最新的Palo Alto Networks Security Operations Professional - SecOps-Pro免費考試真題

問題1
An administrator has configured Cortex XDR to ingest logs from third-party firewalls and is using Cortex XDR agents on endpoints. The goal is to see network connections from the firewalls correlated with the endpoint processes that initiated them. Which feature handles this correlation to form network stories?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題2
An incident response team is investigating a potential breach involving an internal server communicating with a suspicious external IP address. Initial checks on VirusTotal for the external IP yield no results. Upon further investigation, network telemetry suggests the communication pattern is highly unusual and indicative of command-and-control (C2) activity. The team needs to determine if this C2 traffic is associated with a known threat actor, understand their TTPs, and identify specific exploit methods. Which of the following distinct characteristics, when comparing WildFire, Unit 42, and VirusTotal, are most critical for the team to leverage in this situation?
(Select all that apply)

正確答案: B,C,D
說明:(僅 VCESoft 成員可見)
問題3
A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題4
In Cortex XDR, what can be used to notify analysts of atomic behavior related to processes, registry, files, and network activity?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題5
You are a lead security engineer at a large enterprise, tasked with optimizing the organization's threat intelligence pipeline for maximum effectiveness against polymorphic malware and advanced persistent threats (APTs). The current setup primarily relies on basic SIEM correlation and generic firewall rules. Your goal is to implement a solution that provides real-time, context- rich intelligence, automates detection of unknown threats, and enables proactive defense. Which of the following architectural and operational decisions would be most aligned with achieving these objectives?

正確答案: C
說明:(僅 VCESoft 成員可見)
問題6
Which solution will minimize mean time to resolution (MTTR) when, as a result of previous malware infection, a company's Windows endpoint is suffering a small amount of file corruption and modified registry keys?

正確答案: C
說明:(僅 VCESoft 成員可見)