Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Security Operations Professional

Domain 2Objective 7

2.7 Evaluate False Positive, False Negative, and True Positive Security Cases SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 1)

Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.

13questions here
3free pages
5concepts
16%of the exam

Questions 1–5

  1. 1application · medium

    A security analyst is reviewing a case where a user's machine was compromised by a phishing email. The email gateway did not generate an alert for the email because the sender domain had a high reputation score. The analyst confirms the email contained a malicious attachment that executed and installed a backdoor. How should the analyst classify this case?

    Select an answer first
  2. 2application · medium

    A security operations center (SOC) analyst reviews a case where an endpoint protection platform did not generate any alert for a process that later was confirmed to be a novel ransomware variant. The ransomware encrypted files on the host, and the analyst confirmed the sample was not in any threat intelligence feed at the time of execution. How should the analyst classify this security case?

    Select an answer first
  3. 3foundation · easy

    Which scenario best illustrates a false negative security case?

    Select an answer first
  4. 4application · medium

    A security analyst is reviewing a case where a user's machine was infected with malware that was delivered via a USB drive. The endpoint protection platform did not generate any alert because the malware was a new, unknown variant. The analyst confirms the malware was present and executed on the machine. How should the analyst classify this case?

    Select an answer first
  5. 5foundation · easy

    A security analyst investigates an alert for a suspicious PowerShell command. The investigation reveals that the command was executed by a threat actor and resulted in data exfiltration. How should this security case be classified?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.