Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Security Operations Professional

Domain 2Objective 7

2.7 Evaluate False Positive, False Negative, and True Positive Security Cases SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 2)

Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.

13questions here
3free pages
5concepts
16%of the exam

Questions 6–10

  1. 6application · medium

    A security analyst investigates an alert triggered by a user's workstation beaconing to a known malware command-and-control domain. The analyst reviews the endpoint logs and confirms the domain was contacted, but the traffic was generated by a vulnerability scanner that was mistakenly configured with the user's proxy credentials. How should the analyst classify this security case?

    Select an answer first
  2. 7foundation · medium

    A security operations center receives an alert from an endpoint detection and response (EDR) tool. The alert indicates that a workstation executed a PowerShell command that downloaded a file from an external IP address and then ran it. The analyst investigates and finds the file is a known remote access trojan (RAT) that is not present in the local threat intelligence feed but is confirmed malicious by an external sandbox analysis. The workstation's user had no reason to download this file. Which classification best describes this security case?

    Select an answer first
  3. 8application · medium

    A security analyst is reviewing a case where a user's machine was compromised by a drive-by download from a compromised website. The web filter did not generate an alert for the website because it was categorized as 'business' and had a high reputation score. The analyst confirms the website was compromised and served malicious JavaScript. How should the analyst classify this case?

    Select an answer first
  4. 9application · medium

    An analyst investigates an alert that triggered on a user executing a PowerShell command that matched a known obfuscation technique. The analyst reviews the command line and sees it decodes a base64 string that downloads and executes a payload from a suspicious domain. Further analysis confirms the payload is a known remote access trojan (RAT). How should the analyst classify this case?

    Select an answer first
  5. 10foundation · medium

    A security operations analyst is reviewing a case generated by an intrusion detection system. The alert fired on network traffic that matches a known exploit signature, but after investigation, the analyst determines the traffic was a benign penetration test conducted by the organization's own security team. Which security case classification best describes this alert?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.