Courseiva

Certified Security Operations Architect (SecOps-Architect) (SecOps-Architect) — Questions 76150

217 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQmedium

Your security leadership requests a monthly report showing the percentage of security alerts that are automatically remediated by Cortex XSOAR playbooks versus those requiring manual intervention. What is this metric commonly called?

A.Incident Escalation Velocity
B.Automation Rate / Playbook Resolution Percentage
C.Alert Suppression Ratio
D.Mean Time to Ingest
AnswerB

This metric quantifies the success and volume of automated tasks versus manual triage.

Why this answer

Automation Rate or Automation Coverage measures the proportion of security operations tasks handled programmatically by orchestration tools compared to manual analyst effort.

77
Multi-Selecthard

An architect is reviewing Cortex XSIAM dashboards designed to monitor threat detection coverage against the MITRE ATT&CK framework. Which THREE components are critical to measure accurately for this coverage analysis? (Choose three)

Select 3 answers
A.Validation status of detection rules against simulated attacks (e.g., adversary emulation)
B.Physical temperature of the firewall appliance power supplies
C.Percentage of MITRE ATT&CK techniques with active, tested detection rules
D.Identification of telemetry gaps where required log sources are missing
E.Cortex XDR license renewal date
AnswersA, C, D

Testing rules with simulation ensures detection logic actually fires as expected.

Why this answer

MITRE ATT&CK coverage reporting requires measuring technique detection coverage across endpoints/networks, active alert validation for those techniques, and identifying coverage gaps.

78
MCQmedium

You need to establish a baseline for normal network traffic and security events across multiple disparate log sources in Cortex XSIAM. What feature should you leverage to aggregate and normalize this data for consistent metric reporting?

A.WildFire Local Analysis Appliances
B.Cortex XSIAM Parsing Rules and Data Models
C.Cortex XSOAR Email Integration Instances
D.Prisma SASE Traffic Shapers
AnswerB

Parsing rules and data models normalize diverse log formats into standard fields for reliable metric baselining.

Why this answer

Cortex XSIAM uses Parsing Rules (CIM normalization) and Data Models to normalize heterogeneous log data into a consistent schema, enabling accurate cross-source metric reporting.

79
MCQeasy

When planning an incident response table-top exercise for a Security Operations team, which framework provides a standardized taxonomy for describing adversary behaviors and tactics?

A.PCI-DSS v4.0
B.ITIL v4 Service Management
C.ISO/IEC 27001
D.MITRE ATT&CK Framework
AnswerD

MITRE ATT&CK provides standard terminology for adversary techniques.

Why this answer

MITRE ATT&CK provides a comprehensive matrix of adversary tactics and techniques.

80
MCQhard

An architect is establishing security metrics for a multi-tenant Cortex XSIAM environment. Different business units require distinct SLA targets and independent metric baselines. How should the architect configure this separation?

A.Leverage multi-tenancy partitioning, tenant-specific incident types, and scoped dashboard roles to enforce custom SLAs and baselines.
B.Disable data segregation so all business units share a single unified metric baseline.
C.Export all raw logs to local CSV files and calculate metrics manually in spreadsheets.
D.Configure global default SLAs that apply identical thresholds to all business units without modification.
AnswerA

Partitioning and tenant-specific configurations allow customized metrics and SLAs for each business unit.

Why this answer

In multi-tenant or segmented Cortex XSIAM architectures, tenant isolation, distinct RBAC, and separate dashboard/incident configuration rules allow customized SLAs and baselines per business unit.

81
Multi-Selectmedium

An architect is configuring Panorama to manage software and content updates across managed firewalls. Which TWO update deployment workflows are supported by Panorama? (Choose two)

Select 2 answers
A.Using FTP to push Windows desktop OS patches to firewalls.
B.Staged deployment where updates are pushed to test device groups before rolling out to production device groups.
C.Automatically downloading and installing PAN-OS major upgrades on all production firewalls during peak business hours without review.
D.Forcing all firewalls to boot into maintenance mode every 10 minutes.
E.Scheduling dynamic content updates (Antivirus, Applications and Threats) to occur automatically at designated off-peak times.
AnswersB, E

Staged deployments ensure updates are tested on non-production firewalls before enterprise rollout.

Why this answer

Panorama allows scheduling updates, deploying content updates to specific device groups first (staged rollout), and managing PAN-OS software image downloads and installations.

82
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to inspect encrypted TLS traffic passing through the firewall without terminating the SSL session on the firewall itself (e.g., to identify malicious JA3 signatures or SNI without decryption). Which feature should the architect configure?

A.Installing GlobalProtect portal certificates.
B.App-ID inspection of SSL/TLS Server Name Indication (SNI) and certificate attributes during handshake.
C.Formatting logs into raw Syslog CEF.
D.Disabling all security profiles.
AnswerB

App-ID inspects SNI and certificate metadata during the TLS handshake to identify applications without full decryption.

Why this answer

SSH Proxy or SSL Decryption without decryption (using SSL Forward Proxy visibility or inspecting SNI/certificate metadata) allows visibility into encrypted traffic metadata. Specifically, App-ID uses SNI and certificate inspection in TLS handshakes without full decryption.

83
MCQhard

An architect is designing a multi-region threat intelligence sharing architecture using Cortex XSOAR. They need to synchronize indicators across independent regional XSOAR instances without creating circular loops. Which protocol and architecture pattern should be implemented?

A.Direct database replication of the internal SQLite tables
B.TAXII 2.1 Server and Client integration feeds across instances
C.Unencrypted FTP file drops of CSV indicator lists
D.Raw Syslog forwarding of indicator JSON blobs
AnswerB

TAXII 2.1 standardizes federated threat intelligence sharing.

Why this answer

TAXII (Trusted Automated Exchange of Intelligence Information) client-server architecture is standard for federated indicator sharing.

84
Multi-Selecthard

When designing a comprehensive security metrics dashboard in Cortex XSIAM for C-level executives, which THREE categories of metrics should be included to provide a balanced view of security posture? (Choose three)

Select 3 answers
A.Individual firewall rule line numbers and syntax formatting
B.Risk and Vulnerability Exposure Trends
C.Cortex XSOAR playbook Python script syntax errors
D.Security Coverage and Visibility Metrics (e.g., agent coverage)
E.Incident Response Velocity (MTTD / MTTR)
AnswersB, D, E

Risk trends provide executives with a high-level view of enterprise threat exposure.

Why this answer

Executive dashboards require a balance of risk posture, operational efficiency (such as MTTR/MTTD), and coverage/visibility metrics rather than low-level technical granular data.

85
MCQhard

An enterprise security architect is configuring automated threat intelligence sharing between Cortex XSOAR and external ISACs using STIX/TAXII. Which component within Cortex XSOAR is primarily responsible for managing incoming threat indicators, deduplication, and indicator scoring?

