Sample questions
Certified Security Operations Professional (SecOps-Pro) practice questions
What does the 'Cortex XDR Agent' do if it cannot communicate with the cloud for an extended period?
Which THREE pieces of information are displayed in the Incident View?
A user is reporting that their XSIAM dashboard widgets are displaying 'No Data'. What is the most likely cause?
You are investigating a ransomware incident. You want to see the parent process that spawned the malicious file. Which feature should you use?
You need to export a report of all alerts from the last 30 days for a compliance audit. Which section of the console should you use?
Where do you configure the settings to ensure that the Cortex XDR agent receives regular updates from the Cortex XDR console?
An analyst is reviewing the 'Causality View' of an alert. What does a dotted line between two processes signify?
Which TWO methods can be used to investigate an endpoint in Cortex XDR?
An administrator needs to quickly identify a specific alert type across a massive dataset in Cortex XSIAM. Which query language is primarily used to perform this investigation?
When reviewing an incident in the Investigation area, what does the 'Graph' view display?
When configuring a Behavioral Threat Protection (BTP) profile, what is the impact of setting the protection mode to 'Block'?
You want to automate the response to a specific type of alert. Where should you configure this?
Which THREE components are part of the Cortex XDR architecture?
You are configuring a new Logstash data collector to ingest logs into Cortex XSIAM. Which specific component must be deployed within the customer environment to facilitate secure,…
You need to export data from Cortex XSIAM to a third-party SIEM. Which feature facilitates the automated forwarding of data?
A security analyst needs to review logs from an endpoint that is reporting as 'Disconnected' in the Cortex XDR console. What is the first step to troubleshoot this communication is…
When performing a 'Live Terminal' session on an endpoint, what must be true for the connection to succeed?
Which THREE actions are available when responding to an incident via the Response feature?
What is the primary function of the 'Cortex XDR Data Lake'?
Which configuration setting in the Malware profile determines if the agent should move a file to a secure location upon detection?
If an endpoint is marked as 'Out of Date', what does this mean?
You notice that your custom BIOC rule is not firing on a host where the malicious activity is confirmed. What is a common reason for this?
You are troubleshooting an issue where a specific detection rule is failing to trigger despite matching log data. Which tool allows you to simulate the detection rule against histo…
Which TWO features are included in the Cortex XSIAM 'Unified SOC' dashboard capabilities?