76Security Monitoring and Alert Triage
A Security Operations Center (SOC) analyst is reviewing alerts generated by a Palo Alto Networks Next-Generation Firewall (NGFW) configured with Threat Prevention. An alert is trig...
false positivealert classificationC2 beaconingNGFW threat prevention - Question #77Security Monitoring and Alert Triage
During a routine security audit, it's discovered that a critical server was successfully breached weeks ago by an advanced persistent threat (APT) group. The breach involved sophis...
false negativeAPT lateral movementCortex XDRWildFire - Question #78Security Monitoring and Alert Triage
A Palo Alto Networks NGFW with URL Filtering and Threat Prevention enabled flags an internal user attempting to access a 'gambling' category website. The SOC policy strictly prohib...
false positiveURL filteringalert classificationmiscategorization - Question #79Security Monitoring and Alert Triage
A SOC uses Palo Alto Networks Cortex XDR for endpoint detection and response. A new custom behavioral threat detection rule is implemented to identify suspicious PowerShell activit...
false positiveCortex XDRdetection rule tuningPowerShell behavioral detection - Question #80Security Orchestration Automation and Response
A large enterprise utilizes Palo Alto Networks security infrastructure, including NGFWs, Cortex XSOAR for security orchestration, automation, and response, and a centralized SIEM....
false negativeXSOAR playbooksCVE coverage gapthreat intelligence ingestion