A.Cortex XDR Analytics Engine
B.Incident Investigation Canvas
C.Threat Intelligence Management (TIM) module
D.Machine Learning Service Broker
AnswerC

Correct. TIM provides centralized indicator lifecycle management, scoring, and bidirectional sharing.

Why this answer

The Threat Intelligence Management (TIM) module within Cortex XSOAR handles indicator lifecycle management, deduplication, scoring, and propagation to enforcement points.

86
MCQeasy

An architect is designing a Panorama deployment to manage 100 firewalls. To ensure high availability and redundancy for Panorama itself, which deployment architecture should the architect recommend?

A.Panorama HA Active/Active pair with split-brain data routing.
B.Panorama High Availability (HA) Active/Passive pair with state and configuration synchronization.
C.Clustered Kubernetes deployment using raw etcd replication without PAN-OS HA.
D.A single standalone virtual machine backed up by nightly AWS snapshots only.
AnswerB

An Active/Passive Panorama HA pair ensures management continuity if the primary Panorama fails.

Why this answer

Panorama High Availability uses an Active/Passive pair configuration sharing configuration state via sync mechanisms.

87
MCQeasy

During a major security incident, a SOC architect needs to ensure that all evidence collected adheres to chain of custody principles. Which foundational security concept is primarily being enforced?

A.High availability and redundant storage arrays
B.Integrity and non-repudiation of digital evidence
C.Role-based access control permission inheritance
D.Network bandwidth optimization and traffic shaping
AnswerB

Correct. Maintaining evidence integrity and documenting handling ensures it remains legally admissible.

Why this answer

Chain of custody ensures that evidence is collected, handled, analyzed, and preserved in a manner that maintains its integrity and admissibility in legal proceedings.

88
MCQeasy

An architect is designing a Zero Trust Network Access (ZTNA) incident response strategy using Prisma Access. When a compromised user device is detected, which action should the automated response workflow trigger to prevent lateral movement?

A.Purge the corporate DNS root servers
B.Apply a dynamic user group or quarantine security policy to immediately revoke network access
C.Factory reset the physical core switches
D.Reboot all enterprise domain controllers
AnswerB

Correct. Dynamic user groups and policy enforcement in Prisma Access allow immediate isolation of compromised sessions.

Why this answer

Prisma Access allows administrators to dynamically quarantine or restrict access for compromised users or devices by modifying security rules or session states.

89
MCQmedium

You are configuring scheduled metric reports to be emailed weekly to department heads using Cortex XSIAM. Which mechanism should you use to automate the generation and delivery of these reports?

A.Scheduled Reporting and Report Execution settings
B.Panorama Device Group sync commands
C.Cortex XDR Agent Auto-Update policies
D.WildFire API submission scripts
AnswerA

Scheduled reporting features allow automatic compilation and email delivery of metric reports.

Why this answer

Cortex XSIAM and Cortex XSOAR both support scheduled reporting capabilities that compile dashboards and export them via email to specified stakeholders on a recurring basis.

90
MCQmedium

An architect is designing an automated containment workflow in Cortex XSOAR. The requirement is to isolate a compromised endpoint running Cortex XDR agent without disrupting critical domain controllers. Which configuration parameter must be validated in the isolation command?

A.Exclusion lists and targeted device IDs to prevent critical asset isolation
B.PAN-OS external dynamic list expiration timers
C.Global firewall rule bypass codes
D.Syslog forwarding facility levels
AnswerA

Correct. Proper targeting and exclusion verification ensure critical infrastructure remains accessible.

Why this answer

When executing endpoint isolation in Cortex XDR via XSOAR, the architect must ensure exceptions or proper scoping are applied to prevent isolating essential infrastructure like Domain Controllers.

91
Multi-Selectmedium

Which TWO metrics are commonly used to measure the impact and ROI of a Cortex XSOAR implementation in a SOC? (Choose two)

Select 2 answers
A.Total gigabytes of firewall log traffic archived per month
B.WildFire file detonation queue length
C.Number of physical security badge swipes at the SOC entrance
D.Reduction in Mean Time to Resolve (MTTR) for standard incident types
E.Total analyst hours saved through automated playbook execution
AnswersD, E

SOAR accelerates remediation, directly lowering MTTR.

Why this answer

ROI and impact for SOAR are measured by tracking reductions in Mean Time to Resolve (MTTR) and increases in automation rates (hours saved).

92
Multi-Selecthard

An architect is designing an enterprise incident response communication plan. Which THREE components are critical for effective operational coordination during a major security incident? (Choose three)

Select 3 answers
A.Pre-defined stakeholder and legal notification escalation trees
B.Centralized incident war room / ticketing audit trail
C.Secure out-of-band communication channels for incident responders
D.Publicly posting all unredacted forensic disk images on social media
E.Disabling all documentation to maintain total secrecy
AnswersA, B, C

Escalation trees ensure timely reporting to legal, PR, and executive leadership.

Why this answer

Effective operational coordination requires secure communication channels, stakeholder notification trees, and centralized logging.

93
MCQhard

An architect is integrating Palo Alto Networks NGFW with AWS VPC environments using the VM-Series auto-scaling template. When a new VM-Series instance spins up dynamically via AWS Auto Scaling, how does the new firewall register and receive its initial configuration without manual administrative intervention?

A.Through bootstrapping using an S3 bucket containing an init-cfg.txt file, bootstrap folders, and a valid Panorama registration auth-key.
B.By listening for multicast broadcast packets sent by AWS Route 53.
C.By executing an interactive SSH wizard triggered via AWS CloudWatch alarms.
D.By downloading policies from the AWS Systems Manager Parameter Store via raw SNMP.
AnswerA

Bootstrapping automates onboarding by reading configuration, software, and license tokens from an S3 bucket at first boot.

Why this answer

VM-Series bootstrap allows the firewall to load an init-cfg.txt file, bootstrap package, and contact Panorama upon first boot using API keys and Panorama IP settings.

94
MCQeasy

What is the primary benefit of tracking Mean Time to Detect (MTTD) in a Security Operations Center?

A.It calculates the exact financial loss resulting from a data breach.
B.It measures the bandwidth consumption of threat intelligence feeds.
C.It measures how quickly potential security incidents are identified after they occur.
D.It determines the CPU utilization of the Cortex XDR agent.
AnswerC

MTTD quantifies detection latency from the initial point of compromise or log generation to alert generation.

Why this answer

MTTD measures the speed at which the SOC identifies potential security incidents, helping determine the window of exposure before investigation begins.

95
Multi-Selecthard

An architect is designing a secure cloud network architecture using Prisma Access. Which TWO deployment models or components are available in Prisma Access to connect corporate data centers and branch offices? (Choose two)

Select 2 answers
A.Installing Cortex XDR Agent directly onto ISP core routers.
B.Using public FTP servers to bridge internal LAN traffic to the cloud.
C.Remote Networks (connecting branch offices via IPsec VPN tunnels to Prisma Access cloud nodes).
D.Service Connections (connecting corporate headquarters or data centers to Prisma Access for secure hub-and-spoke routing).
E.Direct physical copper coaxial cables spliced from branch offices into the nearest Palo Alto Networks corporate office.
AnswersC, D

Remote Networks is the standard architecture for connecting branch offices to Prisma Access.

