
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 1
2.1 Identify and Explain the Steps of the NIST Incident Response Plan SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 3)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
28questions here
6free pages
5concepts
16%of the exam
Questions 11–15
- 11
Which of the following activities is part of the eradication step in the Containment, Eradication, and Recovery phase?
Select an answer first - 12
In the NIST incident response lifecycle, what is the primary purpose of the Post-Incident Activity phase?
Select an answer first - 13
A security operations center (SOC) receives an alert for a potential malware infection on a critical server. The alert is based on a single endpoint detection and response (EDR) signal. The SOC manager must decide whether to escalate the alert to a full incident response. Which factor should be the PRIMARY consideration in this decision?
Select an answer first - 14
Which of the following is a typical output of the Post-Incident Activity phase?
Select an answer first - 15
After a major incident, the incident response team conducts a lessons-learned meeting. The team identifies that the lack of a formal communication plan caused delays in notifying stakeholders. Which action best addresses this gap in the context of the NIST lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.