
Palo Alto NetworksCertified Security Operations Architect
Domain 2Objective 3
2.3 Define the Strategy for Data Sources, Integrations, and Feeds, and Select the Appropriate Onboarding Methods SECURITY-OPERATIONS-ARCHITECT Practice Questions (Page 4)
Part of the Platform and Data Architecture domain, which accounts for 49% of the SECURITY-OPERATIONS-ARCHITECT exam.
33questions here
7free pages
7concepts
49%of the exam
Questions 16–20
- 16
A company must comply with data retention regulations that require logs to be kept for 2 years. They also need to ensure that sensitive data is protected. Which practices should they implement? (Select all that apply.)
Select an answer first - 17
A security operations team is selecting threat intelligence feeds. They have a limited budget and need to cover both external threats and insider threats. They are considering two feeds: one focused on external malware and one focused on user behavior analytics. Which approach is most effective?
Select an answer first - 18
A company's security platform stores logs for 30 days, but their compliance team requires 90 days of retention for certain data. The platform's storage is limited. What is the best approach to meet the requirement?
Select an answer first - 19
A company ingests logs from multiple sources: firewalls, endpoints, and cloud services. Each source uses different log formats and field names. The security team wants to ensure that alerts are consistent and searchable across all data. What should they implement?
Select an answer first - 20
Which onboarding method is most appropriate for a data source that does not support agent installation and requires real-time event streaming?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-ARCHITECT” is a trademark of its owner, used for identification only.