Why this answer

Prisma Access connects corporate locations via Remote Networks (IPsec VPN from branch routers/firewalls) and Service Connections (connecting data centers or HQ to Prisma Access via IPsec/BGP).

96
MCQmedium

An architect is designing a Palo Alto Networks VM-Series deployment in Google Cloud Platform (GCP). To enable high availability with automated failover of traffic across multiple VM-Series instances, which GCP networking feature is typically integrated with PAN-OS High Availability?

A.GCP Cloud Storage S3 buckets acting as static routers.
B.Panorama SNMPv1 traps polling GCP virtual disks.
C.Physical serial port cross-connects between GCP server racks.
D.GCP Load Balancers and custom forwarding rules integrated with PAN-OS SDN API calls for route manipulation.
AnswerD

GCP load balancing and SDN API calls allow PAN-OS to dynamically manage GCP routing during failover.

Why this answer

GCP internal and external HTTP(S) / TCP/UDP load balancers combined with GCP Forwarding Rules and PAN-OS SDN API integration handle traffic distribution and failover.

97
MCQmedium

An architect is designing an enterprise deployment of Palo Alto Networks firewalls managed by Panorama. A requirement is that certain firewall configuration changes (such as local interface IP addresses) must remain unique per firewall while security rules remain centrally managed. Which Panorama feature should the architect use?

A.GlobalProtect HIP object criteria.
B.Panorama Pre-Rules with static 'any-any' destinations.
C.Template Variables defined in Panorama templates with unique values assigned per firewall.
D.Global Administrative lockdown mode.
AnswerC

Template variables allow a single template to apply to multiple firewalls while inserting unique values (like IPs) per device.

Why this answer

Template Variables allow defining unique values per firewall while using centralized templates.

98
Multi-Selecthard

An enterprise security architect is reviewing threat detection coverage using the MITRE ATT&CK Navigator. Which THREE strategic objectives can be achieved using this exercise? (Choose three)

Select 3 answers
A.Identifying detection gaps and blind spots across security monitoring tools
B.Mapping existing SIEM/XSIAM analytics rules to specific adversary techniques
C.Prioritizing security telemetry and detection engineering investments
D.Automatically overclocking enterprise workstation CPUs
E.Configuring static IP addresses on firewall interfaces
AnswersA, B, C

Visualizing coverage highlights unmonitored adversary techniques.

Why this answer

MITRE ATT&CK Navigator helps identify detection gaps, prioritize security investments, and map telemetry coverage.

99
Multi-Selectmedium

An architect is designing a Palo Alto Networks High Availability (HA) deployment. Which TWO statements are correct regarding HA state synchronization and failover behavior? (Choose two)

Select 2 answers
A.Active TCP and UDP sessions are synchronized across the HA2 link so sessions persist seamlessly during a failover.
B.The HA2 link requires a dedicated public IP address routable over the public internet.
C.Configuration changes made on the active firewall are automatically synchronized to the passive firewall via the HA1 control link.
D.Failover requires manual intervention via CLI command on the passive unit every time.
E.HA synchronization replaces the need for Panorama configuration management entirely.
AnswersA, C

HA2 session sync ensures active state tables are shared, preventing connection drops during failover.

Why this answer

HA state sync synchronizes active sessions, IPsec security associations, NAT tables, and ARP tables across the HA2 link. Configuration sync is handled via HA1.

100
Multi-Selecthard

An architect is designing an automated incident response architecture integrating Palo Alto Networks NGFW, Cortex XDR, and Cortex XSOAR. Which TWO architectural principles ensure an effective automated security ecosystem? (Choose two)

Select 2 answers
A.Isolating all security tools on completely disconnected local networks without internet or API access.
B.Centralizing threat intelligence sharing and indicator blocking via External Dynamic Lists and XSOAR playbooks.
C.Disabling all automated remediation to ensure zero visibility.
D.Leveraging standardized APIs and integration packs across XSOAR, XDR, and Panorama for seamless orchestration.
E.Relying entirely on manual phone calls and spreadsheets for every security alert.
AnswersB, D

Automating indicator sharing via EDLs and XSOAR ensures fast threat containment across the enterprise.

Why this answer

An effective integrated architecture relies on standardized telemetry sharing (Cortex Data Lake / XDR), API-driven orchestration (XSOAR playbooks), and centralized policy governance (Panorama).

101
MCQmedium

You are configuring log ingestion in Cortex XSIAM from a third-party firewall using a generic syslog collector. The logs are arriving, but the parser is failing to extract destination IP addresses correctly. What is the recommended troubleshooting step?

A.Modify or create a custom XDM parsing rule for the vendor log format
B.Increase the Syslog port number from 514 to 6514
C.Disable Magnifier behavioral analytics
D.Reinstall the Cortex XDR agent on the third-party firewall
AnswerA

Custom parsing rules correct extraction errors for unsupported log formats.

Why this answer

Custom parsing rules in XSIAM can be created or adjusted using XDM mapping tools to correctly parse non-standard log formats.

102
Multi-Selecthard

An architect is designing an automated threat intelligence enrichment pipeline in Cortex XSOAR. Which THREE actions are typically performed during indicator lifecycle management? (Choose three)

Select 3 answers
A.Physically replacing the server motherboard every 90 days
B.Correlating and calculating composite reputation scores across multiple sources
C.Ingesting indicators from structured STIX/TAXII feeds
D.Automatically expiring or aging out stale indicators based on TTL
E.Manually recompiling the Linux kernel for every IOC added
AnswersB, C, D

Reputation scoring merges multi-vendor intelligence into a reliable score.

Why this answer

Indicator lifecycle management involves ingestion, reputation scoring, expiration, and sharing or blocking.

103
MCQhard

An enterprise is designing a zero-trust architecture where Cortex XDR integrates with Palo Alto Networks Next-Generation Firewalls. Which protocol and component facilitate real-time dynamic blocklisting of compromised endpoints across both the firewall and the endpoint?

A.Syslog forwarding from firewalls to the local endpoint agent
B.SNMP traps sent from endpoints to the firewall management plane
C.Cortex XDR incident handler pushing dynamic IP/URL lists to firewalls via PAN-OS API
D.User-ID agent querying Active Directory via LDAP
AnswerC

Cortex XDR integrates with PAN-OS to update dynamic address groups or EDL lists.

Why this answer

The Cortex XDR enforcement service pushes dynamic block lists (EDL / IP lists) via XML API or PAN-OS integration to the firewalls.

