Courseiva

CCNA Secops Frameworks And Threat Response Architecture Questions

65 questions · Secops Frameworks And Threat Response Architecture · All types, answers revealed

1
Multi-Selectmedium

An architect is planning the deployment of Cortex XDR agents across a heterogeneous enterprise environment. Which TWO deployment methods are officially supported? (Choose two)

Select 2 answers
A.Embedding the agent installer inside public spam email attachments
B.Active Directory Group Policy Object (GPO) deployment
C.Manual floppy disk installation on every workstation
D.Centralized endpoint management tools (e.g., Microsoft Intune, SCCM, Jamf)
E.Mailing unencrypted USB flash drives to employees' home addresses
AnswersB, D

GPO is a standard enterprise method for deploying Windows software.

Why this answer

Cortex XDR agents can be deployed via Active Directory Group Policy (GPO) or centralized endpoint management tools like SCCM/Intune.

2
MCQeasy

When designing a threat hunting methodology aligned with the MITRE ATT&CK framework, an architect wants to identify adversary persistence mechanisms. Which tactic category should the analyst focus queries on?

A.Initial Access
B.Persistence
C.Collection
D.Execution
AnswerB

Persistence techniques allow adversaries to maintain access across restarts.

Why this answer

Persistence tactics include techniques such as Registry Run Keys, Startup Folder, and Scheduled Tasks.

3
Multi-Selecthard

An organization is building a Threat Intelligence Program aligned with the Diamond Model of Intrusion Analysis. Which THREE core vertices must be analyzed for every adversary event in the incident tracking database? (Choose three)

Select 3 answers
A.Capability (the tools and techniques used by the adversary)
B.Office HVAC cooling capacity metrics
C.Infrastructure (the physical or logical communication channels used)
D.Local cafeteria menu pricing structures
E.Adversary (the actor or organization responsible for the intrusion)
AnswersA, C, E

Correct. Capability represents the software, exploits, and techniques utilized.

Why this answer

The Diamond Model of Intrusion Analysis consists of four core vertices: Adversary, Capability, Infrastructure, and Victim.

4
Multi-Selectmedium

An architect is designing an incident response communications plan for a major data breach affecting regulated customer data. Which TWO stakeholder groups must typically be included in the formal communication escalation matrix during high-severity incidents? (Choose two)

Select 2 answers
A.Building facilities management team
B.Internal cafeteria catering staff
C.Third-party software vendors of unrelated office productivity tools
D.Corporate Communications / Public Relations
E.Legal Counsel / Privacy Officer
AnswersD, E

Correct. PR manages external messaging and brand protection during public-facing breaches.

Why this answer

During major data breaches, legal counsel and corporate communications/PR are critical stakeholders required for regulatory notification and public messaging governance.

5
MCQhard

An architect is deploying the Cortex XDR Broker VM to serve as a syslog collector for legacy network devices. The Broker VM loses connectivity to the Cortex XDR cloud. What happens to the collected syslog data during the outage?

A.The Broker VM automatically switches to backup SMTP forwarding
B.The syslog sender devices resend the packets automatically via TCP retry
C.The data is permanently dropped until connectivity returns
D.The data is buffered locally on the Broker VM and forwarded once reconnected
AnswerD

Local buffering ensures no log loss during brief network outages.

Why this answer

The Broker VM buffers incoming syslog messages locally up to a designated storage threshold until cloud connectivity is restored.

6
Multi-Selectmedium

An architect is configuring role-based access control (RBAC) in Cortex XSIAM for a multi-tenant SOC environment. Which TWO principles should guide the design of security analyst roles? (Choose three - wait, prompt says Which TWO for multi_select half. Let's provide TWO). Which TWO principles should guide the design of security analyst roles? (Choose two)

Select 2 answers
A.Principle of least privilege (granting only necessary permissions for job functions)
B.Sharing a single root administrator account across the entire global SOC team
C.Assigning full Super Administrator privileges to all Tier 1 analysts to accelerate triage
D.Disabling audit logging for administrator actions to save disk space
E.Segregation of duties between incident responders and system administrators
AnswersA, E

Correct. Least privilege limits exposure if an account is compromised.

Why this answer

RBAC design in SOC environments should adhere to the principle of least privilege and role-based segregation of duties between triage analysts and administrators.

7
MCQmedium

You are designing an automated phishing response workflow in Cortex XSOAR. The playbook needs to extract all URLs from an incoming email body and check their reputation using VirusTotal. Which built-in task type should you use to evaluate each URL concurrently?

A.Loop / For-Each Task
B.Data Collection Task
C.Transformation Script Task
D.Manual Review Task
AnswerA

A loop task processes each item in an extracted list of URLs.

Why this answer

A loop task in Cortex XSOAR iterates over lists or arrays, such as extracted URLs, allowing parallel or sequential processing.

8
MCQeasy

When designing a threat hunting architecture, an architect must differentiate between indicator-based searching and hypothesis-driven hunting. Which approach represents a hypothesis-driven threat hunt?

A.Blocking known malicious domains using PAN-OS DNS Security
B.Automating the ingestion of STIX/TAXII feeds into Cortex XSOAR
C.Searching for specific file hashes provided in a recent vendor threat intelligence report
D.Developing a query to detect potential lateral movement using PowerShell remoting based on recent red team exercises
AnswerD

Correct. This starts with a specific behavioral hypothesis derived from TTPs.

