
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 8
2.8 Conduct Basic Threat Hunting Based on a Common Indicator Types SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 4)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
25questions here
5free pages
6concepts
16%of the exam
Questions 16–20
- 16
A threat hunter is starting a hunt for a newly discovered malware family that uses a specific command-and-control (C2) domain. The hunter has access to firewall logs, DNS logs, and endpoint process execution logs. According to the basic threat hunting process, what should the hunter do first?
Select an answer first - 17
In the threat hunting process, what is the purpose of the validation step?
Select an answer first - 18
An analyst needs to find all log entries where the destination domain contains 'malware' as a substring. Which search technique should be used?
Select an answer first - 19
An analyst observes a domain in DNS logs and the same domain in proxy logs. What does this correlation indicate?
Select an answer first - 20
What is the primary purpose of documenting threat hunting activities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.