Skip to content

Security Operations Questions

Practice questions for Security Operations topic in Palo Alto Networks Certified Cybersecurity Practitioner. 26 questions covering this domain.

26 questions8 easy12 medium6 hard
Q1
easy

Which activity proactively searches for hidden threats rather than waiting only for alerts?

Q2
easy

Which process coordinates containment, eradication, recovery, and lessons learned after a security incident?

Q3
hard

No alert has fired, but analysts suspect stealthy activity and search telemetry for hidden adversary behavior. Which activity is this?

Q4
medium

An organization needs Palo Alto Networks threat research, incident response, and security consulting expertise. Which service organization fits?

Q5
medium

A team wants experts to proactively search for hidden threats in its environment. Which service fits?

Q6
medium

A company needs expert monitoring, hunting, and response as an ongoing service. Which Unit 42 service category fits?

Q7
hard

A confirmed breach requires containment, eradication, recovery, and post-incident improvement. Which process should organize the work?

Q8
medium

A company wants to evaluate exposed assets and attack paths before adversaries exploit them. Which service fits?

Q9
hard

A SOC needs centralized event collection and correlation to support investigations. Which platform category is the best fit?

Q10
medium

Responders need to analyze evidence to determine the scope and nature of an incident. Which service activity fits?

Q11
medium

A security leader wants to evaluate security operations maturity, processes, and controls. Which service fits?

Q12
easy

Which platform category collects and analyzes security events for detection and investigation?

Q13
easy

Which platform category automates and coordinates security workflows and response actions?

Q14
easy

Which Cortex solution automates SOC workflows and supports incident collaboration through playbooks?

Q15
medium

Analysts need endpoint, network, identity, cloud, and exposure data in one operational view. Which XSIAM concept fits?

Q16
medium

A tool continuously finds unknown risks and exposed services on connected systems. Which ASM capability is this?

Q17
easy

Which function discovers and manages exposed assets and unknown risks across connected systems?

Q18
hard

A SOC wants to enrich alerts, open tickets, notify teams, and run response steps automatically. Which platform category fits?

Q19
medium

A SOC wants repeatable incident-response steps to run through integrations with less manual work. Which XSOAR capability fits?

Q20
medium

A responder adds context about adversaries, techniques, and indicators to an investigation. Which resource is being used?

Sign in to see all 26 questions

Create a free account to browse all questions — completely free during our launch phase.