104
Multi-Selecthard

An enterprise is establishing a metrics governance framework for Cortex XSOAR automation. Which THREE criteria should be used to determine if a security workflow is a good candidate for automation? (Choose three)

Select 3 answers
A.Requires complex, highly subjective political negotiation between business units
B.Executed exactly once every ten years with unpredictable parameters
C.Well-defined, deterministic decision logic and steps
D.High volume and repetitive execution frequency
E.Reliance on structured data inputs that can be parsed programmatically
AnswersC, D, E

Deterministic workflows are easily translated into programmatic playbooks.

Why this answer

Good automation candidates are repetitive tasks, high-volume processes with structured data, and workflows that follow well-defined, repeatable decision logic without requiring complex subjective human judgment.

105
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to block traffic based on geographic location (e.g., blocking traffic originating from specific countries). Which feature enables this?

A.GeoIP matching in Security Policy rules based on source or destination country tags.
B.Static TCP port filtering rules.
C.GlobalProtect client version checks.
D.DNS root hint server configuration.
AnswerA

GeoIP objects allow creating security rules based on source or destination countries.

Why this answer

GeoIP in Palo Alto Networks security policies allows matching traffic source or destination countries.

106
Multi-Selectmedium

Which TWO metrics are essential when evaluating the effectiveness of a Security Operations Center's (SOC) detection engineering process? (Choose two)

Select 2 answers
A.Cortex XDR agent software license cost per endpoint
B.Total physical weight of server racks in the datacenter
C.Average printer paper consumption in the SOC office
D.False Positive Rate (FPR) of detection rules
E.True Positive Rate (TPR) of detection rules
AnswersD, E

FPR measures alert noise generated by detection rules, guiding engineering tuning efforts.

Why this answer

Detection engineering effectiveness is evaluated by measuring how accurately rules detect threats (True Positive Rate) and how much noise they generate (False Positive Rate).

107
MCQeasy

When designing an operational dashboard in Cortex XSIAM to monitor SOC analyst workload distribution, which metric is most useful?

A.Number of assigned open incidents per analyst
B.WildFire malicious verdict percentage
C.Cortex XDR agent version distribution
D.Total firewall throughput in gigabits per second
AnswerA

Tracking active incident distribution per analyst directly highlights workload and capacity.

Why this answer

Tracking open incidents per analyst or incidents closed per shift helps supervisors identify workload imbalances and burnout risks.

108
MCQhard

Your organization is undergoing an external ISO 27001 audit. The auditors request empirical proof of continuous monitoring effectiveness and incident response responsiveness over the past 12 months. Which Cortex XSIAM / XSOAR artifacts should you present to satisfy this requirement?

A.Aggregated historical SLA compliance reports, MTTD/MTTR trend dashboards, and immutable incident audit logs.
B.A signed letter from the SOC manager stating that the team works very hard.
C.Raw backup files of the firewall configuration database without incident metrics.
D.A list of employee login passwords stored in plaintext.
AnswerA

Historical SLA reports, MTTD/MTTR trends, and audit logs provide concrete proof of continuous monitoring and response capability.

Why this answer

Auditors require historical audit trails, SLA compliance reports, trend graphs of MTTD/MTTR, and immutable incident response logs proving continuous operations and adherence to internal policies.

109
MCQhard

An enterprise security architect is integrating Cortex XSIAM with an external SIEM using the Syslog Export feature. The security team notices that certain sensitive fields need to be redacted before export. Where should the architect configure this transformation?

A.Magnifier machine learning configuration
B.Cortex XDR Agent installation parameters
C.Data Forwarding Rules / Log Forwarding Profiles
D.XSOAR automation playbook script tasks
AnswerC

Log forwarding profiles allow filtering and masking before export.

Why this answer

Log Forwarding profiles in Cortex XSIAM allow filtering, masking, and transforming logs before they are exported via Syslog or HTTP.

110
Multi-Selecthard

An architect is designing an integration between Prisma Access and a third-party SIEM to ingest all security telemetry, traffic logs, and threat logs. Which TWO methods are officially supported for exporting logs from Prisma Access to external SIEMs? (Choose two)

Select 2 answers
A.Use SNMP traps polled every 5 seconds by the SIEM against the Prisma Access public IP.
B.Configure an SSH tunnel directly into the Prisma Access cloud backend hypervisor to pull raw log files.
C.Configure Log Forwarding Profiles within Prisma Access (Panorama managed) to export syslog directly to external SIEM collectors.
D.Install a physical syslog agent on the Prisma Access cloud infrastructure gateway nodes.
E.Configure Cortex Data Lake log forwarding to forward logs to external SIEM endpoints (such as via HTTPS/Syslog).
AnswersC, E

Prisma Access supports direct syslog log forwarding profiles.

Why this answer

Prisma Access supports exporting logs via Syslog from Remote Networks/Mobile Users to an external SIEM, and via Cortex Data Lake (CDLake) log forwarding APIs or forwarders.

111
Multi-Selectmedium

When configuring Cortex XSOAR incident classification and mapping, which TWO elements must be defined for an incoming alert type? (Choose two)

Select 2 answers
A.Field mapping schema between incoming alerts and XSOAR incident fields
B.Physical server CPU core allocation
C.Associated default playbook
D.Endpoint BIOS vendor name
E.Local printer queue ID
AnswersA, C

Field mapping ensures alert data populates the correct incident fields.

Why this answer

Incident types require mapping schemas and associated default playbooks.

112
Multi-Selectmedium

When reporting on SOC operational efficiency using Cortex XSOAR and XSIAM, which TWO metrics measure analyst productivity and throughput? (Choose two)

Select 2 answers
A.Firewall hardware power supply redundancy status
B.Global WildFire malware detection signature version
C.Number of incidents successfully resolved and closed per analyst
D.Average time spent per incident triage phase
E.Cortex XDR agent disk space exclusion list
AnswersC, D

Tracking closed incidents per analyst directly measures operational throughput.

Why this answer

Analyst productivity and throughput are measured by tracking metrics like incidents resolved per analyst and average playbook/task execution speed.

113
Multi-Selectmedium

An architect is designing a Palo Alto Networks SSL Decryption architecture. Which TWO best practices should be implemented to minimize user friction and protect user privacy (e.g., healthcare or financial sites)? (Choose two)

Select 2 answers
A.Decrypt all traffic indiscriminately, including banking and medical portals, without exception.
B.Install a trusted Enterprise Certificate Authority (CA) root certificate onto all managed client endpoints.
C.Use self-signed certificates generated on the firewall without distributing them to endpoints.
D.Disable SSL decryption entirely across all zones.
E.Configure Decryption Exclusions for URL categories containing sensitive data such as Financial Services and Healthcare.
AnswersB, E

Deploying the enterprise root CA prevents browser certificate warnings during forward proxy decryption.

Why this answer

Decryption best practices include creating Decryption Exclusions for sensitive categories (finance, health) and using Forward Trust certificates signed by an internal Enterprise CA.

