Courseiva

Cybersecurity-Practitioner · domain

SOC Operations

Practise Certified Cybersecurity Practitioner (Cybersecurity-Practitioner) SOC Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

46 questions11 easy18 medium17 hard

Focused practice

Practice SOC Operations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about SOC Operations

SOC Operations questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common SOC Operations exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All SOC Operations questions (46)

Click any question to see the full explanation, or start a practice session above.

1

An incident response team is analyzing an Advanced Persistent Threat (APT) group that has successfully infiltrated a corporate network. Which THREE characteristics are typically associated with APT campaigns compared to opportunistic malware? (Choose three)

Hard
2

An organization is deploying an explicit Zero Trust micro-segmentation strategy using Palo Alto Networks Next-Generation Firewalls. They want to ensure that if a workstation is compromised in the engineering VLAN, lateral movement to the financial VLAN is blocked, even if both belong to internal corporate subnets. Which firewall feature must be configured to achieve this?

Hard
3

An organization is building a Zero Trust Architecture and deploying Palo Alto Networks Next-Generation Firewalls to enforce micro-segmentation. Which THREE design elements are essential for a successful Zero Trust segmentation deployment? (Choose three)

Hard
4

When mapping adversary behaviors to the MITRE ATT&CK framework within a Cortex XDR incident investigation, an analyst identifies techniques associated with the 'Credential Access' tactic. Which TWO techniques fall under the Credential Access tactic category? (Choose two)

Hard
5

A security analyst is investigating an alert in Palo Alto Networks Cortex XDR where an attacker successfully dumped LSASS memory to harvest credentials. According to the MITRE ATT&CK framework, under which Tactic should this technique be cataloged?

Medium
6

A security analyst is investigating an unauthorized modification of user permissions in a Palo Alto Networks Prisma Access environment. When evaluating the breach under the MITRE ATT&CK framework, which specific Tactic best categorizes the attacker's actions to establish higher-level access?

Easy
7

A security analyst is provisioning a new User-ID agent to map IP addresses to usernames in a Windows Active Directory domain. To adhere to least-privilege principles, what level of access should be granted to the service account used by the User-ID agent?

Easy
8

A security architect is designing a Zero Trust network segmentation model using Palo Alto Networks Next-Generation Firewalls. To prevent lateral movement of malware across internal VLANs, which operational rule must be strictly enforced?

Medium
9

An organization is implementing a Zero Trust Architecture on their Palo Alto Networks Next-Generation Firewall. They want to ensure that access to internal financial databases is granted based on explicit verification of user identity, device health, and application context, rather than implicit trust based on network location. Which core principle of Zero Trust is being applied?

Medium
10

During a threat hunting exercise on a Palo Alto Networks firewall, an analyst identifies an adversary scanning internal subnets to map out open ports and active hosts prior to launching an exploit. According to MITRE ATT&CK, which Tactic describes this phase?

Medium
11

An administrator wants to configure User-ID mapping sources on a Palo Alto Networks Next-Generation Firewall to identify users behind IP addresses. Which TWO of the following are valid methods supported by PAN-OS for gathering User-ID mappings? (Choose two)

Medium
12

An administrator wants to configure authentication for firewall administrators using RADIUS. Where in the Panorama Web Interface should the administrator configure the RADIUS server profile?

Easy
13

An incident responder notices that a threat actor used living-off-the-land binaries (like PowerShell and Certutil) to download malicious payloads onto endpoints monitored by Cortex XDR. Under the MITRE ATT&CK framework, which Tactic encompasses these execution methods?

Medium
14

An organization implementing a Zero Trust Architecture wants to ensure that administrators accessing Panorama use hardware-backed cryptographic tokens (such as FIDO2 / WebAuthn keys) rather than software-based OTPs. Which authentication method integration should the administrator configure in Panorama?

Hard
15

A security analyst is configuring administrative access on a Cortex XDR platform to ensure that users only have permissions necessary to perform their specific job functions. Which core principle is the analyst implementing?

