SecOps-Pro Palo Alto Networks Certified Security Operations Professional Practice Questions
Prepare for SecOps-Pro with more than an answer.
Unlock the full exam and previous versions
- v1Palo Alto Networks Certified Security Operations Professional 141 questions Current
- SecOps-ProfessionalLegacy Palo Alto Networks Certified Security Operations Professional 250 questions Locked
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Security Operations Fundamentals25%
- Threat Intelligence and Incident Response16%
- Cortex XDR23%
- Cortex XSOAR16%
- Cortex XSIAM20%
- 1
While investigating a suspicious file, an analyst checks the WildFire verdict and sees 'Grayware'. How does this verdict differ from 'Malware' and 'Benign'?
Show answer details
Correct answer: B
Grayware is the classification for Potentially Unwanted Programs (PUPs). It is distinct from Malware (which is intended to harm) and Benign (which is safe). Security policies often block Grayware to improve performance and user experience, even if it's not a direct security exploit.
- 2
A security analyst is conducting a threat hunt using Cortex XDR. They suspect a specific host is communicating with a Command and Control (C2) server. Which combination of indicator types would be MOST valuable for this specific investigation? (Select TWO)
Show answer details
Correct answer: A, C
Malware often uses Domain Generation Algorithms (DGA) or hardcoded domains to reach C2 servers. Investigating DNS queries (Domain indicators) is a critical step in verifying C2 activity.
C2 communications rely on network connections. The Destination IP is a primary network indicator used to identify connections to known malicious infrastructure.
- 3
A Behavioral Threat Protection (BTP) rule in Cortex XDR triggers an alert for 'Suspicious PowerShell Execution' on a developer's machine. Upon investigation, the analyst finds the developer was running a legitimate automation script. How should this incident be classified?
Show answer details
Correct answer: C
A False Positive occurs when a security tool correctly identifies activity matching a logic rule, but the activity itself is benign (not malicious). In this case, the detection logic worked, but the behavior was authorized.
- 4
A SOC manager is designing a Role-Based Access Control (RBAC) strategy for a Cortex XDR environment. The organization requires a specific 'Tier 1 Analyst' role that allows users to view alerts and incidents, perform basic investigations, and add comments, but strictly prohibits them from executing response actions (such as isolating endpoints) or modifying global security policies. Which combination of permissions is the MOST appropriate configuration for this role?
Show answer details
Correct answer: C
Cortex XDR allows for granular custom roles. To meet the requirement of viewing and investigating without response capabilities, a custom role must be created where View permissions are granted but Response Actions (like isolation or Live Terminal) are explicitly disabled. The Instance Administrator role is too powerful regardless of scoping.
- 5
An organization is subject to strict GDPR regulations requiring that personal data in security logs be retained for exactly 90 days and then securely purged. The security architect is configuring Cortex Data Lake to support Cortex XDR. How should the log retention be managed to ensure compliance?
Show answer details
Correct answer: C
Cortex Data Lake allows administrators to define retention policies based on time. Setting a specific 90-day retention policy ensures that data is kept for the required compliance period and then purged, regardless of storage quota usage (assuming quota is sufficient). Relying on overwrite (Option B) is risky for compliance as volume fluctuations could shorten the retention window.
- 6
A CISO requests a high-level weekly report that summarizes the organization's security posture, focusing on the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) metrics, along with a breakdown of incidents by severity. Which feature in Cortex XDR is BEST suited to automate this requirement?
Show answer details
Correct answer: C
Cortex XDR allows users to build custom dashboards with specific widgets (including operational metrics like MTTD/MTTR) and then schedule these dashboards to be generated as PDF reports and emailed to stakeholders on a recurring basis. This directly addresses the automation and content requirements.
