Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Which Cortex XSOAR feature should a Security Operations Architect use to automatically calculate, track, and display SLA compliance metrics for incoming security incidents?
Cortex XDR Analytics Engine
Incident SLAs and SLA dashboards
Incident SLAs track time thresholds and generate automated compliance metrics and dashboard widgets in XSOAR.
WildFire submission quotas
Threat Intelligence Management feeds
You are designing executive dashboards in Cortex XSIAM to report security posture trends over the last quarter. Management requires a metric that shows the reduction in successful phishing compromises resulting from user training. Which metric should you implement?
Average Analyst Playbook Execution Time
Cortex XDR Agent Installation Percentage
Phishing Incident Recurrence and Successful Compromise Rate Trend
Tracking the trend of successful compromises over time accurately measures the impact of user awareness and email security controls.
Total Phishing Payload Extraction Volume
When establishing a baseline for Security Operations Center (SOC) alert volume in Cortex XSIAM, what is the primary purpose of this baseline?
To determine the exact licensing cost for future Cortex XDR expansion
To configure firewall security policies automatically
To replace manual analyst triage with fully automated playbook closures
To identify operational anomalies and deviations that require investigation or tuning
Baselines define normal behavior so that operational anomalies can be flagged and addressed.
While establishing baselines for Cortex XDR alert volume to detect operational anomalies, you notice a massive seasonal spike in alerts that threatens to invalidate your baseline threshold. What is the best practice approach to handle this seasonality in security metrics?
Permanently increase the global alert severity threshold to ignore all alerts during the seasonal window.
Replace all quantitative alert metrics with qualitative analyst feedback scores.
Disable automated alert generation in Cortex XDR until the seasonal window concludes.
Segment historical data and apply contextual rolling baselines that account for expected cyclical business variations.
Segmenting data and applying rolling or seasonal baselines ensures that expected fluctuations do not skew anomaly detection or KPI reporting.
Your SOC leadership team needs to measure the operational efficiency of incident containment. Which metric should you track within Cortex XSOAR to evaluate how quickly analysts isolate compromised endpoints?
False Alarm Percentage
Mean Time to Detect (MTTD)
Mean Time to Contain (MTTC)
MTTC directly measures the speed and effectiveness of containment actions within incident response.
Alert Escalation Ratio
You are preparing a security posture report for the board of directors using Cortex XSIAM. The board wants to understand risk exposure reduction over time. Which metric provides the most executive-level strategic value regarding risk posture?
Mean Time to Remediate (MTTR) critical vulnerabilities and associated threat exposure trends
Tracking remediation velocity for critical vulnerabilities directly maps to enterprise risk exposure reduction.
Total number of firewall rule modifications performed per week
Number of Cortex XDR agent heartbeat failures
Total gigabytes of log data ingested into Cortex Data Lake daily
Want more Operationalizing Security Metrics practice?
Practice this domainWhen designing a threat hunting methodology aligned with the MITRE ATT&CK framework, an architect wants to identify adversary persistence mechanisms. Which tactic category should the analyst focus queries on?
Initial Access
Persistence
Persistence techniques allow adversaries to maintain access across restarts.
Collection
Execution
An architect is designing an incident response workflow in Cortex XSOAR using the Incident Spooler. Which component is primarily responsible for processing queued events into actionable incidents?
Cortex XSOAR Server engine
The core engine processes the spooler queue to create incidents.
Demisto REST API
Threat Intel Management module
Cortex XSIAM Data Lake collector
An incident response architect is defining severity levels for security alerts in Cortex XDR. Which severity classification typically triggers automated containment playbooks without human intervention?
Debugging
Low
Informational
Critical
Critical alerts often trigger immediate automated isolation or blocking.
An organization is integrating Prisma Cloud with Cortex XSOAR to automate cloud incident response. When configuring the Prisma Cloud integration instance in XSOAR, which authentication mechanism is recommended to securely fetch alerts without using static user credentials?
LDAP bind credentials through a Cortex XDR Broker VM
HTTP Basic Authentication with administrative credentials
OAuth 2.0 Client Credentials grant via a dedicated Service Account
Service accounts with generated access keys provide secure, non-user-tied authentication.
SAML 2.0 Federation token exchange
In a multi-tenant Cortex XSOAR deployment, an architect needs to restrict access to specific playbooks so that Tenant A analysts cannot view or execute playbooks owned by Tenant B. Where is this access control configured?
Global Server Configuration settings
Role-Based Access Control (RBAC) settings under Settings > Common > Roles
RBAC allows granular control over what objects a role can access.
