
Palo Alto NetworksCertified Cloud Security Professional
Domain 1Objective 1
1.1 Demonstrate Understanding of SOC Components and Functions CLOUD-SECURITY-PROFESSIONAL Practice Questions (Page 4)
Part of the Security Operations Center (SOC) Fundamentals domain, which accounts for 10% of the CLOUD-SECURITY-PROFESSIONAL exam.
25questions here
5free pages
5concepts
10%of the exam
Questions 16–20
- 16
A SOC is implementing a new escalation policy. The policy states that any alert involving a potential data breach must be escalated directly to the incident commander, bypassing the Tier 2 manager. Which organizational principle does this policy violate?
Select an answer first - 17
Which analytics technique in SOC operations is used to detect insider threats by establishing a baseline of normal user activity and flagging deviations from that baseline?
Select an answer first - 18
During a major incident, the incident responder needs to coordinate containment actions across multiple teams, but the SOC manager is unavailable. According to a typical SOC chain of command, who is the most appropriate person to assume the incident command role?
Select an answer first - 19
Which SOC function is performed after an incident has been contained and eradicated, and involves documenting lessons learned and communicating findings to stakeholders?
Select an answer first - 20
A SOC is evaluating a new tool to provide real-time visibility into process execution, file modifications, and memory activity on endpoints. The tool must also be able to isolate an endpoint from the network upon a confirmed compromise. Which tool category meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CLOUD-SECURITY-PROFESSIONAL” is a trademark of its owner, used for identification only.