Courseiva

Cybersecurity-Apprentice · domain

Security Operations

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

29 questions9 easy10 medium10 hard

Focused practice

Practice Security Operations questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Security Operations

Security Operations questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Operations exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Operations questions (29)

Click any question to see the full explanation, or start a practice session above.

1

An analyst is writing a complex XQL (XDR Query Language) query in Cortex XDR to find all process executions where a PowerShell script was executed with hidden window styles. Which syntax structure correctly filters datasets for this query?

Hard
2

A security engineer is setting up Cortex XDR data collection on endpoint hosts. Which THREE telemetry types does the Cortex XDR agent collect to enable advanced behavioral analytics and threat hunting? (Choose three)

Medium
3

A SOC analyst is reviewing the primary log categories generated by a Palo Alto Networks Next-Generation Firewall. Which TWO log types are natively available in PAN-OS for security monitoring and incident analysis? (Choose two)

Easy
4

When designing a Security Operations Center (SOC) incident triage workflow, which TWO core principles are fundamental for effective incident management? (Choose two)

Easy
5

A security engineer is configuring a syslog integration to forward Cortex XDR incidents to a legacy SIEM. Which output format option is standard for ensuring structured, parsable data export in CEF (Common Event Format) or LEEF?

Hard
6

An administrator is configuring log forwarding on a Palo Alto Networks firewall to send data to an external SIEM. Which THREE destination types are supported natively in PAN-OS Log Forwarding Profiles? (Choose three)

Medium
7

When performing threat hunting in Cortex XDR using XQL, an analyst needs to identify anomalous execution chains. Which THREE XQL query stages or clauses are valid and commonly used in building investigative queries? (Choose three)

Hard
8

A security operations team is configuring threat intelligence feeds in Cortex XSIAM. Which THREE indicator types can typically be ingested and correlated against network and endpoint telemetry? (Choose three)

Hard
9

An organization experiences an alert spike from a misconfigured internal vulnerability scanner mimicking a port scan attack. How can a security analyst suppress or tune this specific alert in Cortex XDR to reduce false positives?

Medium
10

An administrator is reviewing Cortex XDR investigation tools. Which THREE features are available when investigating an incident in the Cortex XDR Incident View? (Choose three)

Medium
11

A SOC automation engineer is building a playbook in Cortex XSOAR to handle compromised credentials. Which THREE common integration actions or automations are typically included in such a playbook? (Choose three)

Hard
12

An analyst is troubleshooting a situation where Cortex XDR agents are failing to report telemetry back to the Cortex XDR server. Which log file on a Windows endpoint should the analyst check to review the communication status of the Cortex XDR agent service?

Hard
13

A SOC analyst needs to create a custom parsing rule in Cortex XSIAM for incoming custom application logs that do not match standard RFC formats. Which component of Cortex XSIAM should the analyst utilize to map these raw log fields to the Common Schema?

Medium
14

A tier-1 SOC analyst receives an alert for a blocked malware execution detected by WildFire on a firewall. What is the standard operational response procedure for this type of high-confidence prevention alert?

Easy
15

A SOC analyst is reviewing real-time firewall traffic in the Application Command Center (ACC). What is the primary purpose of the ACC in a Palo Alto Networks firewall?

Easy
16

A SOC team utilizes Cortex XSIAM for threat detection and response. When analyzing data ingestion health, which dashboard or section should the engineer examine to verify that log collectors are actively receiving and parsing logs from various data sources without dropping packets?

Hard
17

During a security investigation, an analyst discovers that a compromised user account is repeatedly authenticating from an impossible travel location. Which Cortex XDR feature enables the analyst to automatically isolate the user's host endpoint upon detection?

Medium
18

During a routine audit, a SOC supervisor wants to ensure that all administrative logins to Panorama and managed firewalls are centrally tracked and securely archived. Which log type in the PAN-OS logging architecture records administrator login sessions and configuration changes?

Medium
19

A security analyst needs to verify whether a suspicious file hash uploaded to an internal server was previously analyzed by WildFire. Where can the analyst perform a manual hash lookup in the Palo Alto Networks ecosystem?

Easy
20

An analyst notices that a specific URL is incorrectly categorized by the Palo Alto Networks URL Filtering database (BrightCloud/PAN-DB). What is the appropriate procedure to request a re-categorization of this URL?

Easy
21

A SOC engineer is integrating Palo Alto Networks Prisma Cloud alerts into Cortex XSOAR. Which architectural component in Cortex XSOAR is primarily responsible for ingesting these cloud security alerts and triggering automated playbooks?

Hard
22

Which TWO roles or responsibilities are typically associated with a Tier-1 SOC analyst in a standard security operations structure? (Choose two)

Easy
23

During a phishing investigation, a SOC analyst receives an email sample containing malicious URLs. Which tool within Cortex XSOAR can be leveraged to automatically extract URLs, perform reputation checks, and block them on the firewall without manual intervention?

Medium
24

An analyst is investigating an endpoint alert in Cortex XDR and wants to see the chronological timeline of process creation, network connections, and file modifications associated with the malware execution. Which tool provides this granular investigative capability?

Medium
25

An incident responder is investigating a suspected lateral movement attack where an attacker utilized stolen Kerberos tickets (Pass-the-Ticket). Which log source in Cortex XSIAM or Windows event collection is essential for detecting abnormal Kerberos service ticket requests (Event ID 4769)?

Hard
26

A security analyst in a Security Operations Center (SOC) notices a sudden influx of endpoint alerts related to a new ransomware strain. Where should the analyst typically begin their initial triage within Cortex XDR to understand the scope and root cause of the incident?

Easy
27

An administrator is configuring log forwarding from a Palo Alto Networks Next-Generation Firewall to an external SIEM using Syslog. Which menu path on the firewall GUI is used to define the Syslog server profile?

Easy
28

An incident responder notices malicious traffic originating from an internal workstation communicating with a known Command and Control (C2) IP address. To prevent further communication across the enterprise network, where should the analyst apply a temporary block rule if using Panorama?

Medium
29

An administrator is configuring log forwarding filters in PAN-OS to reduce the volume of unneeded informational logs sent to an external SIEM. Where are these log forwarding filters defined?

Hard

Frequently asked questions

What does the Security Operations domain cover on the Cybersecurity-Apprentice exam?
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 29 Security Operations questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cybersec-apprentice PANW-CYBERSEC-APPRENTICE security operations Practice Questions