
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 1
2.1 Identify and Explain the Steps of the NIST Incident Response Plan SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 4)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
28questions here
6free pages
5concepts
16%of the exam
Questions 16–20
- 16
A company has experienced a data breach. The incident response team has contained the incident and eradicated the threat. However, the team is unsure whether the attacker had access to the data before containment. What is the most important action to take during the recovery phase?
Select an answer first - 17
A company has suffered a ransomware attack. The incident response team has contained the incident and eradicated the malware. However, the team is unsure whether the backups are clean because the ransomware may have been present for several weeks. What is the most appropriate next step?
Select an answer first - 18
Which of the following activities is a key component of the Preparation phase in the NIST incident response lifecycle?
Select an answer first - 19
In the Post-Incident Activity phase, what is the purpose of a lessons-learned meeting?
Select an answer first - 20
A security analyst is investigating an alert about a potential data exfiltration. The analyst has gathered logs from the firewall, the endpoint, and the authentication server. What is the analyst doing in this step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.