Courseiva

Certified Security Operations Architect (SecOps-Architect) (SecOps-Architect) — Questions 175

217 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
Multi-Selectmedium

An architect is planning the deployment of Cortex XDR agents across a heterogeneous enterprise environment. Which TWO deployment methods are officially supported? (Choose two)

Select 2 answers
A.Embedding the agent installer inside public spam email attachments
B.Active Directory Group Policy Object (GPO) deployment
C.Manual floppy disk installation on every workstation
D.Centralized endpoint management tools (e.g., Microsoft Intune, SCCM, Jamf)
E.Mailing unencrypted USB flash drives to employees' home addresses
AnswersB, D

GPO is a standard enterprise method for deploying Windows software.

Why this answer

Cortex XDR agents can be deployed via Active Directory Group Policy (GPO) or centralized endpoint management tools like SCCM/Intune.

2
MCQeasy

When designing a threat hunting methodology aligned with the MITRE ATT&CK framework, an architect wants to identify adversary persistence mechanisms. Which tactic category should the analyst focus queries on?

A.Initial Access
B.Persistence
C.Collection
D.Execution
AnswerB

Persistence techniques allow adversaries to maintain access across restarts.

Why this answer

Persistence tactics include techniques such as Registry Run Keys, Startup Folder, and Scheduled Tasks.

3
MCQhard

An architect is designing a Prisma Cloud Compute deployment for Kubernetes clusters deployed across multiple cloud providers. The architecture requires real-time runtime defense against container escapes and anomalous process execution. Which Prisma Cloud component must be deployed inside each Kubernetes cluster to achieve this?

A.Prisma Access Remote Network connector container pod
B.Panorama virtual appliance deployed as a Kubernetes Ingress controller.
C.GlobalProtect containerized app
D.Prisma Cloud Defender DaemonSet deployed to every node in the Kubernetes cluster.
AnswerD

Defenders run as a DaemonSet to monitor container runtime behavior and enforce security policies locally.

Why this answer

Prisma Cloud Compute Defender daemonsets run on each node in the cluster to provide runtime defense, vulnerability scanning, and compliance checks.

4
Multi-Selecthard

An organization is building a Threat Intelligence Program aligned with the Diamond Model of Intrusion Analysis. Which THREE core vertices must be analyzed for every adversary event in the incident tracking database? (Choose three)

Select 3 answers
A.Capability (the tools and techniques used by the adversary)
B.Office HVAC cooling capacity metrics
C.Infrastructure (the physical or logical communication channels used)
D.Local cafeteria menu pricing structures
E.Adversary (the actor or organization responsible for the intrusion)
AnswersA, C, E

Correct. Capability represents the software, exploits, and techniques utilized.

Why this answer

The Diamond Model of Intrusion Analysis consists of four core vertices: Adversary, Capability, Infrastructure, and Victim.

5
Multi-Selectmedium

An architect is configuring Panorama Template Stacks. Which TWO types of configuration settings are typically defined within Panorama Templates rather than Device Groups? (Choose two)

Select 2 answers
A.Cortex XDR agent installation packages.
B.Security policy rules and URL filtering security profiles.
C.Network interface IP addresses, virtual routers, and static routes.
D.Device system settings, DNS servers, NTP servers, and management plane IP addresses.
E.Dynamic Address Groups and tag registration filters.
AnswersC, D

Templates manage network and device-level settings like interfaces and routing.

Why this answer

Templates manage network and device configurations (interfaces, virtual routers, static routes, system settings, SNMP), while Device Groups manage security policies and profiles.

6
MCQeasy

Which Cortex XSOAR feature should a Security Operations Architect use to automatically calculate, track, and display SLA compliance metrics for incoming security incidents?

A.Cortex XDR Analytics Engine
B.Incident SLAs and SLA dashboards
C.WildFire submission quotas
D.Threat Intelligence Management feeds
AnswerB

Incident SLAs track time thresholds and generate automated compliance metrics and dashboard widgets in XSOAR.

Why this answer

Cortex XSOAR uses SLAs (Service Level Agreements) tied to incident types and severity levels to automatically track and calculate compliance metrics.

7
MCQeasy

An architect is defining Key Performance Indicators (KPIs) in Cortex XSIAM to measure the efficiency of Tier-1 analysts. Which built-in metric best evaluates the speed at which analysts initially acknowledge and begin investigating incoming alerts?

A.Mean Time to Acknowledge (MTTA)
B.False Positive Rate (FPR)
C.Mean Time to Resolution (MTTR)
D.Mean Time to Contain (MTTC)
AnswerA

MTTA tracks the duration between alert creation and the start of active investigation.

Why this answer

Mean Time to Acknowledge (MTTA) specifically measures the speed at which analysts transition an alert from new to in-progress, directly evaluating initial triage speed.

8
MCQeasy

An architect is configuring High Availability (HA) Active/Passive on two PA-5220 firewalls. During a failover event, active TCP sessions are maintained without requiring re-authentication. Which feature makes this possible?

A.GlobalProtect cookie persistence
B.HA2 session synchronization
C.Dynamic DNS updates
D.Panorama configuration push
AnswerB

HA2 synchronizes state tables so active sessions seamlessly fail over.

Why this answer

HA2 session synchronization copies active session table entries from the active peer to the passive peer in real time.

9
Multi-Selectmedium

An architect is designing an incident response communications plan for a major data breach affecting regulated customer data. Which TWO stakeholder groups must typically be included in the formal communication escalation matrix during high-severity incidents? (Choose two)

Select 2 answers
A.Building facilities management team
B.Internal cafeteria catering staff
C.Third-party software vendors of unrelated office productivity tools
D.Corporate Communications / Public Relations
E.Legal Counsel / Privacy Officer
AnswersD, E

Correct. PR manages external messaging and brand protection during public-facing breaches.

Why this answer

During major data breaches, legal counsel and corporate communications/PR are critical stakeholders required for regulatory notification and public messaging governance.

10
MCQhard

An architect is deploying the Cortex XDR Broker VM to serve as a syslog collector for legacy network devices. The Broker VM loses connectivity to the Cortex XDR cloud. What happens to the collected syslog data during the outage?

A.The Broker VM automatically switches to backup SMTP forwarding
B.The syslog sender devices resend the packets automatically via TCP retry
C.The data is permanently dropped until connectivity returns
D.The data is buffered locally on the Broker VM and forwarded once reconnected
AnswerD

Local buffering ensures no log loss during brief network outages.

Why this answer

The Broker VM buffers incoming syslog messages locally up to a designated storage threshold until cloud connectivity is restored.

