Courseiva

CCNA SOC Fundamentals And Operations Questions

33 questions · SOC Fundamentals And Operations · All types, answers revealed

1
Multi-Selecteasy

Which TWO actions are considered 'Best Practices' for maintaining SOC operational documentation?

Select 2 answers
A.Store only in printed binders
B.Limit access to the manager only
C.Create documentation only once
D.Maintain clear version control
E.Regular review and update cycles
AnswersD, E

Essential for tracking changes in IR processes.

Why this answer

Keeping documentation updated and version-controlled is critical to ensure it remains relevant.

2
MCQeasy

Which SOC operational document defines the service level objectives (SLOs) for incident response times?

A.Runbook
B.SLA
C.Security Policy
D.Playbook
AnswerB

Service Level Agreements govern the expected response performance.

Why this answer

An SLA (Service Level Agreement) is the primary document defining response time requirements.

3
Multi-Selecthard

Which TWO types of logs are critical for investigating a potential data exfiltration event?

Select 2 answers
A.Traffic logs
B.Printer configuration logs
C.Power management logs
D.Room temperature logs
E.System and file activity logs
AnswersA, E

Shows the flow of data out of the network.

Why this answer

Traffic logs and file access/system logs are necessary to reconstruct data exfiltration movements.

4
MCQeasy

In the SOC structure, which role is typically responsible for the initial triage and validation of security alerts?

A.Tier 1 Analyst
B.Threat Researcher
C.Tier 3 Analyst
D.SOC Manager
AnswerA

Tier 1 is the entry level tasked with triaging alerts.

Why this answer

Tier 1 analysts are responsible for the first line of defense and initial alert triage.

5
MCQeasy

A security analyst is investigating a phishing alert in Cortex XSOAR. Which workflow component is best utilized to standardize the response process for repetitive phishing email triage?

A.Integration instance
B.Indicator auto-extraction
C.Playbook
D.Dashboard widget
AnswerC

A playbook defines the automated sequence of tasks required to resolve the incident.

Why this answer

Playbooks are the standard method in Cortex XSOAR for automating and standardizing incident response workflows.

6
MCQmedium

In Cortex XSOAR, which feature allows you to automatically create an incident when a specific email is received in a monitored inbox?

A.Incident Classifier
B.Data collection rule
C.Automation script
D.Mail Listener
AnswerD

The mail listener service monitors for emails to trigger incidents.

Why this answer

Mail listeners are configured in Cortex XSOAR to poll mailboxes and trigger incident creation via automation.

7
Multi-Selecteasy

Which THREE roles are commonly involved in the SOC operational structure?

Select 3 answers
A.IT Helpdesk Lead
B.SOC Manager
C.Tier 1 Analyst
D.Sales Engineer
E.Tier 2 Analyst
AnswersB, C, E

Oversees the entire operation.

Why this answer

Tier 1, Tier 2, and SOC Managers are standard components of a functional SOC team.

8
MCQmedium

An analyst is reviewing a firewall policy. Which feature allows them to view the traffic logs that specifically match that rule?

A.Security Profile
B.Rule Base View
C.Policy Optimizer
D.Log Viewer
AnswerD

Clicking the log icon in the policy rule opens the filtered log view.

Why this answer

The 'Log' icon or 'View Logs' option in the policy window allows jumping directly to the logs associated with that specific rule.

9
Multi-Selecthard

Which TWO metrics are essential when evaluating the effectiveness of a SOC operational process?

Select 2 answers
A.Total number of employees
B.Annual hardware expenditure
C.Mean Time to Respond (MTTR)
D.Mean Time to Acknowledge (MTTA)
E.Total number of emails sent
AnswersC, D

Measures how fast the SOC takes action.

Why this answer

MTTR and MTTA are the standard industry KPIs for measuring SOC operational efficiency and success.

10
Multi-Selecthard

Which THREE methods can be used in Cortex XSOAR to ingest indicators?

Select 3 answers
A.Direct database SQL injection
B.Manual entry via the UI
C.Auto-extraction from incidents
D.Integrated threat intelligence feeds
E.Hardware port mirroring
AnswersB, C, D

Analysts can add indicators manually.

Why this answer

Cortex XSOAR supports automated ingestion through threat feeds, manual entry, and incident extraction.

11
MCQmedium

In XSOAR, an analyst wants to share a finding with another team member. Which feature allows for real-time collaboration within the incident workspace?

A.Work Plan
B.War Room
C.Indicator Tab
D.Incident Summary
AnswerB

The War Room is the collaborative chat and execution environment.

Why this answer

The War Room allows multiple analysts to comment, run commands, and share findings in a single collaborative interface.

