
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 2
2.2 Explain the Concept of Incident Management and Response SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 7)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
34questions here
7free pages
8concepts
16%of the exam
Questions 31–34
- 31
A security analyst receives an alert about a single workstation exhibiting unusual outbound traffic. Initial triage confirms the traffic is malicious and the workstation is compromised. The incident commander wants to prevent lateral movement while preserving evidence for forensic analysis. Which action aligns with the containment phase of the incident management lifecycle?
Select an answer first - 32
A security analyst receives an alert about a possible brute-force attack on a VPN gateway. The analyst is unsure if the alert is a true positive. The incident management lifecycle includes preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Which phase is the analyst currently in?
Select an answer first - 33
Which factor is most commonly used to determine the priority of an incident?
Select an answer first - 34
During a major incident, the incident commander is overwhelmed with requests from multiple stakeholders, including legal, PR, and executives. The commander is spending too much time on communication and not enough on coordinating the response. What is the most effective way to address this?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SECURITY-OPERATIONS-PROFESSIONAL
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.