
Palo Alto NetworksCertified Security Operations Professional
Domain 3Objective 1
3.1 Identify and Explain the Use of Key Cortex XDR Elements SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 3)
Part of the Cortex XDR domain, which accounts for 23% of the SECURITY-OPERATIONS-PROFESSIONAL exam.
30questions here
6free pages
8concepts
23%of the exam
Questions 11–15
- 11
Which of the following is NOT a typical data source for Cortex XDR investigations?
Select an answer first - 12
An analyst is examining an alert for a suspicious executable that was downloaded and executed on a user's laptop. The analyst needs to determine the original process that initiated the download and trace every subsequent action taken by the executable, including any child processes it spawned and files it modified. Which Cortex XDR investigation feature provides this specific root-cause-to-impact mapping?
Select an answer first - 13
A security operations center (SOC) is handling a critical incident. An alert was generated for a suspicious PowerShell command on a server. The analyst investigates and finds that the PowerShell command downloaded and executed a payload. The analyst submits the payload to WildFire, which returns a verdict of 'malicious'. The analyst then uses the Causality View to see that the PowerShell command was spawned by a scheduled task that was created by a compromised user account. The analyst needs to remediate the incident. The analyst has already isolated the server. What is the most important next step in the remediation process?
Select an answer first - 14
During an investigation of a potential insider threat, an analyst needs to gather evidence from multiple sources: the user's workstation activity, the network firewall logs showing their outbound connections, and the cloud access logs from their Office 365 account. The analyst wants to view all this data in a single investigation interface to correlate the user's actions across all environments. Which Cortex XDR data source capability enables this comprehensive investigation?
Select an answer first - 15
How does WildFire integrate with Cortex XDR to enhance detection of unknown threats?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.