12
MCQhard

While analyzing a breach, an analyst identifies an IOC that is not yet flagged by automated systems. Which tool is used to manually update the global blacklist to prevent further spread across the organization?

A.Custom Threat Intelligence
B.Dynamic Address Groups
C.Security Profiles
D.Service Objects
AnswerA

Custom TI allows for the manual ingestion and application of IOCs for blocking.

Why this answer

Cortex XDR Custom Threat Intelligence allows analysts to manually push indicators to block across the enterprise.

13
MCQeasy

What is the primary purpose of a SOC 'Daily Standup' meeting?

A.Technical training
B.Vendor management
C.Operational alignment and incident status sync
D.Long-term strategy planning
AnswerC

Synchronizing shift teams and identifying hot issues is the primary goal.

Why this answer

The daily standup is for operational alignment, shift handovers, and discussing urgent high-priority incidents.

14
Multi-Selectmedium

Which TWO data sources should a SOC analyst correlate to identify a compromised user account?

Select 2 answers
A.Printer hardware logs
B.Authentication logs
C.Endpoint process logs
D.Physical building access logs
E.Cafeteria transaction logs
AnswersB, C

Necessary to see login behavior.

Why this answer

Correlating authentication logs and endpoint process logs provides a holistic view of user identity compromise.

15
MCQeasy

Which type of alert in Cortex XDR represents a high-confidence threat that has been automatically grouped with related events?

A.Incident
B.Log
C.Indicator
D.Exclusion
E.Exception
AnswerA

Incidents aggregate related alerts into a single investigation object.

Why this answer

An Incident in Cortex XDR is a collection of related alerts that represent a single threat narrative.

16
MCQhard

During a threat hunting mission in XDR Query Builder, you need to find all processes running from the 'temp' directory. Which XDR language is utilized?

A.Python
B.Regex
C.XQL
D.SQL
AnswerC

XQL is the proprietary language for querying XDR data.

Why this answer

XDR Query Language (XQL) is used for advanced hunting and data exploration in Cortex XDR.

17
MCQeasy

In the context of the SOC maturity model, which phase focuses primarily on the formalization of playbooks and the integration of automated threat intelligence?

A.Defined
B.Optimized
C.Managed
D.Ad-hoc
AnswerA

The Defined phase focuses on formalizing procedures and integrating tooling.

Why this answer

The defined or standardized phase of SOC maturity involves creating repeatable processes and integrating automation.

18
MCQhard

You are designing a SOC operational workflow using Cortex XDR. You need to ensure that alerts from high-value servers are prioritized over workstations. What feature allows for this granular incident management?

A.BiS Rules
B.Incident Response Rule
C.Alert Exclusion Profiles
D.Agent Profiles
AnswerB

Response rules and incident settings allow for grouping and prioritizing based on asset tags.

Why this answer

Incident grouping and severity logic in Cortex XDR allow for custom alert prioritization based on asset criticality.

19
MCQmedium

An analyst needs to correlate logs from multiple Palo Alto Networks firewalls to identify lateral movement. Which tool provides the centralized log aggregation and analytics required for this operation?

A.AutoFocus
B.Panorama
C.Prisma Access
D.Cortex Data Lake
AnswerD

Cortex Data Lake is designed to store and analyze large volumes of security telemetry.

Why this answer

Cortex Data Lake serves as the centralized repository and analytics engine for logs across the PANW ecosystem.

20
MCQmedium

Which component of Cortex XDR is responsible for blocking processes that display malicious behavior on an endpoint?

A.Exploit Prevention
B.Behavioral Threat Protection
C.Network Isolation
D.Host Insight
AnswerB

BTP detects and blocks malicious process behavior on the host.

Why this answer

The Cortex XDR agent uses Behavioral Threat Protection to stop malicious processes in real-time.

21
MCQmedium

During an investigation, you discover a malicious file hash. To determine the global prevalence and classification of this file, which Palo Alto Networks service should you consult?

A.Cortex XDR
B.WildFire
C.Threat Vault
D.GlobalProtect
AnswerB

WildFire provides global intelligence on file reputation and analysis.

Why this answer

WildFire is the cloud-based malware analysis service that tracks global file reputation.

22
Multi-Selectmedium

Which THREE items should be included in a standard SOC shift-handover report?

Select 3 answers
A.Entire network configuration file
B.Status of high-priority incidents
C.Pending action items from the previous shift
D.Known operational or infrastructure issues
E.Personal employee performance reviews
AnswersB, C, D

Ensures continuity for ongoing threats.

Why this answer

High-priority incidents, pending action items, and known issues are essential for a smooth shift transition.

23
Multi-Selectmedium

Which THREE features are provided by the Palo Alto Networks Cortex platform for SOC operations?

