SecOps-Architect Practice Question: Secops Frameworks And Threat Response Architecture
An architect is designing a threat detection architecture using Cortex XSIAM analytics. Which THREE types of data sources are critical to ingest to provide comprehensive visibility for detecting lateral movement and credential dumping? (Choose three)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Active Directory / Authentication logs (e.g., Windows Security Event logs for Kerberos/NTLM)
Detecting lateral movement and credential dumping requires endpoint telemetry (process execution, LSASS access), authentication logs (Active Directory/Kerberos), and network flow/connection logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Active Directory / Authentication logs (e.g., Windows Security Event logs for Kerberos/NTLM)
Why this is correct
Correct. AD logs reveal pass-the-hash, abnormal authentication spikes, and lateral movement.
- ✓
Network traffic flow logs (e.g., PAN-OS Traffic and Threat logs)
Why this is correct
Correct. Network logs identify abnormal internal-to-internal connection attempts and C2 traffic.
- ✓
Endpoint process execution and OS telemetry (e.g., Cortex XDR agent logs)
Why this is correct
Correct. Endpoint telemetry detects local credential dumping tools (like Mimikatz) and suspicious process spawning.
- ✗
HVAC temperature and humidity sensor telemetry
Why it's wrong here
Incorrect. Environmental telemetry is unrelated to enterprise network lateral movement.
- ✗
Cafeteria POS terminal receipt printer error logs
Why it's wrong here
Incorrect. Receipt printer logs provide no security value for detecting lateral movement.
About these practice questions
This SecOps-Architect question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This SecOps-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SecOps-Architect exam.