Palo Alto Networks SecOps-Pro - Palo Alto Networks Security Operations Professional Exam
Page: 3 / 22
Total 109 questions
Question #11 (Topic: Exam A)
Which component of Cortex XDR is designed to detect insider threats?
A. Forensics
B. Identity Analytics
C. Cloud Identity Engine
D. Host Insights
Answer: B
Question #12 (Topic: Exam A)
A new incident in Cortex XSIAM contains WildFire malware and Behavioral Threat Protection (BTP) alertsout an unsigned process attempting to dump the memory of Isass.exe.
Which initial verdict applies to this incident?
Which initial verdict applies to this incident?
A. False positive
B. True positive
C. False negative
D. True negative
Answer: B
Question #13 (Topic: Exam A)
A file hash is evaluated a Cortex XSOAR by using two unique threat feeds:
VirusTotal feed (rating of B- usually reliable) and the file verdict is malicious
AlienVault feed (rating of B- usually reliable) and the file verdict is benign
What is the file verdict in XSOAR?
VirusTotal feed (rating of B- usually reliable) and the file verdict is malicious
AlienVault feed (rating of B- usually reliable) and the file verdict is benign
What is the file verdict in XSOAR?
A. Benign
B. Malicious
C. Unknown
D. Suspicious
Answer: B
Question #14 (Topic: Exam A)
A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint.
Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?
Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?
A. Log stitching
B. User authentication management
C. Indicator of compromise (IOC) rule
D. Analytics
Answer: A
Question #15 (Topic: Exam A)
Where can an administrator begin to grant a new non-SSO user access to a Cortex XDR tenant?
A. Cortex XDR tenant settings under Access Management
B. Cortex Gateway
C. Customer Support Portal
D. IT Service Portal
Answer: A