Why this answer

Hypothesis-driven hunting starts with a theory about potential adversary behavior or TTPs and uses analytics to search for undiscovered activity.

9
Multi-Selecthard

An organization is integrating Cortex XSIAM with third-party security tools for automated remediation. Which THREE mechanisms are supported for triggering external actions from XSIAM/XSOAR? (Choose three)

Select 3 answers
A.Leveraging Python automation scripts using the Demisto/XSOAR API library
B.Direct physical rewiring of Ethernet patch panels
C.Executing integration commands within playbooks
D.Calling external webhooks via HTTP Request automation scripts
E.Inserting punch cards into magnetic readers
AnswersA, C, D

Python scripts can invoke external APIs and custom logic.

Why this answer

Actions can be triggered via REST APIs, SDKs, and built-in integration commands.

10
MCQmedium

An architect is designing an integration between Cortex XSOAR and a third-party ticketing system (e.g., ServiceNow). The requirement is to ensure that when an incident severity is updated in XSOAR, the ticket in ServiceNow is automatically updated. Which architectural feature facilitates this synchronization?

A.Syslog forwarding over UDP port 514
B.Bi-directional incident field mapping and integration commands
C.PAN-OS Dynamic Address Group API push
D.GlobalProtect client certificate renewal protocol
AnswerB

Correct. Mapping rules and integration commands synchronize incident fields across platforms.

Why this answer

Bi-directional incident mapping and mapping rules in XSOAR integration instances allow field values to sync automatically between XSOAR and ticketing systems.

11
MCQeasy

An organization wants to measure the efficiency of its SOC by tracking how quickly analysts acknowledge incoming high-priority alerts. Which metric is being measured?

A.Mean Time to Detect (MTTD)
B.Mean Time to Acknowledge (MTA)
C.Mean Time Between Failures (MTBF)
D.Mean Time to Patch (MTTP)
AnswerB

MTA measures the time elapsed from alert generation to analyst acknowledgement.

Why this answer

Mean Time to Acknowledge (MTA) or Mean Time to Respond (MTTR) tracks acknowledgement and response speed.

12
MCQmedium

An architect is integrating Cortex XSIAM with ServiceNow to automatically create IT service management (ITSM) tickets when incidents are promoted. Where is the field mapping between Cortex XSIAM incident fields and ServiceNow incident fields configured?

A.ServiceNow Integration Instance Mapper configuration
B.Magnifier machine learning threshold slider
C.Syslog server forwarding configuration
D.Cortex XDR Agent policy settings
AnswerA

Instance mappers define incoming and outgoing field mappings between systems.

Why this answer

Incident fields and ITSM mapping in Cortex XSIAM/XSOAR are configured in the Incident Mirroring and Integrations mapping settings.

13
MCQhard

An enterprise security architect is designing high availability for Cortex XSOAR engines. If the primary engine fails, what mechanism ensures zero data loss and uninterrupted playbook execution for active incidents?

A.Periodic XML configuration exports via cron jobs
B.Automatic client-side browser caching of playbook states
C.Active-Active cluster architecture backed by external PostgreSQL and Redis
D.DNS round-robin load balancing between local SQLite storage files
AnswerC

External database and Redis clustering ensure state persistence and failover.

Why this answer

Cortex XSOAR high availability utilizes an active-passive or active-active cluster backed by an external PostgreSQL database and Redis data store.

14
Multi-Selecteasy

When designing an incident post-mortem (lessons learned) process following NIST guidelines, which TWO activities should the security architect mandate? (Choose two)

Select 2 answers
A.Conducting a root cause analysis review meeting with key stakeholders
B.Deleting all firewall and SIEM log archives immediately
C.Reverting all system configurations to factory defaults without review
D.Updating detection rules and SOAR playbooks based on operational gaps identified
E.Publicly disclosing employee disciplinary actions on social media
AnswersA, D

Correct. Analyzing how the incident occurred and how response was handled is vital for improvement.

Why this answer

Post-incident activities include conducting a root cause analysis meeting, documenting lessons learned, updating playbooks, and improving detection rules.

15
MCQmedium

A security architect is designing an incident escalation matrix for a multinational SOC. Which metric is most critical to measure the effectiveness of the Tier 1 triage team before escalating incidents to Tier 2?

A.Mean Time to Acknowledge (MTTA) and Triage accuracy
B.Number of global security patents filed
C.Mean Time to Patch (MTTP)
D.Total volume of firewall rules configured
AnswerA

Correct. MTTA and triage accuracy measure the speed and precision of initial alert handling.

Why this answer

Mean Time to Triage (MTTT) or Mean Time to Acknowledge (MTTA) measures how quickly Tier 1 processes and validates incoming alerts before escalating.

16
MCQhard

An architect is designing an enterprise threat hunting program utilizing Cortex XSIAM. They want to create a custom analytics rule that triggers when a specific sequence of three distinct event types occurs within a 10-minute window on the same endpoint. Which feature should be used?

A.Static IP Blocklist configuration
B.XSOAR Email Parsing Rules
C.Cortex XDR Agent Local Analysis settings
D.XQL Correlation Rules (Sequence matching)
AnswerD

XQL correlation rules support sequence matching across time windows.