11
Multi-Selecthard

An architect is troubleshooting why security metric trends in Cortex XSIAM appear erratic and unreliable. Which THREE factors commonly cause metric distortion in a SOC? (Choose three)

Select 3 answers
A.Configuring browser bookmarks for dashboard access
B.Intermittent log ingestion pipeline failures or collector outages
C.Using dark mode instead of light mode in the Cortex XSIAM web UI
D.Inconsistent log parsing or changes in log formats from third-party vendors
E.Unannounced mass deployment or decommissioning of endpoint agents
AnswersB, D, E

Missing log data during pipeline outages creates artificial drops in metric trends.

Why this answer

Metric distortion is frequently caused by log source ingestion failures, inconsistent log parsing/normalization, and sudden shifts in business operations or endpoint coverage.

12
Multi-Selecthard

An architect is designing an integration between Prisma Cloud and AWS to perform Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) scanning. Which TWO AWS architectural permissions or resources must be established for complete CSPM and CWPP integration? (Choose two)

Select 2 answers
A.An AWS IAM Role configured with SecurityAudit and read-only access policies, secured via an External ID.
B.Direct root SSH access to the AWS hypervisor management plane.
C.AWS CloudTrail integration to ingest API audit logs for real-time threat detection (Cloud Native Network Segmentation / Runtime).
D.Modifying the AWS VPC core router BIOS code.
E.Physical serial console cables plugged into AWS data center racks.
AnswersA, C

CSPM integration requires read-only IAM permissions with an external ID for secure cross-account assessment.

Why this answer

Prisma Cloud CSPM requires an IAM Role with read-only permissions (and appropriate AWS managed policies like SecurityAudit) and an External ID. CWPP requires Defender permissions or cloud-native deployment.

13
Multi-Selectmedium

An architect is configuring role-based access control (RBAC) in Cortex XSIAM for a multi-tenant SOC environment. Which TWO principles should guide the design of security analyst roles? (Choose three - wait, prompt says Which TWO for multi_select half. Let's provide TWO). Which TWO principles should guide the design of security analyst roles? (Choose two)

Select 2 answers
A.Principle of least privilege (granting only necessary permissions for job functions)
B.Sharing a single root administrator account across the entire global SOC team
C.Assigning full Super Administrator privileges to all Tier 1 analysts to accelerate triage
D.Disabling audit logging for administrator actions to save disk space
E.Segregation of duties between incident responders and system administrators
AnswersA, E

Correct. Least privilege limits exposure if an account is compromised.

Why this answer

RBAC design in SOC environments should adhere to the principle of least privilege and role-based segregation of duties between triage analysts and administrators.

14
MCQmedium

An architect is configuring a Panorama Device Group and needs to create security rules that apply to all firewalls in the enterprise, regardless of their specific regional location. Where should the architect place these rules within the Panorama rule hierarchy?

A.Template stack interface configurations.
B.Local firewall CLI configuration files only.
C.Panorama Pre-Rules configured at the topmost level before device group specific rules.
D.Post-rules at the bottom of a single remote branch device group.
AnswerC

Panorama Pre-Rules enforce mandatory security policies globally across all managed firewalls before local rules are evaluated.

Why this answer

Panorama supports Pre-Rules and Post-Rules, with Pre-Rules evaluated before device group local rules and Pre-Rules enforced globally across all device groups when configured at the global level.

15
MCQmedium

You are designing an automated phishing response workflow in Cortex XSOAR. The playbook needs to extract all URLs from an incoming email body and check their reputation using VirusTotal. Which built-in task type should you use to evaluate each URL concurrently?

A.Loop / For-Each Task
B.Data Collection Task
C.Transformation Script Task
D.Manual Review Task
AnswerA

A loop task processes each item in an extracted list of URLs.

Why this answer

A loop task in Cortex XSOAR iterates over lists or arrays, such as extracted URLs, allowing parallel or sequential processing.

16
MCQmedium

An incident response team uses Cortex XSOAR playbooks for automated enrichment. Leadership wants to measure how much time automation saves per incident compared to manual lookup tasks. Which methodology should the architect use to calculate this metric?

A.Multiply total successful automated task executions by the estimated manual execution time per task.
B.Subtract the total number of closed incidents from the number of open incidents.
C.Measure the average CPU load of the Cortex XSOAR server during playbook execution.
D.Divide total firewall logs by the number of active Cortex XSOAR integrations.
AnswerA

This formula provides an accurate quantitative measure of time reclaimed by SOAR playbooks.

Why this answer

To calculate time saved by automation, multiply the number of automated task executions by the estimated time it would take an analyst to perform those same tasks manually.

17
MCQeasy

When designing a threat hunting architecture, an architect must differentiate between indicator-based searching and hypothesis-driven hunting. Which approach represents a hypothesis-driven threat hunt?

A.Blocking known malicious domains using PAN-OS DNS Security
B.Automating the ingestion of STIX/TAXII feeds into Cortex XSOAR
C.Searching for specific file hashes provided in a recent vendor threat intelligence report
D.Developing a query to detect potential lateral movement using PowerShell remoting based on recent red team exercises
AnswerD

Correct. This starts with a specific behavioral hypothesis derived from TTPs.

Why this answer

Hypothesis-driven hunting starts with a theory about potential adversary behavior or TTPs and uses analytics to search for undiscovered activity.

18
Multi-Selecthard

An organization is integrating Cortex XSIAM with third-party security tools for automated remediation. Which THREE mechanisms are supported for triggering external actions from XSIAM/XSOAR? (Choose three)

Select 3 answers
A.Leveraging Python automation scripts using the Demisto/XSOAR API library
B.Direct physical rewiring of Ethernet patch panels
C.Executing integration commands within playbooks
D.Calling external webhooks via HTTP Request automation scripts
E.Inserting punch cards into magnetic readers
AnswersA, C, D

Python scripts can invoke external APIs and custom logic.

Why this answer

Actions can be triggered via REST APIs, SDKs, and built-in integration commands.

19
MCQmedium

An architect is designing an integration between Cortex XSOAR and a third-party ticketing system (e.g., ServiceNow). The requirement is to ensure that when an incident severity is updated in XSOAR, the ticket in ServiceNow is automatically updated. Which architectural feature facilitates this synchronization?

A.Syslog forwarding over UDP port 514
B.Bi-directional incident field mapping and integration commands
C.PAN-OS Dynamic Address Group API push
D.GlobalProtect client certificate renewal protocol
AnswerB

Correct. Mapping rules and integration commands synchronize incident fields across platforms.

