Cybersecurity-Apprentice · domain
Security Operations
Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Security Operations
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Operations exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Operations questions (29)
Click any question to see the full explanation, or start a practice session above.
An analyst is writing a complex XQL (XDR Query Language) query in Cortex XDR to find all process executions where a PowerShell script was executed with hidden window styles. Which syntax structure correctly filters datasets for this query?
Hard2A security engineer is setting up Cortex XDR data collection on endpoint hosts. Which THREE telemetry types does the Cortex XDR agent collect to enable advanced behavioral analytics and threat hunting? (Choose three)
Medium3A SOC analyst is reviewing the primary log categories generated by a Palo Alto Networks Next-Generation Firewall. Which TWO log types are natively available in PAN-OS for security monitoring and incident analysis? (Choose two)
Easy4When designing a Security Operations Center (SOC) incident triage workflow, which TWO core principles are fundamental for effective incident management? (Choose two)
Easy5A security engineer is configuring a syslog integration to forward Cortex XDR incidents to a legacy SIEM. Which output format option is standard for ensuring structured, parsable data export in CEF (Common Event Format) or LEEF?
Hard6An administrator is configuring log forwarding on a Palo Alto Networks firewall to send data to an external SIEM. Which THREE destination types are supported natively in PAN-OS Log Forwarding Profiles? (Choose three)
Medium7When performing threat hunting in Cortex XDR using XQL, an analyst needs to identify anomalous execution chains. Which THREE XQL query stages or clauses are valid and commonly used in building investigative queries? (Choose three)
Hard8A security operations team is configuring threat intelligence feeds in Cortex XSIAM. Which THREE indicator types can typically be ingested and correlated against network and endpoint telemetry? (Choose three)
Hard9An organization experiences an alert spike from a misconfigured internal vulnerability scanner mimicking a port scan attack. How can a security analyst suppress or tune this specific alert in Cortex XDR to reduce false positives?
Medium10An administrator is reviewing Cortex XDR investigation tools. Which THREE features are available when investigating an incident in the Cortex XDR Incident View? (Choose three)
Medium11A SOC automation engineer is building a playbook in Cortex XSOAR to handle compromised credentials. Which THREE common integration actions or automations are typically included in such a playbook? (Choose three)
Hard12An analyst is troubleshooting a situation where Cortex XDR agents are failing to report telemetry back to the Cortex XDR server. Which log file on a Windows endpoint should the analyst check to review the communication status of the Cortex XDR agent service?
Hard13A SOC analyst needs to create a custom parsing rule in Cortex XSIAM for incoming custom application logs that do not match standard RFC formats. Which component of Cortex XSIAM should the analyst utilize to map these raw log fields to the Common Schema?
Medium14A tier-1 SOC analyst receives an alert for a blocked malware execution detected by WildFire on a firewall. What is the standard operational response procedure for this type of high-confidence prevention alert?
Easy15A SOC analyst is reviewing real-time firewall traffic in the Application Command Center (ACC). What is the primary purpose of the ACC in a Palo Alto Networks firewall?
Easy16A SOC team utilizes Cortex XSIAM for threat detection and response. When analyzing data ingestion health, which dashboard or section should the engineer examine to verify that log collectors are actively receiving and parsing logs from various data sources without dropping packets?
Hard17During a security investigation, an analyst discovers that a compromised user account is repeatedly authenticating from an impossible travel location. Which Cortex XDR feature enables the analyst to automatically isolate the user's host endpoint upon detection?
Medium18During a routine audit, a SOC supervisor wants to ensure that all administrative logins to Panorama and managed firewalls are centrally tracked and securely archived. Which log type in the PAN-OS logging architecture records administrator login sessions and configuration changes?
Medium19A security analyst needs to verify whether a suspicious file hash uploaded to an internal server was previously analyzed by WildFire. Where can the analyst perform a manual hash lookup in the Palo Alto Networks ecosystem?
Easy20An analyst notices that a specific URL is incorrectly categorized by the Palo Alto Networks URL Filtering database (BrightCloud/PAN-DB). What is the appropriate procedure to request a re-categorization of this URL?
Easy21A SOC engineer is integrating Palo Alto Networks Prisma Cloud alerts into Cortex XSOAR. Which architectural component in Cortex XSOAR is primarily responsible for ingesting these cloud security alerts and triggering automated playbooks?
Hard22Which TWO roles or responsibilities are typically associated with a Tier-1 SOC analyst in a standard security operations structure? (Choose two)
Easy23During a phishing investigation, a SOC analyst receives an email sample containing malicious URLs. Which tool within Cortex XSOAR can be leveraged to automatically extract URLs, perform reputation checks, and block them on the firewall without manual intervention?
Medium24An analyst is investigating an endpoint alert in Cortex XDR and wants to see the chronological timeline of process creation, network connections, and file modifications associated with the malware execution. Which tool provides this granular investigative capability?
Medium25An incident responder is investigating a suspected lateral movement attack where an attacker utilized stolen Kerberos tickets (Pass-the-Ticket). Which log source in Cortex XSIAM or Windows event collection is essential for detecting abnormal Kerberos service ticket requests (Event ID 4769)?
Hard26A security analyst in a Security Operations Center (SOC) notices a sudden influx of endpoint alerts related to a new ransomware strain. Where should the analyst typically begin their initial triage within Cortex XDR to understand the scope and root cause of the incident?
Easy27An administrator is configuring log forwarding from a Palo Alto Networks Next-Generation Firewall to an external SIEM using Syslog. Which menu path on the firewall GUI is used to define the Syslog server profile?
Easy28An incident responder notices malicious traffic originating from an internal workstation communicating with a known Command and Control (C2) IP address. To prevent further communication across the enterprise network, where should the analyst apply a temporary block rule if using Panorama?
Medium29An administrator is configuring log forwarding filters in PAN-OS to reduce the volume of unneeded informational logs sent to an external SIEM. Where are these log forwarding filters defined?
HardOther domains
All Cybersecurity-Apprentice exam domains
Frequently asked questions
- What does the Security Operations domain cover on the Cybersecurity-Apprentice exam?
- Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 29 Security Operations questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.