Skip to content

Security Operations Questions

Practice questions for Security Operations topic in Palo Alto Networks Certified Cybersecurity Apprentice. 26 questions covering this domain.

26 questions6 easy12 medium8 hard
Q1
medium

An analyst reviews evidence to determine whether an alert is a true incident. Which function is being performed?

Q2
easy

A centralized team monitors, investigates, and responds to security activity. Which term fits?

Q3
medium

A SOC first recognizes suspicious behavior from telemetry and alerts. Which function is being performed?

Q4
hard

Analysts need to correlate firewall, endpoint, and cloud logs to find related suspicious activity. Which technology best fits?

Q5
hard

A phishing alert triggers a playbook that enriches indicators, notifies users, and creates a ticket. Which technology best fits?

Q6
medium

A team contains a compromised endpoint and blocks malicious traffic. Which function is being performed?

Q7
easy

A notification is generated when activity may require analyst attention. Which term fits?

Q8
medium

A SOC uses machine learning and automated enrichment to reduce manual triage. Which optimization method is this?

Q9
easy

A raw security-relevant occurrence is recorded by a system. Which term fits?

Q10
hard

A SOC wants help prioritizing noisy alerts and identifying likely true threats. Which concept is most aligned?

Q11
medium

After an incident, a team updates detections and processes to reduce future risk. Which function is being performed?

Q12
medium

Analysts share findings across teams so related alerts are understood faster. Which optimization method is this?

Q13
hard

A rule fires on normal administrator behavior every morning, wasting analyst time. What problem should be tuned?

Q14
hard

A team wants network devices and servers to send logs to a central collector using a common logging protocol. Which function applies?

Q15
easy

A benign activity is incorrectly flagged as malicious. Which term fits?

Q16
medium

A team maps processes to a recognized security framework to guide operations. Which optimization method is this?

Q17
medium

Security is integrated into development and operations workflows instead of being only a final review. Which term fits?

Q18
hard

A later investigation shows malware activity occurred but the SOC never received an alert. What problem does this show?

Q19
medium

A SOC periodically updates rules and procedures as threats and business requirements change. Which optimization method is this?

Q20
easy

A real threat is missed and no alert is generated. Which term fits?

Sign in to see all 26 questions

Create a free account to browse all questions — completely free during our launch phase.