Why this answer

Bi-directional incident mapping and mapping rules in XSOAR integration instances allow field values to sync automatically between XSOAR and ticketing systems.

20
Multi-Selectmedium

An architect is configuring High Availability (HA) on Palo Alto Networks firewalls. Which TWO failure conditions can trigger an automatic HA failover in an Active/Passive deployment? (Choose two)

Select 2 answers
A.Link monitoring failure (loss of connectivity on a monitored critical interface).
B.A scheduled Panorama software inventory check.
C.Loss of heartbeat and control communication over the HA1 link (peer down).
D.Changing the firewall hostname string.
E.An administrator manually changing the firewall GUI theme color from dark to light mode.
AnswersA, C

Link monitoring triggers failover if designated critical interfaces lose link status.

Why this answer

HA failover can be triggered by path monitoring failures, link monitoring failures, hardware power supply failure, or loss of heartbeats over the HA1 link.

21
Multi-Selecthard

An architect is designing an integrated security architecture combining Prisma Cloud and Palo Alto Networks NGFWs. Which TWO architectural capabilities does this integration provide? (Choose two)

Select 2 answers
A.Physically connecting AWS data centers to corporate offices using copper Ethernet cables.
B.Providing end-to-end visibility and compliance posture for multi-cloud resources alongside network threat protection.
C.Sharing cloud workload context and security tags with firewalls to dynamically enforce security policies based on cloud metadata.
D.Running GlobalProtect gateway software inside AWS S3 storage buckets.
E.Replacing all firewall data plane processors with software container pods.
AnswersB, C

Combining Prisma Cloud posture management with NGFW threat protection provides comprehensive security visibility.

Why this answer

Integrating Prisma Cloud with NGFWs enables cloud workload context sharing, microsegmentation enforcement, and unified visibility across cloud and network perimeters.

22
MCQeasy

An organization wants to measure the efficiency of its SOC by tracking how quickly analysts acknowledge incoming high-priority alerts. Which metric is being measured?

A.Mean Time to Detect (MTTD)
B.Mean Time to Acknowledge (MTA)
C.Mean Time Between Failures (MTBF)
D.Mean Time to Patch (MTTP)
AnswerB

MTA measures the time elapsed from alert generation to analyst acknowledgement.

Why this answer

Mean Time to Acknowledge (MTA) or Mean Time to Respond (MTTR) tracks acknowledgement and response speed.

23
Multi-Selectmedium

An architect is configuring High Availability (HA) on a pair of Palo Alto Networks firewalls. Which TWO prerequisites must be met before enabling HA on the firewalls? (Choose two)

Select 2 answers
A.Management interfaces must be configured on completely different subnet masks with mismatched default gateways.
B.Both firewalls must be running the exact same PAN-OS software version.
C.Both firewalls must have different models (e.g., PA-3220 paired with PA-5220).
D.Both firewalls must have identical license and support subscriptions installed.
E.HA ports must be connected to the internet via public IP addresses.
AnswersB, D

HA peers must run identical PAN-OS versions to ensure configuration and state compatibility.

Why this answer

HA peers must have identical hardware/VM models, identical PAN-OS software versions, matching license configurations, and dedicated HA cable connections.

24
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to inspect unknown files submitted by users over HTTP/FTP/SMTP to determine if they contain zero-day malware. Which service should the architect configure?

A.WildFire cloud-based malware analysis
B.URL Filtering cloud database
C.GlobalProtect portal
D.DNS Security service
AnswerA

WildFire sandboxes unknown files to identify zero-day malware behavior.

Why this answer

WildFire is Palo Alto Networks cloud-based threat analysis service that sandboxes unknown files to detect zero-day malware.

25
MCQmedium

An architect is integrating Cortex XSIAM with ServiceNow to automatically create IT service management (ITSM) tickets when incidents are promoted. Where is the field mapping between Cortex XSIAM incident fields and ServiceNow incident fields configured?

A.ServiceNow Integration Instance Mapper configuration
B.Magnifier machine learning threshold slider
C.Syslog server forwarding configuration
D.Cortex XDR Agent policy settings
AnswerA

Instance mappers define incoming and outgoing field mappings between systems.

Why this answer

Incident fields and ITSM mapping in Cortex XSIAM/XSOAR are configured in the Incident Mirroring and Integrations mapping settings.

26
Multi-Selecthard

An architect is configuring Cortex XDR external integrations. Which TWO native log ingestion or threat intelligence integration options are supported by Cortex XDR? (Choose two)

Select 2 answers
A.Polling Windows Active Directory via SNMPv1 for group policies.
B.Integrating external Threat Intelligence feeds using STIX/TAXII server connections.
C.Using NetBIOS broadcast packets to scrape passwords from domain controllers.
D.Directly flashing raw firmware onto third-party routers via XDR agent plugins.
E.Ingesting third-party network and security logs via the Cortex XDR Broker VM and Syslog Collector.
AnswersB, E

Cortex XDR supports STIX/TAXII feeds to ingest IOCs for correlation and detection.

Why this answer

Cortex XDR supports ingesting third-party alerts and logs via Syslog Collector / Broker VM and integrating Threat Intelligence feeds via STIX/TAXII.

27
MCQhard

An enterprise security architect is designing high availability for Cortex XSOAR engines. If the primary engine fails, what mechanism ensures zero data loss and uninterrupted playbook execution for active incidents?

A.Periodic XML configuration exports via cron jobs
B.Automatic client-side browser caching of playbook states
C.Active-Active cluster architecture backed by external PostgreSQL and Redis
D.DNS round-robin load balancing between local SQLite storage files
AnswerC

External database and Redis clustering ensure state persistence and failover.

Why this answer

Cortex XSOAR high availability utilizes an active-passive or active-active cluster backed by an external PostgreSQL database and Redis data store.

28
MCQmedium

An architect is configuring a Palo Alto Networks firewall and needs to ensure that DNS requests originating from internal clients to known malicious domains are automatically intercepted or blocked. Which security feature provides this capability?

A.DNS Security service with sinkhole configuration.
B.Static host file entries on the firewall management interface.
C.SNMP trap alert generator.
D.DHCP lease reservation tables.
AnswerA

DNS Security analyzes DNS queries and can sinkhole malicious domains to capture infected hosts.

Why this answer

DNS Security service uses machine learning and threat intelligence to analyze and block malicious DNS requests in real time.

29
MCQeasy

Which metric category is primarily used to evaluate the financial and operational cost savings delivered by a security orchestration and automation (SOAR) implementation?