Playbook JSON source code permissions
Integration instance parameters
An enterprise security architect is integrating Cortex XSIAM with an external SIEM using the Syslog Export feature. The security team notices that certain sensitive fields need to be redacted before export. Where should the architect configure this transformation?
Magnifier machine learning configuration
Cortex XDR Agent installation parameters
Data Forwarding Rules / Log Forwarding Profiles
Log forwarding profiles allow filtering and masking before export.
XSOAR automation playbook script tasks
Want more Secops Frameworks And Threat Response Architecture practice?
Practice this domainAn architect is integrating Cortex XSOAR with Palo Alto Networks Panorama to automate firewall rule creation. A playbook needs to check if a security policy rule already exists before creating a new one. Which Cortex XSOAR integration command should the architect use to query the existing rules on Panorama?
xdr-get-firewall-rules
panorama-list-policies
pan-os-get-security-rules
The pan-os-get-security-rules command queries Panorama or NGFW for existing security rules.
fw-query-rules
An architect is designing a centralized logging and management architecture using Panorama for 50 distributed Next-Generation Firewalls. Each firewall generates high volumes of traffic logs. To optimize bandwidth consumption and storage, which Panorama feature should the architect configure on the managed firewalls to forward logs directly to an external SIEM while retaining centralized policy management?
Disable traffic logging entirely on the firewalls and only enable threat logging to save bandwidth.
Configure Panorama Collector groups to act as an intermediate proxy for all syslog traffic to the SIEM.
Configure Log Forwarding Profiles on the firewalls to send syslog directly to the SIEM while keeping Panorama for configuration and management.
Log Forwarding Profiles allow firewalls to send logs directly to external destinations like SIEMs independently of Panorama collection.
Configure Panorama to ingest all logs and then use an automated script to rsync logs from Panorama to the SIEM every night.
An architect is deploying Panorama and needs to manage firewalls deployed across different geographic regions with distinct administrative teams. Each team should only be able to view and manage their own local firewalls and policies, but global security rules must apply to all. Which Panorama structural feature should the architect implement?
Device Groups combined with Administrator Roles and Access Domains.
Device Groups organize firewalls logically, while Access Domains and Admin Roles restrict administrators to specific device groups and templates.
Multiple virtual routers inside a single device group.
Separate Panorama virtual appliances for each region configured in an HA mesh cluster.
Dynamic Address Groups with tag-based RBAC.
An architect is configuring User-ID to identify users behind a Microsoft Active Directory domain. Which protocol does the Palo Alto Networks User-ID agent use to query Active Directory security event logs for user login and logoff events?
NetFlow v9 templates
SNMPv3 polling of Active Directory database tables
WMI or Windows RPC/SMB to read Security Event Logs
User-ID agent queries Windows security event logs via WMI or RPC/SMB.
HTTP POST requests sent by the Active Directory DNS service
An architect is deploying Prisma Access to secure remote workers. The organization uses explicit proxying for web traffic and requires user-ID mapping for explicit proxy connections. Which Prisma Access component and configuration must be deployed to correctly map users authenticated via an explicit proxy to their respective User-ID groups?
Deploy the Explicit Proxy feature in Prisma Access, configure proxy authentication, and integrate with Cloud Identity Engine (CIE) to extract user identity from proxy headers.
Cloud Identity Engine combined with Prisma Access explicit proxy configuration maps authenticated proxy users correctly.
Rely solely on GlobalProtect portal cookies for explicit proxy traffic identification.
Configure standard IP-to-User mapping via User-ID agents on the remote user laptops without a proxy.
Configure SNMP traps on the proxy server to send ARP tables to Panorama.
An enterprise architect is designing an architecture where Prisma Cloud computes compliance for multi-cloud environments (AWS, Azure, GCP). To provide least-privilege access for Prisma Cloud to discover and assess resource configurations across multiple AWS accounts, which deployment method should the architect recommend?
A single hardcoded AWS IAM Access Key and Secret Access Key embedded in the Prisma Cloud console settings.
Deploying a Prisma Cloud Defender daemonset on every AWS EC2 instance in the enterprise.
AWS IAM Role with a unique External ID and CloudFormation stack sets deployed across all target accounts linked to a master payer account.
Using IAM roles with external IDs provides secure cross-account trust without sharing long-lived AWS secret keys.
Configuring AWS Security Hub to push JSON dumps via FTP to Prisma Cloud.
Want more Palo Alto Networks Product Integration And Architecture practice?
Practice this domainThe SecOps-Architect exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 3 domains: Operationalizing Security Metrics, Secops Frameworks And Threat Response Architecture, Palo Alto Networks Product Integration And Architecture. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks SecOps-Architect exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.