Why this answer

Data Stitching and XQL correlation rules allow multi-event sequence detection across datasets and time windows.

17
Multi-Selecteasy

When designing a Security Operations Center (SOC) using the NIST cybersecurity framework, which TWO functions are categorized under the 'Detect' core function? (Choose two)

Select 2 answers
A.Disaster Recovery plan execution
B.Incident Recovery Planning
C.Security Continuous Monitoring (SCM)
D.Access Control policy enforcement
E.Detection Processes and Procedures
AnswersC, E

Correct. Continuous monitoring is a core component of the Detect function.

Why this answer

The NIST CSF 'Detect' function includes Anomalies and Events, Security Continuous Monitoring, and Detection Processes.

18
MCQeasy

Which role in a well-structured Security Operations Center (SOC) is primarily responsible for performing tier-2 incident triage, deep investigation, and playbook execution?

A.Compliance Auditor
B.Chief Information Security Officer (CISO)
C.SOC Tier-2 Analyst / Incident Responder
D.Helpdesk Support Technician
AnswerC

Tier-2 analysts investigate complex alerts escalated from Tier-1.

Why this answer

Tier-2 analysts handle escalated alerts requiring deeper investigation and active remediation.

19
MCQhard

An enterprise security architect is designing data residency compliance controls for Cortex XSIAM. European Union customer data must not leave the EU region. Where is data residency enforced in Cortex XSIAM?

A.By configuring log filtering rules in XSOAR playbooks
B.By enabling TLS 1.3 encryption on the Broker VM
C.By selecting the appropriate EU-hosted cloud tenant region during initial tenant provisioning
D.By setting local registry keys on each Windows endpoint agent
AnswerC

Tenant provisioning region dictates storage and processing location.

Why this answer

Data residency is determined by the geographic location of the tenant tenant cluster provisioned during onboarding.

20
MCQeasy

An architect is designing an incident response lifecycle based on the NIST SP 800-61 framework for a Security Operations Center (SOC). Which phase immediately follows the Containment, Eradication, and Recovery phase?

A.Detection and Analysis
B.Post-Incident Activity
C.Threat Intelligence Enrichment
D.Risk Assessment
AnswerB

Correct. Post-Incident Activity (often called Lessons Learned) is the final phase of the NIST incident response lifecycle.

Why this answer

According to NIST SP 800-61, the lifecycle phases are Preparation, Detection and Analysis, Containment, Eradication, and Recovery, and finally Post-Incident Activity (Lessons Learned).

21
Multi-Selectmedium

An architect is deploying Cortex XDR Broker VMs in a DMZ architecture. Which TWO network requirements must be satisfied for successful operation? (Choose two)

Select 2 answers
A.Inbound syslog or SNMP trap connectivity from local log sources
B.Inbound RDP access from public internet IP addresses
C.Direct database replication port 5432 to external client workstations
D.Outbound HTTPS (TCP port 443) connectivity to the Cortex XDR cloud tenant
E.Unencrypted FTP access for configuration file uploads
AnswersA, D

Log sources must be able to send syslog/SNMP data to the Broker VM.

Why this answer

Broker VMs require outbound HTTPS access to the Cortex cloud and inbound connectivity from log sources.

22
MCQmedium

An architect is configuring Indicator Sharing in Cortex XSOAR using the Threat Intel Management module. How are incoming STIX/TAXII indicator feeds prioritized when conflicting reputation scores are received from multiple sources?

A.Alphabetical sorting of feed names
B.Manual override for every single indicator
C.First-in, first-out ingestion timestamp priority
D.By configuring source reliability and vendor weight settings
AnswerD

Source reliability and vendor weights dictate how conflicting scores are resolved.

Why this answer

Threat Intel Management in XSOAR uses indicator scoring rules and source reliability weights to determine the final composite score.

23
MCQmedium

You are configuring Cortex XSOAR integration instances and need to ensure that API keys and passwords are stored securely without appearing in plaintext within playbook logs or incident data. Where should these credentials be stored?

A.Inside public incident context data fields
B.Hardcoded in custom Python automation scripts
C.As encrypted integration parameters / Vault-managed credentials
D.Plaintext in the playbook YAML file
AnswerC

Integration parameters configured as credentials are encrypted and masked.

Why this answer

Integration credentials in Cortex XSOAR should be stored as encrypted integration parameters (credentials type) managed by the platform vault.

24
MCQhard

An enterprise security architect is designing an automated threat response architecture using Cortex XSOAR. The design requires parsing unstructured phishing emails received in a dedicated mailbox. Which XSOAR capability should be leveraged to automatically extract indicators such as URLs, file hashes, and sender domains from the email body?

A.Cortex XDR file quarantine policy engine
B.Minemeld RSS feed collector
C.PAN-OS WildFire sandbox detonation queue
D.Phishing parser and indicator extraction engines
AnswerD

Correct. Phishing parsers automatically parse email headers and bodies to extract IOCs for automated enrichment.

Why this answer

Cortex XSOAR utilizes built-in email parsing parsers and regex-based extraction mechanisms, often enhanced by parsers within the Phishing integration pack, to extract indicators.

25
MCQmedium

A SOC architect is integrating Cortex XSOAR with Palo Alto Networks Cortex XDR to automate the triage of high-severity alerts. Which specific architecture component should be configured to ensure seamless bi-directional incident synchronization and automated playbook execution?