114
MCQmedium

A security architect is establishing an operational metrics dashboard for executive leadership. Which metric best demonstrates the risk reduction impact of automated security orchestration and response (SOAR) playbooks?

A.Total number of raw logs ingested per second (EPS)
B.Mean Time to Respond (MTTR) / Containment Time
C.Average CPU utilization of the SIEM collector nodes
D.Number of security personnel trained on phishing awareness
AnswerB

Correct. MTTR measures how quickly security operations contain and remediate threats, directly reflecting SOAR value.

Why this answer

Mean Time to Respond (MTTR) or Containment Time directly shows how automation accelerates remediation and reduces organizational exposure time.

115
Multi-Selectmedium

An architect is configuring Cortex XSOAR incident automation. Which TWO core components are fundamental to building an effective XSOAR playbook? (Choose two)

Select 2 answers
A.Panorama Dynamic Address Group tags used as storage databases.
B.Physical firewall interface cards plugged into the XSOAR server PCI slots.
C.Integration instances that execute specific API commands against third-party and Palo Alto Networks tools.
D.Tasks and conditions that determine the logical flow and decision-making branches of the incident response workflow.
E.Direct kernel-level device drivers installed on the XSOAR server operating system.
AnswersC, D

Integration instances provide the execution engine for commands within playbook tasks.

Why this answer

Cortex XSOAR playbooks consist of tasks, integration commands, conditions, scripts, and inputs/outputs to orchestrate incident response workflows.

116
MCQmedium

An architect is configuring User-ID mapping via GlobalProtect. When remote users connect via GlobalProtect, how does the firewall learn the user-to-IP mapping without querying Active Directory domain controllers directly?

A.GlobalProtect stores user mappings inside Cortex XDR cloud databases.
B.GlobalProtect gateway directly registers the authenticated username and assigned tunnel IP with the User-ID subsystem.
C.GlobalProtect relies on DNS reverse-lookup polling every 24 hours.
D.GlobalProtect uses SNMP traps to poll local Wi-Fi routers.
AnswerB

GlobalProtect reports user-to-IP mappings directly to User-ID upon connection.

Why this answer

GlobalProtect portals and gateways natively send user authentication mapping information to the User-ID subsystem upon successful VPN tunnel establishment.

117
Multi-Selecthard

An architect is designing a Prisma Access deployment with multiple Remote Networks. Which TWO routing mechanisms are supported for connecting customer premises equipment (CPE) to Prisma Access Node locations? (Choose two)

Select 2 answers
A.OSPF adjacency established directly across the public internet between branch firewalls and Prisma Access.
B.Static routing configured over IPsec VPN tunnels.
C.Raw Ethernet crossover cables run directly between branch offices and Prisma Access cloud nodes.
D.AppleTalk routing protocol over GRE tunnels.
E.BGP (Border Gateway Protocol) routing over IPsec VPN tunnels.
AnswersB, E

Static routes can be defined in Panorama for Prisma Access remote networks.

Why this answer

Prisma Access supports BGP (Border Gateway Protocol) over IPsec VPN as well as static routing over IPsec VPN to connect customer remote networks.

118
Multi-Selecthard

An architect is designing a high-availability Cortex XDR deployment. Which TWO architectural elements are critical for ensuring reliable agent telemetry delivery and management? (Choose two)

Select 2 answers
A.Configuring SNMPv1 polling on all endpoint loopback interfaces.
B.Deploying Cortex XDR Broker VMs to act as local proxies and event collectors, reducing WAN traffic.
C.Using raw FTP daemons to transfer endpoint RAM dumps across unencrypted networks.
D.Installing physical serial console cables between every workstation and the XDR cloud data center.
E.Ensuring outbound HTTPS (TCP port 443) connectivity from endpoints and Broker VMs to the Cortex XDR cloud tenant.
AnswersB, E

Broker VMs optimize WAN bandwidth and serve as local collectors/proxies.

Why this answer

Cortex XDR architecture relies on Cortex XDR Broker VMs for local log collection and proxying, and reliable outbound HTTPS connectivity from agents to the cloud backend.

119
MCQhard

An architect is configuring automated metric collection in Cortex XSOAR using incident tags and custom fields to measure playbook automation efficiency. Which metric calculation accurately isolates the value added by automation versus manual analyst intervention?

A.Mean Time to Ingest
B.Touchless Resolution Rate (percentage of incidents closed without manual tasks)
C.Playbook Step Execution Count
D.Total Incident Dwell Time
AnswerB

Touchless resolution rate directly measures the effectiveness of automated playbooks versus human effort.

Why this answer

Touchless Resolution Rate measures the percentage of incidents resolved completely without human intervention, isolating automation efficiency.

120
Multi-Selectmedium

An architect is troubleshooting a User-ID deployment where IP-to-username mappings are missing for users on a specific subnet. Which TWO sources or tools can be checked to verify mapping status on the Palo Alto Networks firewall? (Choose two)

Select 2 answers
A.Check the BIOS boot sequence of the firewall management plane.
B.Check the GlobalProtect client GUI for hardware warranty details.
C.Run the CLI command 'show user ip-user-mapping all' on the firewall to view current mappings.
D.Check the User-ID agent status and connection state on the firewall under Device > User Identification.
E.Verify the physical fiber optic cable transceivers on HA2.
AnswersC, D

The CLI command 'show user ip-user-mapping all' displays active IP-to-user mappings on the firewall.

Why this answer

Mappings can be verified on the firewall using CLI commands ('show user ip-user-mapping all' or 'show user group-mapping state') and the Operational Commands or User-ID agent status.

121
MCQmedium

An architect is configuring Palo Alto Networks firewall logging. By default, when are traffic logs generated for allowed sessions?

A.Every 1 millisecond regardless of session state.
B.Only when an administrator manually clicks 'Export Logs'.
C.When the session terminates (closes).
D.Only when the session first initiates.
AnswerC

Traffic logs for allowed connections are written to the log database when the session ends.

Why this answer

Traffic logs for allowed sessions are generated when the session terminates (closes), logging total bytes, packet counts, and duration.

122
MCQhard

An architect is designing an enterprise deployment of Prisma Access and needs to ensure that mobile users authenticate against an external SAML 2.0 Identity Provider before establishing a GlobalProtect connection. Where should the SAML Authentication profile be configured in Panorama?

A.Panorama Template stack interface MTU settings.
B.External Dynamic List URL objects.
C.Firewall Zone Protection profile settings.
D.Panorama Authentication Profile assigned to the GlobalProtect Portal and Gateway configurations.
AnswerD

GlobalProtect Portal and Gateway reference the SAML Authentication Profile to redirect users to the IdP.

Why this answer

In Prisma Access / GlobalProtect architectures, the SAML Authentication profile is configured in Panorama under Authentication profiles and assigned to the GlobalProtect Gateway and Portal configurations.

