
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 8
2.8 Conduct Basic Threat Hunting Based on a Common Indicator Types SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 2)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
25questions here
5free pages
6concepts
16%of the exam
Questions 6–10
- 6
Which of the following is a common indicator type used in threat hunting to identify a specific network destination?
Select an answer first - 7
A security analyst is hunting for a phishing campaign that uses a specific email address as the sender. The analyst wants to identify any internal users who received emails from this address. Which data source and search approach should the analyst use?
Select an answer first - 8
A threat hunter is investigating a potential data exfiltration. The hunter finds that a host has been sending large amounts of data to an IP address that is not on any threat list. The hunter also notices that the host recently downloaded a file with a hash that matches a known malware signature. What should the hunter do to assess the severity of the situation?
Select an answer first - 9
An analyst is hunting for indicators of compromise (IOCs) in a large dataset of firewall logs. The analyst has a list of suspicious IP addresses and domains. Which search technique would yield the most comprehensive results?
Select an answer first - 10
When reporting threat hunting findings, what is the most important characteristic of the report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.