A.Firewall Packet Inspection Latency
B.Hours Saved through Automation / Manual Labor Hours Reclaimed
C.Endpoint Agent Crash Frequency
D.Threat Intelligence Feed Ingestion Bandwidth
AnswerB

This metric calculates the operational efficiency and financial ROI gained by automating routine security tasks.

Why this answer

Hours saved through automation (or Cost Savings via Automation) measures how much manual labor was eliminated by automated playbooks.

30
MCQmedium

An architect is auditing security operations metrics and notices that the False Positive Rate (FPR) for endpoint detection alerts in Cortex XDR has steadily increased over the past two quarters. What is the most appropriate remediation strategy to address this trend?

A.Increase the alert severity threshold globally to hide low-priority alerts
B.Tune analytic profiles and update local exception/suppression lists in Cortex XDR
C.Disable behavioral analytics modules to stop generating anomaly-based alerts
D.Reduce the log retention period to purge historical false positive data
AnswerB

Refining analytic rules and creating proper exceptions directly addresses the root cause of high FPR.

Why this answer

Tuning analytics rules and suppression lists based on historical feedback directly reduces false positives in Cortex XDR.

31
Multi-Selecteasy

When designing an incident post-mortem (lessons learned) process following NIST guidelines, which TWO activities should the security architect mandate? (Choose two)

Select 2 answers
A.Conducting a root cause analysis review meeting with key stakeholders
B.Deleting all firewall and SIEM log archives immediately
C.Reverting all system configurations to factory defaults without review
D.Updating detection rules and SOAR playbooks based on operational gaps identified
E.Publicly disclosing employee disciplinary actions on social media
AnswersA, D

Correct. Analyzing how the incident occurred and how response was handled is vital for improvement.

Why this answer

Post-incident activities include conducting a root cause analysis meeting, documenting lessons learned, updating playbooks, and improving detection rules.

32
MCQeasy

Which metric should a SOC manager review to determine whether alerts are being investigated in a timely manner after they are generated?

A.Total Log Storage Volume in Terabytes
B.Firewall Rule Hit Count
C.Mean Time to Acknowledge (MTTA)
D.Cortex XDR Agent Deployment Percentage
AnswerC

MTTA specifically measures how quickly alerts are picked up and acknowledged by analysts.

Why this answer

Mean Time to Acknowledge (MTTA) or Mean Time to Triage measures the speed from alert creation to the start of analyst investigation.

33
Multi-Selectmedium

An architect is troubleshooting a User-ID deployment where users authenticating via captive portal are not getting correctly mapped. Which TWO conditions must be verified to ensure captive portal functions properly? (Choose two)

Select 2 answers
A.Verify that an Authentication Profile and Authentication Policy are correctly configured to prompt users.
B.Verify that a security policy rule allows traffic to the captive portal IP address and authentication port.
C.Ensure that the firewall's management plane CPU is disabled to allow unhindered redirects.
D.Ensure that User-ID agents are disabled when captive portal is active.
E.Verify that all users have installed the Prisma Cloud Defender agent.
AnswersA, B

Captive portal requires an authentication profile to validate credentials against LDAP/RADIUS/SAML.

Why this answer

Captive portal requires an appropriate Authentication Profile/Sequence, an explicit security policy allowing HTTP/HTTPS traffic to the captive portal IP/port, and correctly configured redirection settings.

34
MCQeasy

What is the primary value of tracking 'False Positive Rate' (FPR) as an operational security metric in a SOC?

A.It determines the exact number of active endpoints in Cortex XDR.
B.It calculates the physical power consumption of security appliances.
C.It helps identify noisy detection rules that contribute to analyst fatigue and require tuning.
D.It measures the total network bandwidth consumed by the organization.
AnswerC

High FPR indicates alert noise and analyst fatigue, signaling the need for rule tuning.

Why this answer

Tracking FPR helps identify noisy detection rules that waste analyst time, driving alert tuning and rule refinement.

35
MCQhard

An architect is configuring a Cortex XDR integration with a third-party SIEM. The SIEM requires log data formatted in Common Event Format (CEF) over Syslog. Where should the architect configure this output format in the Cortex XDR architecture?

A.Cortex XDR Broker VM Syslog Collector profile configured with CEF mapping.
B.Prisma Cloud compliance check rule definitions.
C.Panorama firewall administrative GUI banner settings.
D.GlobalProtect gateway portal authentication profile.
AnswerA

The Broker VM Syslog Collector translates XDR logs into CEF format for external SIEM consumption.

Why this answer

Cortex XDR Log Forwarding profiles or Broker VM Syslog Collector configurations allow formatting logs in CEF or JSON before forwarding to external SIEMs.

36
MCQmedium

An architect is deploying Panorama and needs to manage firewalls deployed across different geographic regions with distinct administrative teams. Each team should only be able to view and manage their own local firewalls and policies, but global security rules must apply to all. Which Panorama structural feature should the architect implement?

A.Device Groups combined with Administrator Roles and Access Domains.
B.Multiple virtual routers inside a single device group.
C.Separate Panorama virtual appliances for each region configured in an HA mesh cluster.
D.Dynamic Address Groups with tag-based RBAC.
AnswerA

Device Groups organize firewalls logically, while Access Domains and Admin Roles restrict administrators to specific device groups and templates.

Why this answer

Panorama uses Device Groups and Administrative Roles/Domains to implement role-based access control (RBAC) and logical grouping for multi-tenancy or regional separation.

37
Multi-Selectmedium

An architect is configuring Palo Alto Networks firewall security policies using WildCard masks and Address Objects. Which TWO best practices should be followed when designing address objects and security rules? (Choose two)

Select 2 answers
A.Use descriptive naming conventions for Address Objects and Address Groups to clearly indicate their purpose and zone.
B.Group related IP addresses and subnets into Address Groups to simplify security rule management.
C.Delete all predefined PAN-OS application objects from the firewall.
D.Use a single security rule with source 'any', destination 'any', and application 'any' for all enterprise traffic.
E.Hardcode individual IP addresses directly into every security rule without using address objects.
AnswersA, B

Descriptive naming improves readability, maintainability, and auditability of security policies.

Why this answer

Best practices include using descriptive naming conventions, grouping related IP addresses into Address Groups, and avoiding overly broad 'any-any' rules.

38
MCQeasy

An architect is designing a high availability deployment for Palo Alto Networks firewalls. What is the primary purpose of the HA1 link?

A.Transfer high-speed data plane network traffic during normal operation.
B.Forward system logs to external SIEM collectors.
C.Provide direct internet access to client workstations behind the firewall.
D.Synchronize control plane configurations and exchange heartbeat keepalive messages between HA peers.
AnswerD

HA1 handles control plane heartbeats and configuration synchronization.