A.Prisma Access Remote Network Connector
B.AutoFocus Tag Synchronizer
C.Cortex XSOAR Content Pack for Cortex XDR
D.Minemeld Global Feed Engine
AnswerC

Correct. The official Content Pack provides the integration commands and automation scripts needed for bi-directional synchronization.

Why this answer

The Cortex XSOAR integration utilizes the Cortex XDR incident management APIs via an instance-configured integration to fetch incidents, update statuses, and run playbooks.

26
Multi-Selectmedium

When configuring role-based access control (RBAC) in Cortex XSOAR for an Incident Response team, which TWO permissions can be assigned to restrict unauthorized modifications? (Choose two)

Select 2 answers
A.Allow Incident Deletion
B.Allow Kernel Module Loading
C.Allow Server Configuration Edits
D.Allow BIOS Firmware Flashing
E.Allow Local Firewall Port Opening
AnswersA, C

Incident deletion permission restricts who can remove sensitive incident records.

Why this answer

RBAC in Cortex XSOAR allows granular control over incident deletion, settings modification, and script execution.

27
MCQeasy

When planning an incident response table-top exercise for a Security Operations team, which framework provides a standardized taxonomy for describing adversary behaviors and tactics?

A.PCI-DSS v4.0
B.ITIL v4 Service Management
C.ISO/IEC 27001
D.MITRE ATT&CK Framework
AnswerD

MITRE ATT&CK provides standard terminology for adversary techniques.

Why this answer

MITRE ATT&CK provides a comprehensive matrix of adversary tactics and techniques.

28
MCQhard

An architect is designing a multi-region threat intelligence sharing architecture using Cortex XSOAR. They need to synchronize indicators across independent regional XSOAR instances without creating circular loops. Which protocol and architecture pattern should be implemented?

A.Direct database replication of the internal SQLite tables
B.TAXII 2.1 Server and Client integration feeds across instances
C.Unencrypted FTP file drops of CSV indicator lists
D.Raw Syslog forwarding of indicator JSON blobs
AnswerB

TAXII 2.1 standardizes federated threat intelligence sharing.

Why this answer

TAXII (Trusted Automated Exchange of Intelligence Information) client-server architecture is standard for federated indicator sharing.

29
MCQhard

An enterprise security architect is configuring automated threat intelligence sharing between Cortex XSOAR and external ISACs using STIX/TAXII. Which component within Cortex XSOAR is primarily responsible for managing incoming threat indicators, deduplication, and indicator scoring?

A.Cortex XDR Analytics Engine
B.Incident Investigation Canvas
C.Threat Intelligence Management (TIM) module
D.Machine Learning Service Broker
AnswerC

Correct. TIM provides centralized indicator lifecycle management, scoring, and bidirectional sharing.

Why this answer

The Threat Intelligence Management (TIM) module within Cortex XSOAR handles indicator lifecycle management, deduplication, scoring, and propagation to enforcement points.

30
MCQeasy

During a major security incident, a SOC architect needs to ensure that all evidence collected adheres to chain of custody principles. Which foundational security concept is primarily being enforced?

A.High availability and redundant storage arrays
B.Integrity and non-repudiation of digital evidence
C.Role-based access control permission inheritance
D.Network bandwidth optimization and traffic shaping
AnswerB

Correct. Maintaining evidence integrity and documenting handling ensures it remains legally admissible.

Why this answer

Chain of custody ensures that evidence is collected, handled, analyzed, and preserved in a manner that maintains its integrity and admissibility in legal proceedings.

31
MCQeasy

An architect is designing a Zero Trust Network Access (ZTNA) incident response strategy using Prisma Access. When a compromised user device is detected, which action should the automated response workflow trigger to prevent lateral movement?

A.Purge the corporate DNS root servers
B.Apply a dynamic user group or quarantine security policy to immediately revoke network access
C.Factory reset the physical core switches
D.Reboot all enterprise domain controllers
AnswerB

Correct. Dynamic user groups and policy enforcement in Prisma Access allow immediate isolation of compromised sessions.

Why this answer

Prisma Access allows administrators to dynamically quarantine or restrict access for compromised users or devices by modifying security rules or session states.

32
MCQmedium

An architect is designing an automated containment workflow in Cortex XSOAR. The requirement is to isolate a compromised endpoint running Cortex XDR agent without disrupting critical domain controllers. Which configuration parameter must be validated in the isolation command?

A.Exclusion lists and targeted device IDs to prevent critical asset isolation
B.PAN-OS external dynamic list expiration timers
C.Global firewall rule bypass codes
D.Syslog forwarding facility levels
AnswerA

Correct. Proper targeting and exclusion verification ensure critical infrastructure remains accessible.

Why this answer

When executing endpoint isolation in Cortex XDR via XSOAR, the architect must ensure exceptions or proper scoping are applied to prevent isolating essential infrastructure like Domain Controllers.

33
Multi-Selecthard

An architect is designing an enterprise incident response communication plan. Which THREE components are critical for effective operational coordination during a major security incident? (Choose three)

Select 3 answers
A.Pre-defined stakeholder and legal notification escalation trees
B.Centralized incident war room / ticketing audit trail
C.Secure out-of-band communication channels for incident responders
D.Publicly posting all unredacted forensic disk images on social media
E.Disabling all documentation to maintain total secrecy
AnswersA, B, C

Escalation trees ensure timely reporting to legal, PR, and executive leadership.

