SecOps-Pro Cortex XDR Practice Question
You are creating a custom BIOC rule to detect suspicious PowerShell execution. The rule must trigger when PowerShell is executed with an encoded command. Which field should you focus on in the rule builder?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
actor_process_command_line
The command line arguments contain the encoded script block, which is essential for detecting obfuscated PowerShell activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
file_hash
Why it's wrong here
The file hash does not change based on the command line arguments provided.
- ✗
target_process_path
Why it's wrong here
This refers to the process being targeted, not the source of the execution.
- ✗
process_name
Why it's wrong here
This only identifies the executable, not the arguments used.
- ✓
actor_process_command_line
Why this is correct
This field contains the full command line arguments, including the encoded script.
About these practice questions
One of 205 original SecOps-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This SecOps-Pro practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SecOps-Pro exam.