123
Multi-Selecthard

An architect is designing an automated threat containment workflow using Cortex XSOAR and Palo Alto Networks NGFWs. Which TWO actions can XSOAR automatically execute on the firewall as part of an incident remediation playbook? (Choose two)

Select 2 answers
A.Terminate active user sessions on the firewall using PAN-OS API commands.
B.Downgrade the firewall PAN-OS software version to an unpatched legacy release.
C.Reformat the firewall management plane solid-state drive remotely.
D.Block a compromised IP address or domain by dynamically adding it to a firewall External Dynamic List or Custom Address Group.
E.Physically disconnect the fiber optic patch cables from the firewall data ports via remote robotic arm control.
AnswersA, D

XSOAR can terminate active sessions matching specific criteria via the PAN-OS API.

Why this answer

Cortex XSOAR integrations with PAN-OS / Panorama can block IP addresses/domains by adding them to external dynamic lists or custom address objects, and terminate active user sessions.

124
MCQeasy

Which framework is widely recognized as a comprehensive guideline for establishing a foundational cybersecurity program through five core functions: Identify, Protect, Detect, Respond, and Recover?

A.CIS Critical Security Controls
B.NIST Cybersecurity Framework (CSF)
C.ISO/IEC 27017
D.MITRE D3FEND
AnswerB

NIST CSF uses the Identify, Protect, Detect, Respond, and Recover functions.

Why this answer

The NIST Cybersecurity Framework (CSF) is structured around these five core functions.

125
MCQeasy

When aligning a security operations center (SOC) with the NIST Incident Response lifecycle, which phase immediately follows 'Containment, Eradication, and Recovery'?

A.Vulnerability Assessment
B.Triage and Scoping
C.Post-Incident Activity (Lessons Learned)
D.Threat Hunting
AnswerC

Lessons learned is the final phase of the NIST IR lifecycle.

Why this answer

The NIST SP 800-61 lifecycle phases are Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity (Lessons Learned).

126
MCQhard

An architect is configuring Panorama to push configuration updates to managed firewalls using Panorama Templates and Template Stacks. A specific setting needs to be overridden at an individual firewall level without altering the template stack hierarchy. Which Panorama feature enables this capability?

A.Template Variables assigned specific values per managed firewall.
B.Panorama WildCard objects
C.Device-level CLI overrides via administrative lockdown mode.
D.Global Object Override rules
AnswerA

Template variables allow dynamic substitution of IP addresses, gateways, and other settings per firewall while using a common template.

Why this answer

Panorama Template Variables allow administrators to define variable values per firewall while keeping the underlying template structure uniform.

127
MCQmedium

An architect is configuring User-ID mapping using the Palo Alto Networks Windows-based User-ID Agent. To ensure high availability and prevent single points of failure, how should multiple User-ID agents be configured in Panorama or the firewall?

A.Deploy agents on every user workstation without domain controllers.
B.Merge all agents into a single physical process via CLI kernel patching.
C.Configure multiple User-ID agents in a server list where the firewall queries secondary agents if the primary agent becomes unreachable.
D.Rely solely on static IP address lists.
AnswerC

Configuring multiple User-ID agents provides redundancy and failover for user mapping queries.

Why this answer

Panorama and firewalls allow configuring multiple User-ID agents in a priority-ordered list or server monitor group so if one agent fails, another takes over.

128
MCQmedium

An architect is designing a multi-tenant Prisma Access architecture. Different business units require separate address spaces, security policies, and administrative boundaries. Which Prisma Access feature enables this logical separation?

A.Panorama Device Groups and Folders with role-based access control (RBAC).
B.Cortex XDR agent exclusion lists.
C.Physical stacking cables linking remote branch routers.
D.GlobalProtect client-side registry keys.
AnswerA

Folders and device groups combined with RBAC provide logical multi-tenancy in Prisma Access.

Why this answer

Prisma Access uses folder structures, device groups, and Panorama multi-tenancy constructs (such as multi-tenant Panorama deployment or distinct Prisma Access folders in Panorama) to logically segment business units.

129
MCQeasy

An architect is configuring User-ID to map users via Palo Alto Networks Terminal Services (TS) Agent. Where must the TS Agent be installed in the network architecture?

A.Directly on the Microsoft Terminal Server or Citrix XenApp server.
B.Inside the Cortex XDR Broker VM appliance.
C.On the external DNS root server.
D.On the Panorama management virtual appliance.
AnswerA

TS agent runs on the terminal server to map user sessions sharing the same server IP to unique source ports.

Why this answer

The TS Agent must be installed directly on the Microsoft Terminal Server or Citrix XenApp server to track which user is mapped to which TCP port range.

130
Multi-Selecthard

When designing an automated metric reporting pipeline from Cortex XSIAM to an external SIEM or data warehouse using APIs, which THREE architectural considerations must be addressed? (Choose three)

Select 3 answers
A.Monitor screen resolution settings of the analyst workstations
B.API rate limits and pagination handling to prevent data loss during extraction
C.Data volume bandwidth planning to avoid network saturation during peak hours
D.Secure authentication token management and encryption in transit (TLS)
E.Physical cable length between the client desktop and the office printer
AnswersB, C, D

API rate limits dictate query batch sizes and require robust pagination logic.

Why this answer

External API integrations require managing API rate limits, ensuring secure authentication/encryption in transit, and handling data volume/bandwidth throttling.

131
MCQeasy

An architect is configuring log ingestion for Cortex XSIAM. Which native Palo Alto Networks collector type is designed to gather syslog and CEF formatted logs from third-party security devices without requiring an external forwarder VM?

A.Cortex XSIAM Broker VM
B.AutoFocus Cloud API connector
C.Panorama Management Server direct API
D.GlobalProtect Gateway agent
AnswerA

Correct. The Broker VM is deployed on-premises or in the cloud to collect and forward syslog, CEF, and other data sources to XSIAM.

Why this answer

Cortex XSIAM supports Cloud Identity Engine and Broker VM architectures, where the Broker VM acts as a local collector for syslog, SNMP, and other third-party formats.

132
MCQhard

An architect is designing an enterprise incident response workflow in Cortex XSOAR. When a phishing email is reported, the playbook needs to parse the email headers, extract attachments, submit them to WildFire, and notify the security team via Slack. Which component in Cortex XSOAR is responsible for receiving the incoming phishing email and triggering the playbook?

A.Prisma Access Remote Network IPsec tunnel.
B.GlobalProtect client certificate authority.
C.Email integration instance (such as Email Server or EWS) with incident classification and mapping.
D.Panorama SNMP trap listener.
AnswerC

Email integrations ingest incoming emails, create incidents, and trigger playbooks automatically.

Why this answer

Incoming email integration instances (such as Email Parsing / EWS / Gmail integrations) ingest emails and trigger associated playbooks based on classifier mapping.