Easy
16

An administrator is integrating Okta with Palo Alto Networks Prisma Cloud using SAML 2.0 to handle administrative logins. Which component of Identity and Access Management (IAM) is primarily responsible for validating the user's credentials?

Easy
17

A SOC manager wants to restrict administrator access so that network engineers can modify firewall security policies, but cannot modify system-level settings or firewall high-availability (HA) parameters. Where should the manager configure this restriction in Panorama?

Easy
18

A security analyst is investigating a suspected lateral movement attempt within an enterprise network protected by Palo Alto Networks firewalls. According to the MITRE ATT&CK framework, which TWO of the following techniques are commonly categorized under the Lateral Movement tactic? (Choose two)

Medium
19

An enterprise security team is reviewing its Zero Trust Architecture deployment to ensure compliance with modern identity and access management standards. Which TWO practices are fundamental requirements of a true Zero Trust identity strategy? (Choose two)

Hard
20

An administrator is configuring authentication profiles in PAN-OS to integrate an external identity provider. Which TWO of the following server types can be directly configured as authentication server profiles in a Palo Alto Networks firewall? (Choose two)

Medium
21

An enterprise is implementing a Zero Trust Architecture across its cloud and on-premises environments using Palo Alto Networks Prisma Access and Next-Generation Firewalls. Which THREE of the following principles are core tenets of a Zero Trust Architecture? (Choose three)

Hard
22

An analyst investigating an APT campaign notes that the threat group modified Windows registry run keys to maintain persistence. In the context of MITRE ATT&CK, under which Tactic should this specific technique be documented?

Medium
23

While investigating a sophisticated adversary group using the MITRE ATT&CK navigator, a SOC analyst notes that the threat actor leveraged valid accounts to maintain persistence while modifying group memberships to escalate privileges. Which combination of MITRE ATT&CK tactics best describes these observed phases?

Hard
24

A security operations team is tracking an Advanced Persistent Threat (APT) group that exhibits custom command-and-control (C2) behavior, slow and low data exfiltration, and leverages living-off-the-land binaries. Which characteristic most reliably distinguishes this APT activity from a commodity malware campaign?

Hard
25

An incident responder analyzing an APT intrusion discovers that the attacker compressed and encrypted sensitive files locally on a compromised server before staging them for exfiltration. Under the MITRE ATT&CK framework, which Tactic describes this staging behavior?

Medium
26

An organization is deploying Palo Alto Networks firewalls in a Zero Trust Architecture. The security team wants to ensure that administrative access follows the principle of least privilege by tying administrator accounts to dynamic group memberships managed in an external LDAP directory, rather than maintaining static local accounts. Which feature in PAN-OS supports this?

Hard
27

During an incident investigation in Cortex XDR, an analyst identifies that an attacker utilized Windows Management Instrumentation (WMI) to execute commands remotely across multiple endpoints. According to the MITRE ATT&CK framework, under which tactic should this activity be categorized?

Medium
28

A security operations team is reviewing MITRE ATT&CK Tactic classifications for an incident involving credential theft and subsequent unauthorized actions on a Palo Alto Networks protected network. Which THREE of the following Tactics fall under the 'Post-Compromise' or later stages of the attack lifecycle? (Choose three)

Hard
29

A SOC analyst is investigating a suspected Advanced Persistent Threat (APT) group that exhibits classic characteristics during its operation lifecycle. Which THREE traits are typically associated with advanced persistent threat campaigns? (Choose three)

Medium
30

A security analyst reviews a Palo Alto Networks firewall traffic log showing an outbound connection over an encrypted tunnel to an unknown external IP address. The analyst suspects command-and-control traffic. Under the MITRE ATT&CK framework, which Tactic covers this network communication channel?

Medium
31

An enterprise is replacing its traditional perimeter defense model with Palo Alto Networks Prisma Access to enforce continuous verification of every user and device regardless of their network location. Which architectural framework is being applied?