Why this answer

Effective operational coordination requires secure communication channels, stakeholder notification trees, and centralized logging.

34
Multi-Selecthard

An enterprise security architect is reviewing threat detection coverage using the MITRE ATT&CK Navigator. Which THREE strategic objectives can be achieved using this exercise? (Choose three)

Select 3 answers
A.Identifying detection gaps and blind spots across security monitoring tools
B.Mapping existing SIEM/XSIAM analytics rules to specific adversary techniques
C.Prioritizing security telemetry and detection engineering investments
D.Automatically overclocking enterprise workstation CPUs
E.Configuring static IP addresses on firewall interfaces
AnswersA, B, C

Visualizing coverage highlights unmonitored adversary techniques.

Why this answer

MITRE ATT&CK Navigator helps identify detection gaps, prioritize security investments, and map telemetry coverage.

35
MCQmedium

You are configuring log ingestion in Cortex XSIAM from a third-party firewall using a generic syslog collector. The logs are arriving, but the parser is failing to extract destination IP addresses correctly. What is the recommended troubleshooting step?

A.Modify or create a custom XDM parsing rule for the vendor log format
B.Increase the Syslog port number from 514 to 6514
C.Disable Magnifier behavioral analytics
D.Reinstall the Cortex XDR agent on the third-party firewall
AnswerA

Custom parsing rules correct extraction errors for unsupported log formats.

Why this answer

Custom parsing rules in XSIAM can be created or adjusted using XDM mapping tools to correctly parse non-standard log formats.

36
Multi-Selecthard

An architect is designing an automated threat intelligence enrichment pipeline in Cortex XSOAR. Which THREE actions are typically performed during indicator lifecycle management? (Choose three)

Select 3 answers
A.Physically replacing the server motherboard every 90 days
B.Correlating and calculating composite reputation scores across multiple sources
C.Ingesting indicators from structured STIX/TAXII feeds
D.Automatically expiring or aging out stale indicators based on TTL
E.Manually recompiling the Linux kernel for every IOC added
AnswersB, C, D

Reputation scoring merges multi-vendor intelligence into a reliable score.

Why this answer

Indicator lifecycle management involves ingestion, reputation scoring, expiration, and sharing or blocking.

37
MCQhard

An enterprise is designing a zero-trust architecture where Cortex XDR integrates with Palo Alto Networks Next-Generation Firewalls. Which protocol and component facilitate real-time dynamic blocklisting of compromised endpoints across both the firewall and the endpoint?

A.Syslog forwarding from firewalls to the local endpoint agent
B.SNMP traps sent from endpoints to the firewall management plane
C.Cortex XDR incident handler pushing dynamic IP/URL lists to firewalls via PAN-OS API
D.User-ID agent querying Active Directory via LDAP
AnswerC

Cortex XDR integrates with PAN-OS to update dynamic address groups or EDL lists.

Why this answer

The Cortex XDR enforcement service pushes dynamic block lists (EDL / IP lists) via XML API or PAN-OS integration to the firewalls.

38
MCQhard

An enterprise security architect is integrating Cortex XSIAM with an external SIEM using the Syslog Export feature. The security team notices that certain sensitive fields need to be redacted before export. Where should the architect configure this transformation?

A.Magnifier machine learning configuration
B.Cortex XDR Agent installation parameters
C.Data Forwarding Rules / Log Forwarding Profiles
D.XSOAR automation playbook script tasks
AnswerC

Log forwarding profiles allow filtering and masking before export.

Why this answer

Log Forwarding profiles in Cortex XSIAM allow filtering, masking, and transforming logs before they are exported via Syslog or HTTP.

39
Multi-Selectmedium

When configuring Cortex XSOAR incident classification and mapping, which TWO elements must be defined for an incoming alert type? (Choose two)

Select 2 answers
A.Field mapping schema between incoming alerts and XSOAR incident fields
B.Physical server CPU core allocation
C.Associated default playbook
D.Endpoint BIOS vendor name
E.Local printer queue ID
AnswersA, C

Field mapping ensures alert data populates the correct incident fields.

Why this answer

Incident types require mapping schemas and associated default playbooks.

40
MCQmedium

A security architect is establishing an operational metrics dashboard for executive leadership. Which metric best demonstrates the risk reduction impact of automated security orchestration and response (SOAR) playbooks?

A.Total number of raw logs ingested per second (EPS)
B.Mean Time to Respond (MTTR) / Containment Time
C.Average CPU utilization of the SIEM collector nodes
D.Number of security personnel trained on phishing awareness
AnswerB

Correct. MTTR measures how quickly security operations contain and remediate threats, directly reflecting SOAR value.

Why this answer

Mean Time to Respond (MTTR) or Containment Time directly shows how automation accelerates remediation and reduces organizational exposure time.

41
MCQeasy

Which framework is widely recognized as a comprehensive guideline for establishing a foundational cybersecurity program through five core functions: Identify, Protect, Detect, Respond, and Recover?

A.CIS Critical Security Controls
B.NIST Cybersecurity Framework (CSF)
C.ISO/IEC 27017
D.MITRE D3FEND
AnswerB

NIST CSF uses the Identify, Protect, Detect, Respond, and Recover functions.