133
Multi-Selecthard

An architect is designing a Prisma Cloud Compute deployment for cloud-native applications. Which TWO security scanning and monitoring capabilities are provided by Prisma Cloud Compute? (Choose two)

Select 2 answers
A.Physically rewiring enterprise data center power distribution units.
B.Vulnerability scanning for container images, serverless functions, and virtual machine hosts.
C.Runtime defense monitoring container processes, network connections, and file system modifications for anomalies.
D.Hosting public website domains on Prisma Cloud Defender node storage.
E.Printing physical compliance paper certificates on office laser printers.
AnswersB, C

Prisma Cloud Compute scans container images, serverless functions, and VMs for known CVEs.

Why this answer

Prisma Cloud Compute provides vulnerability scanning for container images, serverless functions, and host VMs, plus runtime defense and compliance checks.

134
Multi-Selecthard

An architect is designing a Prisma Cloud Compute deployment for Kubernetes clusters. Which TWO architectural components must be considered when planning Defender deployments for security monitoring? (Choose two)

Select 2 answers
A.Configuring GlobalProtect gateway tunnels inside every container container root filesystem.
B.Physically soldering Defender chips onto the motherboard of the Kubernetes master node.
C.Installing SNMPv1 agents on all container loopback interfaces.
D.Deploying Defender as a Kubernetes DaemonSet to monitor all pods and container runtimes on every worker node.
E.Ensuring Defenders have network connectivity to the Prisma Cloud Console for policy synchronization and reporting.
AnswersD, E

DaemonSet deployment ensures every node runs a Defender instance protecting local containers.

Why this answer

Prisma Cloud Compute Defenders can be deployed as DaemonSets on Kubernetes nodes or as serverless/App-Embedded defenders depending on the architecture.

135
Multi-Selectmedium

Which TWO practices ensure that security metric reports generated from Cortex XSIAM remain meaningful and actionable over time? (Choose two)

Select 2 answers
A.Assigning clear accountability and ownership for actioning insights generated by the reports
B.Eliminating all historical trend data every 24 hours
C.Regularly reviewing and tuning metric thresholds to align with organizational growth and evolving threat landscapes
D.Restricting dashboard access solely to external auditors
E.Archiving all metric reports into unreadable binary formats with no search capability
AnswersA, C

Metrics are only valuable if someone is accountable for investigating and acting on the findings.

Why this answer

Meaningful reporting requires regular review and tuning of metric thresholds to match organizational growth, and establishing clear ownership for actioning insights derived from the reports.

136
Multi-Selecthard

An enterprise security architect is configuring Cortex XSIAM data ingestion and analytics. Which THREE data sources are essential for comprehensive endpoint and cloud threat detection? (Choose three)

Select 3 answers
A.Endpoint EDR telemetry (process execution, file modifications, network connections)
B.Local calculator application cache files
C.Cloud provider audit logs (AWS CloudTrail, Azure Activity Logs)
D.Local printer driver configuration backups
E.Network traffic flow logs and firewall security logs
AnswersA, C, E

Endpoint telemetry is core to XSIAM and XDR detection capabilities.

Why this answer

Comprehensive detection in XSIAM relies on endpoint telemetry, cloud audit logs, and network traffic data.

137
MCQhard

An organization wants to implement the MITRE ATT&CK framework into their threat detection engineering lifecycle within Cortex XSIAM. Which specific feature enables architects to map incoming telemetry and custom correlation rules directly to ATT&CK tactics and techniques to measure coverage?

A.ATT&CK Coverage Dashboard and Analytics Mapping
B.Panorama Dynamic Address Groups
C.AutoFocus Tagging Engine
D.Traps Agent Policy Editor
AnswerA

Correct. The ATT&CK Coverage dashboard in XSIAM provides direct visibility into technique mapping and detection gaps.

Why this answer

Cortex XSIAM includes a built-in MITRE ATT&CK matrix view that automatically maps triggered alerts and analytics rules to tactics and techniques to track coverage.

138
MCQmedium

In a multi-tenant Cortex XSOAR deployment, an architect needs to restrict access to specific playbooks so that Tenant A analysts cannot view or execute playbooks owned by Tenant B. Where is this access control configured?

A.Global Server Configuration settings
B.Role-Based Access Control (RBAC) settings under Settings > Common > Roles
C.Playbook JSON source code permissions
D.Integration instance parameters
AnswerB

RBAC allows granular control over what objects a role can access.

Why this answer

Role-Based Access Control (RBAC) in Cortex XSOAR allows restricting playbook and incident type visibility based on assigned roles.

139
MCQhard

An architect is designing an automated threat containment architecture using Cortex XSOAR and Prisma Cloud. When Prisma Cloud detects a critical misconfiguration or malware in a running container workload, it triggers a webhook to Cortex XSOAR. What mechanism does XSOAR use to parse the webhook payload and initiate the incident response playbook?

A.Panorama SNMP trap listener daemon.
B.GlobalProtect HIP notification profile.
C.Prisma Access Remote Network IPsec profile.
D.Webhook integration instance with incoming mapper and classifier configuration.
AnswerD

Webhook integrations parse incoming JSON payloads, classify the alert, and trigger corresponding playbooks.

Why this answer

Cortex XSOAR uses Webhook integrations with classifier and mapper configurations to ingest incoming JSON payloads from tools like Prisma Cloud and map them to incident fields.

140
Multi-Selecthard

An architect is designing a threat detection architecture using Cortex XSIAM analytics. Which THREE types of data sources are critical to ingest to provide comprehensive visibility for detecting lateral movement and credential dumping? (Choose three)

Select 3 answers
A.Active Directory / Authentication logs (e.g., Windows Security Event logs for Kerberos/NTLM)
B.Network traffic flow logs (e.g., PAN-OS Traffic and Threat logs)
C.Endpoint process execution and OS telemetry (e.g., Cortex XDR agent logs)
D.HVAC temperature and humidity sensor telemetry
E.Cafeteria POS terminal receipt printer error logs
AnswersA, B, C

Correct. AD logs reveal pass-the-hash, abnormal authentication spikes, and lateral movement.

Why this answer

Detecting lateral movement and credential dumping requires endpoint telemetry (process execution, LSASS access), authentication logs (Active Directory/Kerberos), and network flow/connection logs.

141
MCQeasy

An organization wants to define a Key Performance Indicator (KPI) in Cortex XSOAR that measures the average time taken by an analyst to acknowledge an incoming high-severity incident. Which metric category best captures this measurement?

A.Mean Time to Acknowledge (MTTA)
B.False Positive Rate (FPR)
C.Mean Time to Resolution (MTTR)
D.Mean Time to Contain (MTTC)
AnswerA

MTTA directly captures the time elapsed from incident ingestion to the start of analyst handling.

Why this answer

Mean Time to Acknowledge (MTTA) is a core incident response metric measuring the latency between incident creation and the first human interaction or acknowledgment, reflecting triage efficiency.