Select 3 answers
A.GlobalProtect Enterprise
B.Cortex XSOAR
C.Cortex XDR
D.Cortex Data Lake
E.Panorama Policy Creator
AnswersB, C, D

The automation and orchestration platform.

Why this answer

Cortex provides XDR for detection, XSOAR for automation, and Data Lake for log aggregation.

24
MCQhard

You are troubleshooting a connectivity issue between an internal log forwarder and Cortex Data Lake. Which command should you run on the log forwarder to verify the ingestion status?

A.show log-collector statistics
B.show system status
C.test log-collector connectivity
D.debug log-forwarding status
AnswerA

This command displays real-time health and forwarding stats.

Why this answer

The 'show log-collector statistics' command is used on the log forwarder to check status and ingestion health.

25
Multi-Selectmedium

Which THREE actions can be performed directly from the Cortex XDR incident details page?

Select 3 answers
A.Isolate the endpoint
B.Reset the user's password
C.Run an investigation scan
D.Retrieve forensic files
E.Update firewall OS
AnswersA, C, D

Isolation is a primary response action.

Why this answer

Cortex XDR allows analysts to isolate hosts, retrieve files, and initiate remote scans directly from the incident view.

26
MCQmedium

A SOC manager wants to track the 'Mean Time to Acknowledge' (MTTA) for critical incidents. Which feature in Cortex XSOAR provides this visualization?

A.Dashboard Metrics
B.Playbook Indicators
C.War Room logs
D.Incident Layouts
AnswerA

Dashboards provide the visualization layer for MTTA and other KPIs.

Why this answer

Dashboards and Reports in Cortex XSOAR include built-in metrics for incident lifecycle tracking, including MTTA.

27
MCQmedium

An analyst discovers a false positive alert in Cortex XDR. Where should they go to prevent this alert from triggering again?

A.Agent Uninstallation
B.Policy Deletion
C.Threat Intel Ingestion
D.Alert Exclusion
AnswerD

Exclusions are the mechanism to prevent specific alert triggers.

Why this answer

Alert Exclusions allow you to define criteria to suppress specific alerts based on process, user, or hash.

28
MCQmedium

Your organization has adopted a Zero Trust architecture. Which SOC operational process is most critical to validate that identity-based policies are effective?

A.Hardware Lifecycle
B.User Behavior Analytics
C.Patch Management
D.Vulnerability Scanning
AnswerB

UBA validates that access is legitimate according to user identity.

Why this answer

User Behavior Analytics (UBA) and identity monitoring are central to verifying Zero Trust policies.

29
MCQhard

An incident requires forensic acquisition of a compromised endpoint. Which feature within Cortex XDR enables you to pull specific file artifacts directly from the machine?

A.Live Terminal
B.Scan Endpoint
C.Quarantine File
D.Retrieve File
AnswerD

Retrieve file allows pulling files from an endpoint for analysis.

Why this answer

Cortex XDR's 'Retrieve File' action allows analysts to pull forensic artifacts from endpoints.

30
Multi-Selecteasy

Which TWO of the following are key components of a mature SOC incident response plan?

Select 2 answers
A.Automated hardware repair
B.Public relations policy
C.Defined communication and escalation procedures
D.Budget approval workflows
E.Clear definition of roles and responsibilities
AnswersC, E

Critical for managing stakeholder expectations.

Why this answer

Roles and responsibilities and communication plans are fundamental to structured incident response.

31
MCQhard

When integrating an external threat feed into Cortex XSOAR, which indicator field must be correctly mapped to ensure effective lookup and reputation scoring?

A.Indicator Type
B.Expiration
C.Value
D.Indicator Source
AnswerC

The value field acts as the primary key for reputation lookups.

Why this answer

The 'Value' field is the primary indicator identifier that must be mapped for reputation and lookup services to function.

32
MCQeasy

A new SOC analyst wants to see all traffic blocked by the firewall in the last hour. Where should they navigate in the Panorama monitor tab?

A.Monitor > Logs > Traffic
B.Network > Interfaces
C.Policies > Security
D.Objects > Services
AnswerA

Traffic logs are found under the Monitor tab.

Why this answer

The Monitor tab in Panorama provides access to log views, including filtered traffic logs.

33
MCQhard

You are investigating an alert involving a malicious user identity. Which Cortex XDR dashboard widget provides the best overview of the user's risk profile?

A.Threat Intelligence
B.Endpoint Status
C.User Risk
D.Network Activity
AnswerC

User risk dashboards aggregate identity-based alerts and behaviors.

Why this answer

The User Investigation dashboard or User Risk view in Cortex XDR provides a consolidated view of user-linked alerts and behavioral history.

Ready to test yourself?

Try a timed practice session using only SOC Fundamentals And Operations questions.