
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 8
2.8 Conduct Basic Threat Hunting Based on a Common Indicator Types SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 3)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
25questions here
5free pages
6concepts
16%of the exam
Questions 11–15
- 11
When querying firewall logs for a specific IP address, which search technique is most effective?
Select an answer first - 12
A threat hunter has completed a hunt that identified multiple hosts communicating with a known malicious IP. The hunter needs to report the findings to management, who are not technical. What is the most effective way to communicate the findings?
Select an answer first - 13
A threat hunter has completed a hunt that identified a compromised host communicating with a known malicious IP. The hunter needs to report the findings to the incident response team. What should the report include to be most actionable?
Select an answer first - 14
An analyst wants to search for evidence of a malicious file executing on a host. Which data source is most appropriate for this search?
Select an answer first - 15
A threat hunter is investigating a potential compromise. The hunter finds that a host resolved a known malicious domain, but the subsequent connection was to an IP address not on any threat list. Additionally, the host's endpoint logs show a process creating a file with a hash that is not yet flagged as malicious. The hunter must decide whether to escalate to incident response. Given the conflicting indicators, what is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.