Courseiva

SecOps-Architect Practice Question: Secops Frameworks And Threat Response Architecture

An architect is designing a threat detection architecture using Cortex XSIAM analytics. Which THREE types of data sources are critical to ingest to provide comprehensive visibility for detecting lateral movement and credential dumping? (Choose three)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Active Directory / Authentication logs (e.g., Windows Security Event logs for Kerberos/NTLM)

Detecting lateral movement and credential dumping requires endpoint telemetry (process execution, LSASS access), authentication logs (Active Directory/Kerberos), and network flow/connection logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Active Directory / Authentication logs (e.g., Windows Security Event logs for Kerberos/NTLM)

    Why this is correct

    Correct. AD logs reveal pass-the-hash, abnormal authentication spikes, and lateral movement.

  • Network traffic flow logs (e.g., PAN-OS Traffic and Threat logs)

    Why this is correct

    Correct. Network logs identify abnormal internal-to-internal connection attempts and C2 traffic.

  • Endpoint process execution and OS telemetry (e.g., Cortex XDR agent logs)

    Why this is correct

    Correct. Endpoint telemetry detects local credential dumping tools (like Mimikatz) and suspicious process spawning.

  • HVAC temperature and humidity sensor telemetry

    Why it's wrong here

    Incorrect. Environmental telemetry is unrelated to enterprise network lateral movement.

  • Cafeteria POS terminal receipt printer error logs

    Why it's wrong here

    Incorrect. Receipt printer logs provide no security value for detecting lateral movement.

About these practice questions

This SecOps-Architect question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This SecOps-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SecOps-Architect exam.