
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 8
2.8 Conduct Basic Threat Hunting Based on a Common Indicator Types SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 1)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
25questions here
5free pages
6concepts
16%of the exam
Questions 1–5
- 1
During a threat hunt, an analyst finds that a host resolved a malicious domain and then connected to an IP address that is not on the threat list. The analyst also notices that the host downloaded a file with a hash that matches a known malware signature. What should the analyst conclude?
Select an answer first - 2
During a threat hunt, an analyst finds a file hash in an endpoint log and the same hash in a firewall log's SSL decryption metadata. What does this correlation suggest?
Select an answer first - 3
What is the first step in conducting a basic threat hunt?
Select an answer first - 4
A threat hunter is planning a hunt for a new ransomware strain that is known to use a specific file hash. The hunter has access to endpoint logs, network logs, and email logs. According to the threat hunting process, what should the hunter do after formulating the hypothesis?
Select an answer first - 5
During a threat hunt, an analyst finds that several internal hosts resolved a known malicious domain and then connected to an IP address that is also on the threat list. What should the analyst do next to assess the severity of the potential threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.