Why this answer

The HA1 link is dedicated to control plane communication, configuration synchronization, and heartbeats between HA peers.

39
MCQmedium

A security architect is designing an incident escalation matrix for a multinational SOC. Which metric is most critical to measure the effectiveness of the Tier 1 triage team before escalating incidents to Tier 2?

A.Mean Time to Acknowledge (MTTA) and Triage accuracy
B.Number of global security patents filed
C.Mean Time to Patch (MTTP)
D.Total volume of firewall rules configured
AnswerA

Correct. MTTA and triage accuracy measure the speed and precision of initial alert handling.

Why this answer

Mean Time to Triage (MTTT) or Mean Time to Acknowledge (MTTA) measures how quickly Tier 1 processes and validates incoming alerts before escalating.

40
MCQmedium

A security architect needs to create a custom dashboard widget in Cortex XSOAR to track the average duration of phishing incident investigations over the last quarter. Which widget type should the architect select to display this time-series metric trend over a date range?

A.Pie widget
B.Counter widget
C.Bar widget
D.Line widget
AnswerD

A line widget plots data points over time, perfect for trend analysis.

Why this answer

A line widget in Cortex XSOAR is designed to display trends over time, making it ideal for tracking duration metrics chronologically.

41
MCQhard

An architect is designing an enterprise threat hunting program utilizing Cortex XSIAM. They want to create a custom analytics rule that triggers when a specific sequence of three distinct event types occurs within a 10-minute window on the same endpoint. Which feature should be used?

A.Static IP Blocklist configuration
B.XSOAR Email Parsing Rules
C.Cortex XDR Agent Local Analysis settings
D.XQL Correlation Rules (Sequence matching)
AnswerD

XQL correlation rules support sequence matching across time windows.

Why this answer

Data Stitching and XQL correlation rules allow multi-event sequence detection across datasets and time windows.

42
MCQmedium

An architect is troubleshooting an issue where Palo Alto Networks VM-Series firewalls deployed in AWS are experiencing asymmetric routing issues across multiple network interfaces. Which AWS networking construct must be correctly configured to ensure traffic enters and exits through the correct firewall data interface?

A.Panorama Template stack backup schedules.
B.Palo Alto Networks Management interface static default gateway.
C.AWS Security Groups blocking all inbound ports.
D.AWS Route Tables associated with subnets pointing traffic to specific Elastic Network Interfaces (ENIs).
AnswerD

Proper route table configuration in AWS ensures symmetric routing across VM-Series network interfaces.

Why this answer

AWS Route Tables (specifically custom Route Tables associated with subnets and Elastic Network Interfaces) dictate traffic flow to and from VM-Series interfaces.

43
MCQmedium

An architect is designing a multi-tenant Palo Alto Networks NGFW deployment using Virtual Systems (vsys). Each vsys requires its own isolated set of administrators, security policies, and network interfaces. Which configuration constraint must the architect keep in mind regarding WildFire and Decryption properties in a vsys architecture?

A.Panorama cannot manage firewalls configured with virtual systems.
B.Virtual systems cannot have separate security policies; all policies are strictly global.
C.Decryption is impossible on virtual systems.
D.Physical interfaces can be allocated exclusively to a vsys or shared, and cryptographic profiles can be shared or defined locally per vsys.
AnswerD

Virtual systems allow granular allocation of physical interfaces, security policies, and shared/local object structures.

Why this answer

Some features like WildFire, GlobalProtect portal, and certain cryptographic profiles can be shared or configured globally, but vsys have specific rules regarding interface allocation and shared objects. Specifically, physical interfaces must be assigned to specific vsys or shared, and WildFire can be configured globally or per vsys depending on PAN-OS version.

44
MCQeasy

An architect is configuring a Palo Alto Networks firewall to decrypt inbound SSL/TLS traffic destined for an internal web server. Which certificate configuration is required on the firewall to perform Inbound Inspection?

A.An expired public certificate from a third-party root CA.
B.No certificates are required if SSH is used instead of SSL.
C.A self-signed Certificate Authority (CA) certificate generated solely on the firewall without any server keys.
D.The private key and certificate of the internal web server must be installed on the firewall.
AnswerD

The firewall needs the server's private key to decrypt inbound SSL/TLS sessions.

Why this answer

Inbound Inspection requires importing the server's private key and public certificate onto the firewall so it can decrypt traffic destined for that server.

45
MCQmedium

An architect is tasked with reporting the True Positive Rate (TPR) of automated alert rules in Cortex XSIAM to justify tuning efforts. How should TPR be calculated using SOC operational data?

A.Total False Positives divided by Total Closed Incidents
B.Total Incidents Remediated divided by Total Hours Worked
C.Mean Time to Resolve divided by Mean Time to Detect
D.Verified True Positive Alerts divided by Total Triggered Alerts
AnswerD

TPR measures the proportion of alerts that correctly identified a genuine security incident out of all generated alerts.

Why this answer

True Positive Rate is calculated by dividing the number of verified true positive alerts by the total number of triggered alerts (or true positives plus false negatives, depending on the specific formula variant, but strictly using verified alerts vs total alerts generated).

46
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to control application traffic (such as allowing Skype business calls while blocking Skype file transfers). Which security policy match enables this granularity?

A.Destination IP address matching only.
B.App-ID based security policy rules specifying application and sub-features.
C.TCP port number matching (e.g., port 80/443).
D.Source MAC address filtering.
AnswerB

App-ID inspects traffic semantics to differentiate sub-features of an application, such as file transfer vs. video.

Why this answer

App-ID allows granular control of applications and sub-features (App-ID sub-functions) within a single security policy rule.

47
MCQeasy

An architect is configuring High Availability (HA) on two Palo Alto Networks firewalls. What happens to active sessions on the primary firewall if it experiences a power failure, assuming HA is configured in Active/Passive mode?

A.The firewall reboots into maintenance mode and requires manual CLI intervention.
B.The passive firewall takes over active traffic and maintains sessions via HA2 synchronization.
C.Traffic is permanently blackholed until an administrator logs into Panorama.
D.All active user sessions are immediately dropped and must re-authenticate.
AnswerB

Active/Passive failover transfers stateful sessions via HA2 sync so active connections continue seamlessly.

Why this answer

In Active/Passive HA, when the active unit fails, the passive unit takes over and active sessions are maintained if HA2 session synchronization is enabled.