Why this answer

The NIST Cybersecurity Framework (CSF) is structured around these five core functions.

42
MCQeasy

When aligning a security operations center (SOC) with the NIST Incident Response lifecycle, which phase immediately follows 'Containment, Eradication, and Recovery'?

A.Vulnerability Assessment
B.Triage and Scoping
C.Post-Incident Activity (Lessons Learned)
D.Threat Hunting
AnswerC

Lessons learned is the final phase of the NIST IR lifecycle.

Why this answer

The NIST SP 800-61 lifecycle phases are Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity (Lessons Learned).

43
MCQeasy

An architect is configuring log ingestion for Cortex XSIAM. Which native Palo Alto Networks collector type is designed to gather syslog and CEF formatted logs from third-party security devices without requiring an external forwarder VM?

A.Cortex XSIAM Broker VM
B.AutoFocus Cloud API connector
C.Panorama Management Server direct API
D.GlobalProtect Gateway agent
AnswerA

Correct. The Broker VM is deployed on-premises or in the cloud to collect and forward syslog, CEF, and other data sources to XSIAM.

Why this answer

Cortex XSIAM supports Cloud Identity Engine and Broker VM architectures, where the Broker VM acts as a local collector for syslog, SNMP, and other third-party formats.

44
Multi-Selecthard

An enterprise security architect is configuring Cortex XSIAM data ingestion and analytics. Which THREE data sources are essential for comprehensive endpoint and cloud threat detection? (Choose three)

Select 3 answers
A.Endpoint EDR telemetry (process execution, file modifications, network connections)
B.Local calculator application cache files
C.Cloud provider audit logs (AWS CloudTrail, Azure Activity Logs)
D.Local printer driver configuration backups
E.Network traffic flow logs and firewall security logs
AnswersA, C, E

Endpoint telemetry is core to XSIAM and XDR detection capabilities.

Why this answer

Comprehensive detection in XSIAM relies on endpoint telemetry, cloud audit logs, and network traffic data.

45
MCQhard

An organization wants to implement the MITRE ATT&CK framework into their threat detection engineering lifecycle within Cortex XSIAM. Which specific feature enables architects to map incoming telemetry and custom correlation rules directly to ATT&CK tactics and techniques to measure coverage?

A.ATT&CK Coverage Dashboard and Analytics Mapping
B.Panorama Dynamic Address Groups
C.AutoFocus Tagging Engine
D.Traps Agent Policy Editor
AnswerA

Correct. The ATT&CK Coverage dashboard in XSIAM provides direct visibility into technique mapping and detection gaps.

Why this answer

Cortex XSIAM includes a built-in MITRE ATT&CK matrix view that automatically maps triggered alerts and analytics rules to tactics and techniques to track coverage.

46
MCQmedium

In a multi-tenant Cortex XSOAR deployment, an architect needs to restrict access to specific playbooks so that Tenant A analysts cannot view or execute playbooks owned by Tenant B. Where is this access control configured?

A.Global Server Configuration settings
B.Role-Based Access Control (RBAC) settings under Settings > Common > Roles
C.Playbook JSON source code permissions
D.Integration instance parameters
AnswerB

RBAC allows granular control over what objects a role can access.

Why this answer

Role-Based Access Control (RBAC) in Cortex XSOAR allows restricting playbook and incident type visibility based on assigned roles.

47
Multi-Selecthard

An architect is designing a threat detection architecture using Cortex XSIAM analytics. Which THREE types of data sources are critical to ingest to provide comprehensive visibility for detecting lateral movement and credential dumping? (Choose three)

Select 3 answers
A.Active Directory / Authentication logs (e.g., Windows Security Event logs for Kerberos/NTLM)
B.Network traffic flow logs (e.g., PAN-OS Traffic and Threat logs)
C.Endpoint process execution and OS telemetry (e.g., Cortex XDR agent logs)
D.HVAC temperature and humidity sensor telemetry
E.Cafeteria POS terminal receipt printer error logs
AnswersA, B, C

Correct. AD logs reveal pass-the-hash, abnormal authentication spikes, and lateral movement.

Why this answer

Detecting lateral movement and credential dumping requires endpoint telemetry (process execution, LSASS access), authentication logs (Active Directory/Kerberos), and network flow/connection logs.

48
Multi-Selectmedium

An architect is designing an incident response automation strategy in Cortex XSOAR. Which TWO best practices should be followed when developing custom playbooks? (Choose two)

Select 2 answers
A.Implement robust error handling and conditional branching for integration failures
B.Execute all integration commands synchronously in a single monolithic task block
C.Hardcode API credentials directly inside Python script tasks for fast execution
D.Design modular sub-playbooks to handle repetitive sub-tasks and promote reusability
E.Disable incident context output to save database storage space
AnswersA, D

Error handling prevents playbooks from crashing when external APIs fail.

Why this answer

Playbooks should include proper error handling and modular sub-playbooks to maintain scalability and robustness.

49
MCQmedium

You are deploying Cortex XSIAM and need to ensure that endpoint logs collected from remote agents are normalized into a unified schema before analytics runs. Which feature performs this normalization?

A.Cortex XDR Agent Collector Engine
B.Magnifier behavioral analytics engine
C.Local Analysis Engine (LAE)
D.XDM (XDR Data Model) mapping and parsing rules
AnswerD

XDM maps raw fields into a unified schema for analytics.