142
Multi-Selecthard

An architect is designing a zero-trust network architecture using Prisma Access and Cortex XDR. Which TWO architectural integrations between Prisma Access and Cortex XDR enhance end-to-end visibility and threat detection? (Choose two)

Select 2 answers
A.Replacing all GlobalProtect clients with raw FTP daemons.
B.Configuring Cortex XDR analytics to ingest Prisma Access connection logs to detect anomalous remote user behavior.
C.Using SNMPv1 polling to read Prisma Access RAM from client web browsers.
D.Forwarding Prisma Access traffic, threat, and traffic logs to Cortex Data Lake so Cortex XDR can analyze network events alongside endpoint telemetry.
E.Installing physical firewall ASICs directly onto laptop motherboards via USB.
AnswersB, D

XDR analytics leverage Prisma Access network logs to detect unusual traffic patterns and lateral movement.

Why this answer

Prisma Access forwards traffic and threat logs to Cortex Data Lake / Cortex XDR, enabling XDR to analyze both endpoint and network telemetry across remote users.

143
Multi-Selecthard

An architect is tasked with creating a comprehensive reporting framework in Cortex XSOAR to measure incident response maturity. Which TWO advanced metrics should be incorporated to evaluate the depth and effectiveness of post-incident analysis and containment? (Choose two)

Select 2 answers
A.Containment Effectiveness (percentage of incidents without reinfection or recurrence)
B.Total disk space consumed by log archives
C.Root Cause Identification Time (Mean Time to Identify origin)
D.Number of software licenses assigned to SOC analysts
E.Total number of coffee breaks taken per shift
AnswersA, C

Measures whether containment actions were thorough enough to prevent recurring threats.

Why this answer

Containment Effectiveness and Root Cause Identification Time evaluate the qualitative depth and thoroughness of incident response handling beyond basic speed metrics.

144
Multi-Selectmedium

An architect is designing an incident response automation strategy in Cortex XSOAR. Which TWO best practices should be followed when developing custom playbooks? (Choose two)

Select 2 answers
A.Implement robust error handling and conditional branching for integration failures
B.Execute all integration commands synchronously in a single monolithic task block
C.Hardcode API credentials directly inside Python script tasks for fast execution
D.Design modular sub-playbooks to handle repetitive sub-tasks and promote reusability
E.Disable incident context output to save database storage space
AnswersA, D

Error handling prevents playbooks from crashing when external APIs fail.

Why this answer

Playbooks should include proper error handling and modular sub-playbooks to maintain scalability and robustness.

145
MCQhard

An organization is defining metrics to measure the efficacy of its threat hunting program inside Cortex XSIAM. Which metric provides the strongest indicator of a mature and successful proactive hunting capability?

A.Total number of log queries executed by hunters per day
B.Total storage consumed by threat hunting analytical models
C.Percentage of routine Tier 1 alert triage handled by scripts
D.Number of high-fidelity threats discovered through proactive hunting that convert into new detection rules
AnswerD

Converting proactive finds into automated detection rules demonstrates continuous improvement and risk reduction.

Why this answer

A mature threat hunting program is measured by the number of unique, previously undetected threats uncovered through hypothesis-driven hunting that subsequently result in new automated detection rules.

146
MCQmedium

An enterprise architect is planning a Zero Trust Network Access (ZTNA) migration using Prisma Access. The design must ensure that users are continuously authenticated and authorized before accessing internal applications, regardless of their location. Which component validates user posture and device compliance before granting access?

A.Panorama SNMP trap listener
B.Prisma Cloud Defender host sensor scanning network cables
C.GlobalProtect app performing HIP (Host Information Profile) checks evaluated by Prisma Access.
D.The local DHCP server on the user's home network
AnswerC

HIP checks gather endpoint security posture data (patches, antivirus status) and evaluate it against Prisma Access policy.

Why this answer

Prisma Access integrates with GlobalProtect and Posture Assessment (or third-party MDM/EMM integration) to verify device compliance before granting access.

147
MCQhard

An architect is designing a multi-tenant cloud security architecture using Prisma Cloud. The security team needs to ensure that developers receive security alerts directly inside their collaboration tools (such as Slack or Microsoft Webex) the moment a misconfiguration is detected in infrastructure-as-code or runtime. Which Prisma Cloud feature must the architect configure?

A.GlobalProtect VPN portal banner announcements.
B.Cortex XSOAR email ingestion parsers without alert rules.
C.Panorama SNMP trap forwarding to Slack.
D.Alert Rules combined with notification integrations for Slack and Webhooks.
AnswerD

Alert rules specify when and where notifications are sent, integrating with collaboration platforms via webhooks.

Why this answer

Prisma Cloud Alert Rules allow configuring integrations with Webhooks, Slack, Microsoft Teams, and SIEMs to push real-time alerts.

148
MCQhard

An architect is designing an enterprise incident response workflow using Cortex XSOAR. When a malware alert is triggered in Cortex XDR, XSOAR needs to automatically enrich the alert by querying VirusTotal, checking Active Directory for user details, and isolating the host if malicious. What is this orchestration framework called in Cortex XSOAR?

A.Playbook
B.GlobalProtect HIP Notification object
C.Prisma Access Remote Network profile
D.Panorama Device Group Policy Template
AnswerA

Playbooks orchestrate automated workflows, integrating multiple tools for enrichment and remediation.

Why this answer

Playbooks are the core automation workflows in Cortex XSOAR that chain together integration commands, conditions, and human approval steps.

149
Multi-Selectmedium

An architect is configuring Panorama to manage software and content updates. Which TWO update types can be scheduled and distributed via Panorama to managed firewalls? (Choose two)

Select 2 answers
A.Applications and Threats content updates.
B.Local client browser operating system updates.
C.AWS EC2 instance hypervisor patches.
D.Active Directory domain controller schema updates.
E.Antivirus and WildFire signature updates.
AnswersA, E

Panorama can download and distribute Applications and Threats updates to managed firewalls.

Why this answer

Panorama manages dynamic content updates such as Antivirus, WildFire signatures, Applications and Threats, and PAN-OS software images.

150
MCQmedium

You are designing executive dashboards in Cortex XSIAM to report security posture trends over the last quarter. Management requires a metric that shows the reduction in successful phishing compromises resulting from user training. Which metric should you implement?

A.Average Analyst Playbook Execution Time
B.Cortex XDR Agent Installation Percentage
C.Phishing Incident Recurrence and Successful Compromise Rate Trend
D.Total Phishing Payload Extraction Volume
AnswerC

Tracking the trend of successful compromises over time accurately measures the impact of user awareness and email security controls.

Why this answer

Trend analysis for security posture reporting requires tracking specific risk reduction vectors, such as the volume of successfully blocked or mitigated phishing campaigns over time, correlating training effectiveness to actual incident outcomes.

Page 1

Page 2 of 3

Page 3

All pages