
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 2
2.2 Explain the Concept of Incident Management and Response SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 4)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
34questions here
7free pages
8concepts
16%of the exam
Questions 16–20
- 16
Which phase involves removing the threat from affected systems and eliminating the root cause?
Select an answer first - 17
Which group in an incident response scenario is primarily responsible for providing business context and approving decisions that affect operations?
Select an answer first - 18
A SOC analyst receives an alert about a user account logging in from a new geographic location at an unusual time. The analyst must perform triage. Which action is most appropriate during the initial assessment?
Select an answer first - 19
After a malware outbreak on several servers, the incident response team has contained the spread and eradicated the malware. The team now needs to restore the servers to normal operation. Which action is part of the recovery phase?
Select an answer first - 20
A SOC analyst is triaging an alert about a user account that has been locked out due to multiple failed login attempts. The analyst checks the logs and sees that the failed attempts came from a single IP address over a short period. The user is a high-privilege administrator. What is the most appropriate immediate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.