48
Multi-Selecteasy

When designing a Security Operations Center (SOC) using the NIST cybersecurity framework, which TWO functions are categorized under the 'Detect' core function? (Choose two)

Select 2 answers
A.Disaster Recovery plan execution
B.Incident Recovery Planning
C.Security Continuous Monitoring (SCM)
D.Access Control policy enforcement
E.Detection Processes and Procedures
AnswersC, E

Correct. Continuous monitoring is a core component of the Detect function.

Why this answer

The NIST CSF 'Detect' function includes Anomalies and Events, Security Continuous Monitoring, and Detection Processes.

49
Multi-Selecthard

An architect is designing a secure CI/CD pipeline integration using Prisma Cloud to scan container images before they are pushed to a container registry (such as AWS ECR or Docker Hub). Which TWO mechanisms can be utilized for this pre-deployment image scanning? (Choose two)

Select 2 answers
A.Integrating the Prisma Cloud twistcli scanner utility into the CI/CD pipeline build script (e.g., Jenkins or GitLab CI).
B.Installing the GlobalProtect desktop VPN client on every container container image layer.
C.Physically connecting the build server to a Palo Alto Networks PA-5250 hardware appliance via BNC cables.
D.Configuring Prisma Cloud Jenkins plugin to automatically scan built images for vulnerabilities and compliance violations.
E.Configuring raw SNMP traps on the Docker daemon socket.
AnswersA, D

The twistcli command-line scanner allows developers to scan container images during the build phase before pushing to registries.

Why this answer

Prisma Cloud supports scanning container images in CI/CD pipelines using plugins for Jenkins, GitLab, GitHub Actions, or using the Prisma Cloud CLI scanner tool.

50
Multi-Selecthard

An architect is designing an executive security operations dashboard using Cortex XSIAM to report on security posture trends. Which TWO metrics are essential to include when demonstrating operational scalability and capacity management to senior leadership? (Choose two)

Select 2 answers
A.Active directory domain controller CPU temperatures
B.Alert Volume vs. Incident Conversion Rate
C.Local firewall packet drop counts
D.Cortex XDR agent installation deployment scripts
E.Analyst Workload Capacity and Utilization Trends
AnswersB, E

This metric shows how efficiently raw alerts are filtered down to actionable incidents as volume scales.

Why this answer

Analyst Workload Capacity and Alert Volume vs. Incident Conversion Rate directly demonstrate how well the SOC handles scaling workloads without compromising effectiveness.

51
MCQeasy

Which role in a well-structured Security Operations Center (SOC) is primarily responsible for performing tier-2 incident triage, deep investigation, and playbook execution?

A.Compliance Auditor
B.Chief Information Security Officer (CISO)
C.SOC Tier-2 Analyst / Incident Responder
D.Helpdesk Support Technician
AnswerC

Tier-2 analysts investigate complex alerts escalated from Tier-1.

Why this answer

Tier-2 analysts handle escalated alerts requiring deeper investigation and active remediation.

52
MCQeasy

Which tool within Cortex XSIAM allows an architect to build customized graphical widgets and dashboards for tracking operational metrics?

A.Prisma Access Cloud Management
B.Panorama Policy Optimizer
C.Cortex XSIAM Dashboards and Widget Builder
D.WildFire Web Portal
AnswerC

The Dashboard and Widget Builder in XSIAM enables custom metric visualization using BIQL queries.

Why this answer

Cortex XSIAM provides built-in Dashboards and BIQL-powered widget builders for visualizing security metrics and operational KPIs.

53
MCQhard

An enterprise security architect is designing data residency compliance controls for Cortex XSIAM. European Union customer data must not leave the EU region. Where is data residency enforced in Cortex XSIAM?

A.By configuring log filtering rules in XSOAR playbooks
B.By enabling TLS 1.3 encryption on the Broker VM
C.By selecting the appropriate EU-hosted cloud tenant region during initial tenant provisioning
D.By setting local registry keys on each Windows endpoint agent
AnswerC

Tenant provisioning region dictates storage and processing location.

Why this answer

Data residency is determined by the geographic location of the tenant tenant cluster provisioned during onboarding.

54
MCQeasy

An architect is designing an incident response lifecycle based on the NIST SP 800-61 framework for a Security Operations Center (SOC). Which phase immediately follows the Containment, Eradication, and Recovery phase?

A.Detection and Analysis
B.Post-Incident Activity
C.Threat Intelligence Enrichment
D.Risk Assessment
AnswerB

Correct. Post-Incident Activity (often called Lessons Learned) is the final phase of the NIST incident response lifecycle.

Why this answer

According to NIST SP 800-61, the lifecycle phases are Preparation, Detection and Analysis, Containment, Eradication, and Recovery, and finally Post-Incident Activity (Lessons Learned).

55
Multi-Selectmedium

An architect is deploying Cortex XDR Broker VMs in a DMZ architecture. Which TWO network requirements must be satisfied for successful operation? (Choose two)

Select 2 answers
A.Inbound syslog or SNMP trap connectivity from local log sources
B.Inbound RDP access from public internet IP addresses
C.Direct database replication port 5432 to external client workstations
D.Outbound HTTPS (TCP port 443) connectivity to the Cortex XDR cloud tenant
E.Unencrypted FTP access for configuration file uploads
AnswersA, D

Log sources must be able to send syslog/SNMP data to the Broker VM.

Why this answer

Broker VMs require outbound HTTPS access to the Cortex cloud and inbound connectivity from log sources.

56
MCQhard

An architect is designing an integration between Cortex XDR and an existing third-party SIEM. The requirement is to forward all raw and enriched Cortex XDR incidents and alerts in real time. Which architectural mechanism should be configured within Cortex XDR?

A.Configure an explicit proxy on Panorama to intercept XDR database traffic and mirror it to the SIEM.
B.Install a dedicated firewall between the XDR agent and the cloud backend to sniff telemetry.
C.Deploy an SNMP trap receiver on the SIEM and enable SNMPv1 polling on the XDR agent.
D.Configure a Syslog Server profile or Cortex XDR Streaming API connector to export log data in CEF or JSON format.
AnswerD

Cortex XDR allows integration via Streaming API or Syslog output profiles to forward logs/incidents to third-party SIEMs.

Why this answer

Cortex XDR supports forwarding alerts and incidents to third-party SIEMs using Syslog or HTTP/HTTPS via a configured Cortex XDR Streaming API or Syslog Collector profile.