Why this answer

XSIAM utilizes Agent Content and parsing rules to normalize raw logs into the XDM schema during ingestion.

50
MCQhard

An organization is integrating Prisma Cloud with Cortex XSOAR to automate cloud incident response. When configuring the Prisma Cloud integration instance in XSOAR, which authentication mechanism is recommended to securely fetch alerts without using static user credentials?

A.LDAP bind credentials through a Cortex XDR Broker VM
B.HTTP Basic Authentication with administrative credentials
C.OAuth 2.0 Client Credentials grant via a dedicated Service Account
D.SAML 2.0 Federation token exchange
AnswerC

Service accounts with generated access keys provide secure, non-user-tied authentication.

Why this answer

Prisma Cloud integration instances in XSOAR use Access Key ID and Secret Key generated via Service Accounts for secure API access.

51
MCQeasy

An incident response architect is defining severity levels for security alerts in Cortex XDR. Which severity classification typically triggers automated containment playbooks without human intervention?

A.Debugging
B.Low
C.Informational
D.Critical
AnswerD

Critical alerts often trigger immediate automated isolation or blocking.

Why this answer

High or Critical severity alerts are commonly mapped to automated containment responses in modern SOAR architectures.

52
MCQhard

An architect is designing an automated containment workflow in Cortex XDR where an endpoint must be isolated only if it is confirmed to be communicating with a known Command and Control (C2) server. Which XQL query logic accurately identifies this condition before triggering isolation?

A.dataset = xdr_data | filter alert_name = 'C2 Communication' and causal_agent_id != null | fields agent_id, C2_ip
B.dataset = endpoint_logs | summarize failed_logins = count() by user_name
C.dataset = xdr_data | filter event_type = 'network' and action = 'allowed' | stats count() by actor_process_image_path
D.dataset = network_traffic | filter bytes > 1000000
AnswerA

This query filters for confirmed C2 alerts associated with an active agent ID.

Why this answer

XQL queries aggregate alerts and network events to confirm C2 communication status before automated action.

53
MCQhard

An organization is adopting the Cyber Kill Chain framework to evaluate their intrusion detection capabilities across the network and endpoint layers. During which phase should security architects implement egress filtering and DNS sinkholing to disrupt adversary operations?

A.Reconnaissance
B.Command and Control (C2)
C.Exploitation
D.Installation
AnswerB

Correct. Disrupting communication channels targets the C2 phase of the Cyber Kill Chain.

Why this answer

Command and Control (C2) is the phase where the adversary establishes communication with their infrastructure. Egress filtering and DNS sinkholing are key controls to disrupt this phase.

54
MCQmedium

An architect is configuring automated containment in Cortex XSOAR where analyst approval is required before isolating an executive's laptop. Which task type in the playbook accomplishes this?

A.Syslog Export Task
B.Indicator Enrichment Task
C.Auto-Remediation Task
D.Approval Task (Prompt / Questionnaire task)
AnswerD

Approval tasks pause execution until an authorized user approves or denies the action.

Why this answer

A Data Collection or Manual/Approval task pauses the playbook and sends a notification for user input.

55
MCQeasy

An architect is designing an incident response workflow in Cortex XSOAR using the Incident Spooler. Which component is primarily responsible for processing queued events into actionable incidents?

A.Cortex XSOAR Server engine
B.Demisto REST API
C.Threat Intel Management module
D.Cortex XSIAM Data Lake collector
AnswerA

The core engine processes the spooler queue to create incidents.

Why this answer

The War Room is where manual actions and playbooks execute, but the Server engine handles the queue processing and ingestion from the Incident Spooler.

56
MCQhard

An architect is designing a threat hunting architecture that leverages Cortex XSIAM XQL (XDR Query Language). To identify potential living-off-the-land binaries (LotLB) execution, which query structure correctly filters process execution events for anomalous parent-child relationships?

A.search threat_intel where ip = '10.0.0.1' action = block
B.select * from syslog where facility = auth and action = drop
C.panos_log_generator --filter process_start --output xdr
D.dataset = xdr_data | filter event_type = 'PROCESS_START' and actor_process_image_name = 'winword.exe' and target_process_image_name = 'cmd.exe'
AnswerD

Correct. This XQL syntax correctly queries process start events where Word spawns the command prompt.

Why this answer

XQL queries in XSIAM use datasets like `dataset = xdr_data` with specific filtering commands (`| filter`) to examine process execution telemetry (e.g., cmd.exe spawned by winword.exe).

57
Multi-Selecthard

An architect is designing an automated threat hunting and containment architecture with Cortex XSIAM. Which THREE actions can be triggered automatically upon confirming a high-fidelity behavioral threat detection? (Choose three)

Select 3 answers
A.Physically disconnecting all power cables in the data center
B.Revoking user session tokens and triggering password resets in Active Directory / Azure AD
C.Formatting the corporate intranet web server hard drives
D.Publishing malicious indicators to dynamic blocklists on network firewalls
E.Isolating the compromised endpoint from the network via Cortex XDR agent
AnswersB, D, E

Compromised user accounts can be remediated automatically via SOAR/XSIAM integration.

Why this answer

Automated actions can include endpoint isolation, user password resets, and firewall blocklists.

