SecOps-Pro 無料問題集「Palo Alto Networks Security Operations Professional」
An administrator has configured Cortex XDR to ingest logs from third-party firewalls and is using Cortex XDR agents on endpoints. The goal is to see network connections from the firewalls correlated with the endpoint processes that initiated them. Which feature handles this correlation to form network stories?
正解:B
解答を投票する
During a routine security audit, it's discovered that a critical server was successfully breached weeks ago by an advanced persistent threat (APT) group. The breach involved sophisticated lateral movement and data exfiltration, yet no alerts were generated by the existing security infrastructure, which includes a Palo Alto Networks Cortex XDR endpoint protection platform and a WildFire cloud- based threat analysis service. How would you classify this scenario from the perspective of the security controls, and what is the primary challenge it presents for a SOC?
正解:C
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
An automation engineer is using Cortex XSIAM playbooks to create modular, readable, and structured security workflows. The engineer requires a method to clearly delineate the Engagement, Triage, and Containment phases by introducing visual grouping mechanisms into the playbook canvas. Which playbook element is designed to organize the workflow in this scenario?
正解:C
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)