57
Multi-Selectmedium

An architect is configuring User-ID mapping on a Palo Alto Networks firewall. Which TWO methods can be used to map IP addresses to usernames in environments where Active Directory is not present? (Choose two)

Select 2 answers
A.Manually editing the firewall BIOS clock.
B.SNMP polling of unmanaged switch ARP tables without authentication.
C.Direct NetBIOS password hash cracking on remote workstations.
D.GlobalProtect client connections which report username and IP upon login.
E.Captive Portal prompting users for credentials when accessing HTTP/HTTPS web traffic.
AnswersD, E

GlobalProtect provides direct user mapping regardless of AD presence.

Why this answer

In non-AD environments, User-ID can be mapped using Captive Portal, GlobalProtect, Syslog parsing from proxies/DHCP, or XML API calls.

58
MCQmedium

An architect is configuring Panorama to collect logs from 200 managed firewalls. The log volume exceeds the storage capacity of a single Panorama virtual appliance. Which architectural design should the architect implement to scale log collection?

A.Deploy dedicated Panorama Collector appliances and configure Collector Groups to distribute log ingestion.
B.Route all logs through the firewall management interface via FTP.
C.Delete traffic logs on all firewalls every 5 minutes.
D.Configure GlobalProtect portals to store log databases locally on user laptops.
AnswerA

Collector Groups scale log collection capacity across multiple Panorama collector nodes.

Why this answer

Collector Groups in Panorama allow scaling log collection by grouping dedicated Panorama Collector appliances or virtual appliances to ingest logs from assigned firewalls.

59
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to inspect traffic for spyware callback communications to command-and-control servers. Which security profile should be configured?

A.URL Filtering profile
B.Anti-Spyware security profile
C.Data Filtering profile
D.WildFire analysis profile
AnswerB

Anti-Spyware profiles detect and block spyware callbacks and C2 communications.

Why this answer

Anti-Spyware profiles inspect traffic for known spyware signatures and command-and-control (C2) communication patterns.

60
MCQmedium

An architect is configuring Indicator Sharing in Cortex XSOAR using the Threat Intel Management module. How are incoming STIX/TAXII indicator feeds prioritized when conflicting reputation scores are received from multiple sources?

A.Alphabetical sorting of feed names
B.Manual override for every single indicator
C.First-in, first-out ingestion timestamp priority
D.By configuring source reliability and vendor weight settings
AnswerD

Source reliability and vendor weights dictate how conflicting scores are resolved.

Why this answer

Threat Intel Management in XSOAR uses indicator scoring rules and source reliability weights to determine the final composite score.

61
MCQmedium

You are configuring Cortex XSOAR integration instances and need to ensure that API keys and passwords are stored securely without appearing in plaintext within playbook logs or incident data. Where should these credentials be stored?

A.Inside public incident context data fields
B.Hardcoded in custom Python automation scripts
C.As encrypted integration parameters / Vault-managed credentials
D.Plaintext in the playbook YAML file
AnswerC

Integration parameters configured as credentials are encrypted and masked.

Why this answer

Integration credentials in Cortex XSOAR should be stored as encrypted integration parameters (credentials type) managed by the platform vault.

62
MCQhard

An architect is setting up continuous monitoring of SOC performance metrics in Cortex XSIAM. They want to ensure that incident backlog growth is detected before it impacts analyst morale and SLA compliance. Which derived metric should be established?

A.Cortex XDR License Expiration Countdown
B.Net Backlog Growth Rate (Incoming Incidents minus Resolved Incidents over time)
C.WildFire Sample Submission Latency
D.Total Endpoint Disk Capacity Utilization
AnswerB

Tracking the net difference between created and closed incidents identifies backlog accumulation before SLAs are breached.

Why this answer

Backlog Growth Rate (or Net Incident Intake Rate vs. Resolution Rate) tracks whether incoming incident volume outpaces resolution capacity over a rolling window.

63
MCQhard

An enterprise security architect is designing an automated threat response architecture using Cortex XSOAR. The design requires parsing unstructured phishing emails received in a dedicated mailbox. Which XSOAR capability should be leveraged to automatically extract indicators such as URLs, file hashes, and sender domains from the email body?

A.Cortex XDR file quarantine policy engine
B.Minemeld RSS feed collector
C.PAN-OS WildFire sandbox detonation queue
D.Phishing parser and indicator extraction engines
AnswerD

Correct. Phishing parsers automatically parse email headers and bodies to extract IOCs for automated enrichment.

Why this answer

Cortex XSOAR utilizes built-in email parsing parsers and regex-based extraction mechanisms, often enhanced by parsers within the Phishing integration pack, to extract indicators.

64
MCQhard

An organization utilizing Prisma Cloud calculates Mean Time to Remediate (MTTR) for cloud misconfigurations. The SecOps team notices that the baseline MTTR is heavily skewed by a small number of lingering legacy assets. Which statistical approach should the architect recommend to executive management to provide a more accurate representation of typical remediation performance?

A.Apply a logarithmic transformation to the incident timestamps before calculating the mean
B.Report the arithmetic mean alongside standard deviation
C.Transition reporting from the mean to the median remediation time
D.Exclude all assets older than 90 days from the telemetry database
AnswerC

The median represents the midpoint of the dataset and is resilient against extreme outlier values.

Why this answer

Using the median instead of the mean prevents skewed metrics caused by extreme outliers like lingering legacy assets.

65
MCQmedium

A SOC architect is integrating Cortex XSOAR with Palo Alto Networks Cortex XDR to automate the triage of high-severity alerts. Which specific architecture component should be configured to ensure seamless bi-directional incident synchronization and automated playbook execution?

A.Prisma Access Remote Network Connector
B.AutoFocus Tag Synchronizer
C.Cortex XSOAR Content Pack for Cortex XDR
D.Minemeld Global Feed Engine
AnswerC

Correct. The official Content Pack provides the integration commands and automation scripts needed for bi-directional synchronization.

Why this answer

The Cortex XSOAR integration utilizes the Cortex XDR incident management APIs via an instance-configured integration to fetch incidents, update statuses, and run playbooks.

66
Multi-Selectmedium

When configuring role-based access control (RBAC) in Cortex XSOAR for an Incident Response team, which TWO permissions can be assigned to restrict unauthorized modifications? (Choose two)

Select 2 answers
A.Allow Incident Deletion
B.Allow Kernel Module Loading
C.Allow Server Configuration Edits
D.Allow BIOS Firmware Flashing
E.Allow Local Firewall Port Opening
AnswersA, C

Incident deletion permission restricts who can remove sensitive incident records.

Why this answer

RBAC in Cortex XSOAR allows granular control over incident deletion, settings modification, and script execution.

