Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Security Operations Professional

Domain 2Objective 1

2.1 Identify and Explain the Steps of the NIST Incident Response Plan SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 6)

Part of the Threat Intelligence and Incident / Case Response domain, which accounts for 16% of the SECURITY-OPERATIONS-PROFESSIONAL exam.

28questions here
6free pages
5concepts
16%of the exam

Questions 26–28

  1. 26application · medium

    An analyst detects a potential incident involving a compromised user account. The analyst has confirmed that the account was used to access sensitive data. According to the NIST incident response lifecycle, what should the analyst do next?

    Select an answer first
  2. 27application · medium

    An organization's SIEM generates an alert for a suspicious outbound connection from a finance workstation to an unknown IP address. The analyst reviews the alert and sees that the workstation also has a new scheduled task. According to the NIST incident response lifecycle, which phase is the analyst currently in?

    Select an answer first
  3. 28foundation · easy

    According to NIST SP 800-61, which of the following correctly lists the four main phases of the incident response lifecycle in order?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.