Medium
32

An enterprise is integrating Azure Active Directory (Azure AD) with Palo Alto Networks GlobalProtect for SAML authentication. The SOC wants to enforce conditional access policies so that users logging in from unmanaged devices are blocked from connecting to sensitive corporate segments. Where is the policy evaluating device compliance primarily enforced in this workflow?

Hard
33

A SOC team is analyzing an advanced persistent threat (APT) campaign characterized by long dwell times, custom tooling, stealthy lateral movement, and persistent access designed for continuous espionage. Which attribute best differentiates this APT from a standard opportunistic ransomware attack?

Hard
34

A security team is designing a Zero Trust network access control model using Palo Alto Networks Next-Generation Firewalls. They want to ensure that authentication and authorization policies evaluate device compliance and user identity dynamically on every single connection attempt. Which feature combination best satisfies this requirement?

Hard
35

An organization is deploying Zero Trust Network Access (ZTNA) via Prisma Access. The SOC notices that a user device with compromised posture (missing host integrity check) is successfully authenticated by the SAML IdP but is denied network access. Where is this runtime access enforcement happening?

Hard
36

An administrator needs to ensure that Palo Alto Networks firewall administrators are automatically logged out of the Web Interface after 15 minutes of inactivity to prevent unauthorized access from unattended consoles. Where is this idle timeout configured?

Easy
37

An administrator needs to configure administrative access to Panorama so that a junior SOC analyst can view firewall configurations and logs, but cannot make any changes. Which configuration step enforces the principle of least privilege?

Easy
38

A security analyst needs to configure log forwarding from a Palo Alto Networks firewall to an external SIEM using encrypted TLS syslog. Where are the external log receiver settings configured in Panorama?

Easy
39

A security analyst is hardening administrative access on a Palo Alto Networks Panorama management server. Which TWO of the following best practices should be implemented to ensure secure administrative access? (Choose two)

Medium
40

During an incident response investigation, a SOC analyst discovers that an APT group utilized scheduled tasks and Windows Management Instrumentation (WMI) to maintain access across reboots in a Palo Alto Networks protected enterprise. Which MITRE ATT&CK Tactic categorizes these techniques?

Medium
41

A security analyst is examining an advanced malware sample reported by Cortex XDR. The malware utilizes sophisticated evasion techniques. Which THREE of the following MITRE ATT&CK techniques are commonly associated with the Defense Evasion tactic? (Choose three)

Hard
42

An analyst reviewing Cortex XDR alerts observes an attacker attempting to encode malicious scripts using Base64 to bypass signature-based detection mechanisms on an endpoint. Under the MITRE ATT&CK framework, which Tactic defines this behavior?

Medium
43

An enterprise is enforcing a strict Zero Trust policy where all access requests to internal applications must be authorized via dynamic trust scores calculated by Cortex XSOAR and enforced by Prisma Access. An incident occurs where an administrative account is flagged for anomalous behavior, but the session remains active. Which integration mechanism should be triggered to immediately terminate the active session across all enforcement points?

Hard
44

An administrator is configuring Multi-Factor Authentication (MFA) for Prisma Access administrative access. Which component in the authentication sequence is responsible for validating the secondary MFA token (such as an push notification)?

Easy
45

A security analyst needs to review authentication attempts made by administrators logging into a Palo Alto Networks firewall. Which log type in the Web Interface contains these administrative login records?

Easy
46

An auditor is evaluating compliance with the principle of least privilege for Palo Alto Networks administrator accounts. Which TWO of the following practices indicate a failure or violation of least privilege? (Choose two)

Medium

Frequently asked questions

What does the SOC Operations domain cover on the Cybersecurity-Practitioner exam?
SOC Operations questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 46 SOC Operations questions in the Cybersecurity-Practitioner question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only SOC Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cybersec-practitioner PANW-CYBERSEC-PRACTITIONER soc operations Practice Questions