
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 1
2.1 Identify and Explain the Steps of the NIST Incident Response Plan SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 2)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
28questions here
6free pages
5concepts
16%of the exam
Questions 6–10
- 6
In the Detection and Analysis phase of the NIST incident response lifecycle, what is the primary goal of analyzing a potential incident?
Select an answer first - 7
A security team is responding to a ransomware incident that has encrypted files on several file servers. The team has isolated the affected servers, but the ransomware is still spreading to other systems. The team needs to stop the spread while preserving evidence for potential legal action. Which approach best balances containment and evidence preservation?
Select an answer first - 8
In the Containment, Eradication, and Recovery phase, what is the primary objective of the containment step?
Select an answer first - 9
A company has successfully contained and eradicated a malware outbreak. They are now restoring systems from clean backups and verifying that they are operating normally. According to the NIST incident response lifecycle, which phase are they in?
Select an answer first - 10
A SOC analyst is investigating a potential incident involving a compromised user account. The analyst has confirmed that the account was used to access sensitive data. The analyst must decide whether to contain the incident immediately or continue gathering evidence. Which approach aligns with the NIST incident response lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.