58
Multi-Selectmedium

When designing a threat hunting architecture using XQL in Cortex XSIAM, which TWO best practices improve query performance and efficiency? (Choose two)

Select 2 answers
A.Use indexed fields and precise matching operators where possible
B.Filter by specific datasets and narrow time ranges early in the query
C.Run unbounded queries across all historical data without time constraints
D.Avoid using aggregation functions like count or summarize
E.Select all raw unparsed logs and avoid using specific field names
AnswersA, B

Indexed fields speed up search and aggregation execution.

Why this answer

Filtering early by dataset and time range significantly improves XQL query performance.

59
MCQeasy

An architect is reviewing the Cortex XSIAM Analytics dashboard to identify root causes of security incidents. Which data visualization component aggregates related alerts into a single attack storyline?

A.Incident Storyline
B.Raw Syslog Viewer
C.Indicator Grid
D.Dashboard Widget Editor
AnswerA

Storyline correlates disparate alerts into a single unified attack sequence.

Why this answer

Incident Storyline in Cortex XSIAM automatically correlates related alerts and events into a unified narrative graph.

60
MCQmedium

When setting up automated email parsing in Cortex XSOAR for phishing triage, which integration is specifically required to connect to Microsoft Office 365 using modern authentication (OAuth 2.0)?

A.Microsoft Graph Mail integration
B.SMTP Relay Server integration
C.Legacy Exchange IMAP integration
D.Active Directory LDAP integration
AnswerA

Microsoft Graph Mail uses modern authentication (OAuth 2.0) to fetch emails.

Why this answer

The Microsoft Office 365 Mail integration (or MS Graph Mail) uses OAuth 2.0 to ingest emails securely.

61
MCQeasy

When evaluating the maturity of an Incident Response program using the CMMI (Capability Maturity Model Integration) framework, what characterizes a 'Managed' (Level 2) process?

A.Processes are planned, executed, measured, and controlled at the project level
B.Processes are standardized across the entire organization
C.Processes are entirely ad-hoc and reactive
D.Processes are quantitatively optimized through statistical data
AnswerA

Level 2 indicates managed and repeatable processes.

Why this answer

Level 2 (Managed) processes are planned, executed, measured, and controlled at the project or incident level.

62
Multi-Selecthard

An enterprise security architect is designing an automated containment playbook in Cortex XSOAR for ransomware attacks. Which THREE automated actions should be incorporated into the playbook to effectively contain the threat while preserving forensic evidence? (Choose three)

Select 3 answers
A.Isolate the affected endpoint via Cortex XDR integration
B.Trigger automated memory dump or forensic package collection via Cortex XDR
C.Immediately reimage all domain controllers without investigation
D.Delete all backup snapshots across all storage arrays
E.Revoke active user sessions and force password resets via Identity provider integration
AnswersA, B, E

Correct. Network isolation prevents the ransomware from spreading to other network segments.

Why this answer

Effective ransomware playbooks isolate the endpoint, revoke user sessions to stop lateral movement, and capture forensic artifacts (like memory or triage packages) before destructive remediation occurs.

63
MCQmedium

An architect is designing log retention and data tiering policies in Cortex XSIAM. To balance regulatory compliance requirements (long-term storage) with high-performance analytics (short-term fast search), how should the data architecture be structured?

A.Store all telemetry in volatile RAM cache indefinitely
B.Forward all raw logs exclusively to an external FTP server in plain text
C.Disable all log compression to ensure faster grep searches
D.Configure active analytical storage for high-frequency queries and cold storage tiers for long-term compliance retention
AnswerD

Correct. Data tiering optimizes cost and query performance by separating active analytics from long-term compliance archives.

Why this answer

Cortex XSIAM supports tiered storage architecture where high-performance active storage is used for immediate analytics and threat hunting, while colder storage tiers handle long-term retention.

64
Multi-Selectmedium

An architect is integrating Cortex XSOAR with threat intelligence platforms. Which THREE attributes are essential when evaluating the quality and operational value of ingested threat indicators? (Choose three)

Select 3 answers
A.Total physical disk space required to store raw indicator text
B.Accuracy and false positive rate
C.Font family used in the vendor's PDF reports
D.Context and TTP mapping (relevance to organizational attack surface)
E.Timeliness (velocity of indicator delivery relative to adversary campaigns)
AnswersB, D, E

Correct. Low false positive rates prevent operational fatigue and unintended service disruption.

Why this answer

Indicator quality is assessed based on accuracy (low false positives), context (relevance to industry/infrastructure), and timeliness (speed of intelligence delivery).

65
MCQeasy

When designing a Security Operations Center (SOC) tiering model, what is the primary operational responsibility typically assigned to Tier 2 (Incident Responders)?

A.Developing custom machine learning detection models and threat hunting hypotheses
B.High-volume initial alert triage and closing false positives based on strict runbooks
C.In-depth forensic investigation, root cause analysis, and containment execution
D.Managing physical datacenter security and badge access
AnswerC

Correct. Tier 2 handles escalated alerts requiring deep investigation and active incident response.

Why this answer

Tier 2 analysts perform in-depth investigation, root cause analysis, containment, and eradication for confirmed incidents escalated by Tier 1.

Ready to test yourself?

Try a timed practice session using only Secops Frameworks And Threat Response Architecture questions.