Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

Cybersecurity-Apprentice Security Operations Practice Question

A security analyst in a Security Operations Center (SOC) notices a sudden influx of endpoint alerts related to a new ransomware strain. Where should the analyst typically begin their initial triage within Cortex XDR to understand the scope and root cause of the incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Navigate to Cortex XDR > Incident View to review the automated attack story and affected endpoints.

In Cortex XDR, the Incident View aggregates related alerts into a single incident graph, allowing analysts to quickly see the root cause, scope, and affected endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Run a manual threat hunting query in the Action Center to install new agents.

    Why it's wrong here

    Action Center executes remediations, but triage starts in the Incident View.

  • Access the Policy Editor to disable the infected endpoints from the network.

    Why it's wrong here

    Policy Editor is used for creating security profiles, not for triaging active incidents.

  • Open the Endpoint Protection profiles to manually delete the malware binaries.

    Why it's wrong here

    Profiles configure prevention settings, not incident triage.

  • Navigate to Cortex XDR > Incident View to review the automated attack story and affected endpoints.

    Why this is correct

    The Incident View provides the correlated attack story and root cause analysis.

About these practice questions

This Cybersecurity-Apprentice question is part of Courseiva's 177-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Apprentice practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Apprentice exam.