67
Multi-Selectmedium

An architect is troubleshooting a Panorama deployment where managed firewalls show a 'Disconnected' status in the Panorama GUI. Which TWO connectivity requirements should the architect verify? (Choose two)

Select 2 answers
A.Check the physical color of the office carpet near the server rack.
B.Verify the HDMI cable connection on the firewall console port.
C.Verify that TCP port 3978 (Panorama SSL/TLS communication) is open and not blocked by intermediate firewalls or security groups.
D.Check if the user desktop browser has JavaScript enabled.
E.Verify that the firewall management IP address can successfully reach the Panorama management IP address.
AnswersC, E

Panorama management communication requires TCP port 3978.

Why this answer

Firewalls and Panorama communicate management traffic over TCP port 3978 (SSL/TLS). Verifying network routing, firewall rules, and management interface reachability is crucial.

68
MCQeasy

An architect is configuring Panorama to manage software and content updates across an enterprise fleet of firewalls. To prevent untested dynamic updates (such as Antivirus and WildFire signatures) from breaking production traffic, what is the best practice deployment design in Panorama?

A.Disable all dynamic updates permanently to ensure zero changes.
B.Configure a deployment schedule in Panorama that pushes updates to a test device group first before rolling out to production device groups.
C.Configure firewalls to download updates directly from the public internet without Panorama oversight.
D.Apply updates only during the annual firewall maintenance window.
AnswerB

Staged rollout via device groups ensures stability by testing updates on non-production firewalls first.

Why this answer

Dynamic update schedules in Panorama should use a staging or delayed deployment group strategy rather than applying updates immediately across all firewalls.

69
MCQhard

An architect is evaluating the effectiveness of alert tuning in Cortex XSIAM. Over three months, the total alert volume decreased by 40%, but the number of confirmed breaches detected remained constant. Which metric combination best validates that this tuning was successful and did not introduce blind spots?

A.Increased overall log ingestion volume and higher CPU utilization on endpoints
B.Higher analyst turnover rate and increased playbook execution duration
C.Decreased False Positive Rate combined with stable True Positive detection counts and low MTTD
D.Greater frequency of firewall rule updates and increased bandwidth consumption
AnswerC

A falling false positive rate alongside steady true positive detections proves that noise was eliminated without creating detection blind spots.

Why this answer

Successful tuning reduces false positives without missing true positives. Validating this requires monitoring the False Positive Rate (dropping) alongside Incident Detection Rate or confirmed breach volume (remaining stable or increasing) and low Mean Time to Detect.

70
MCQmedium

Your organization uses Cortex XSOAR to manage incident response. Management wants to ensure that high-priority incidents do not breach internal SLAs. Where should an architect configure notifications or escalations when an incident approaches its SLA threshold?

A.Through WildFire cloud-based detonation configuration menus
B.Within Incident Type SLA settings and associated automation triggers
C.Inside the Cortex XDR agent installation package parameters
D.Via Panorama firewall administrative access control lists
AnswerB

SLA settings in Cortex XSOAR allow defining warning thresholds and automated escalation actions upon nearing breach.

Why this answer

In Cortex XSOAR, SLAs are configured within incident types or SLA definitions, and automated tasks or SLA-based triggers can send notifications or run escalation playbooks when thresholds are neared or breached.

71
MCQmedium

You are presenting security metrics to executive management using Cortex XSIAM dashboards. Leadership expresses concern over an apparent increase in malware detection events month-over-month. As a SecOps Architect, how should you contextualize this trend?

A.Contextualize the trend by demonstrating how expanded sensor coverage and improved detection visibility account for the rise in detections, while noting that successful compromises have decreased.
B.Blame the endpoint users for generating malware and increase disciplinary actions.
C.Confirm that the enterprise security posture is actively degrading and recommend cutting off all external internet access.
D.Disable the specific Cortex XDR analytics rules generating the malware alerts to lower the reported count.
AnswerA

Proper reporting contextualizes raw event counts with visibility improvements and actual downstream compromise rates.

Why this answer

An increase in detected events often reflects improved visibility and broader sensor deployment (e.g., onboarding new log sources or endpoints) rather than a direct increase in actual organizational risk.

72
MCQmedium

An architect is integrating Cortex XSOAR with Palo Alto Networks Panorama to automate firewall rule creation. A playbook needs to check if a security policy rule already exists before creating a new one. Which Cortex XSOAR integration command should the architect use to query the existing rules on Panorama?

A.xdr-get-firewall-rules
B.panorama-list-policies
C.pan-os-get-security-rules
D.fw-query-rules
AnswerC

The pan-os-get-security-rules command queries Panorama or NGFW for existing security rules.

Why this answer

The PAN-OS integration in Cortex XSOAR provides specific API wrapper commands. To check rules, the panoramic or PAN-OS integration uses commands like pan-os-get-security-rules.

73
MCQeasy

An architect is configuring a Palo Alto Networks firewall and wants to inspect compressed or archived files (such as .zip or .tar files) for embedded malware. Which security profile feature enables this inspection?

A.Zone Protection profile with SYN cookies.
B.Antivirus and File Blocking profiles configured with archive unpacking enabled.
C.URL Filtering profile with SSL decryption disabled.
D.DNS Security service sinkhole.
AnswerB

Archive unpacking allows security profiles to inspect files hidden inside compressed archives.

Why this answer

File Blocking and Antivirus profiles support archive unpacking (decompression) to inspect nested files within archives.

74
MCQmedium

An architect is designing an architecture where a Palo Alto Networks firewall receives threat intelligence feeds from external sources in STIX/TAXII format. Which feature on the firewall enables direct ingestion of these customized threat feeds?

A.GlobalProtect HIP object database.
B.External Dynamic Lists (EDLs) configured to poll a TAXII server or URL list.
C.Syslog server forwarding profile.
D.Panorama Device Group Static Address Objects.
AnswerB

EDLs allow dynamic importing of indicator feeds into firewall security policies.

Why this answer

External Dynamic Lists (EDLs) allow firewalls to consume IP addresses, domains, or URLs directly from web servers or STIX/TAXII servers.

75
MCQeasy

An architect is designing a Palo Alto Networks firewall deployment and wants to ensure that security policies are enforced based on applications rather than port numbers. Which core Palo Alto Networks technology achieves this?

A.App-ID application identification engine
B.Static TCP port filtering tables
C.DNS reverse lookup cache
D.MAC address table lookup
AnswerA

App-ID identifies applications accurately regardless of port or protocol.

Why this answer

App-ID is Palo Alto Networks core signature- and heuristic-based application identification engine.

Page 1 of 3

Page 2

All pages