
Palo Alto NetworksCertified Security Operations Professional
Domain 2Objective 1
2.1 Identify and Explain the Steps of the NIST Incident Response Plan SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 6)
Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
28questions here
6free pages
5concepts
16%of the exam
Questions 26–28
- 26
An analyst detects a potential incident involving a compromised user account. The analyst has confirmed that the account was used to access sensitive data. According to the NIST incident response lifecycle, what should the analyst do next?
Select an answer first - 27
An organization's SIEM generates an alert for a suspicious outbound connection from a finance workstation to an unknown IP address. The analyst reviews the alert and sees that the workstation also has a new scheduled task. According to the NIST incident response lifecycle, which phase is the analyst currently in?
Select an answer first - 28
According to NIST SP 800-61, which of the following correctly lists the four main phases of the incident response lifecycle in order?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SECURITY-OPERATIONS-PROFESSIONAL
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.