Palo Alto Networks Certified Security Operations Professional — Free Practice Questions
10 free sample questions from a bank of 85, with the correct answers and explanations. No signup required — start practising right now.
1Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
File search and destroy
Live Terminal session initiation
Running a script
Halting network access
Answer: A
The short version
A — File search and destroy is unavailable on Linux. Live Terminal, script execution, and network isolation are supported on Linux, while file search and destroy is a Windows-oriented remediation flow.
Key concepts in this question
Response actions: analyst-initiated containment and remediation from an incident or endpoint view.
Live Terminal: interactive remote shell for investigation on supported endpoints including Linux.
Network isolation: halting endpoint network access while retaining agent-to-console connectivity.
Why A is correct
Cortex XSIAM exposes Live Terminal sessions, running scripts or commands, and host isolation for Linux servers. File search and destroy, which searches for and deletes malicious files across endpoints, is documented as unavailable for Linux in this workflow. The straightforward mechanism is platform coverage: the Linux agent supports terminal, script, and isolation actions, but not that particular file-destroy flow.
Why the others are wrong
B. Live Terminal initiation is a core Linux investigation action for inspecting processes, files, and system state.
C. Running a script is supported on Linux for custom collection or containment steps.
D. Halting network access, or host isolation, is a standard Linux containment action.
SecOps Pro exam tip
Remember response actions by OS: if an option names file search and destroy against Linux, treat it as the unavailable outlier.
2What is the role of content packs in Cortex XSOAR?
To provide rebuilt bundles for supporting security orchestration use cases
To support technical support teams with relevant information required to troubleshoot
To serve as a central location for installing, exchanging, and contributing content
To serve as a major software versioning update
Answer: A
The short version
A — Content packs are prebuilt bundles supporting security orchestration use cases. They package playbooks, integrations, scripts, and related objects so a SOC can adopt a use case quickly.
Key concepts in this question
Content packs: versioned bundles of XSOAR/XSIAM automation content for a use case or vendor.
Orchestration use case: an end-to-end workflow such as phishing triage or endpoint containment.
Marketplace: the central location where packs are sourced and installed.
Why A is correct
Content packs exist to operationalize orchestration use cases without building every integration, playbook, and script from scratch. Installing a pack delivers the rebuilt, tested bundle for that purpose, such as a vendor integration plus its playbooks and automations. That directly matches the banked key: bundles for supporting security orchestration use cases.
Why the others are wrong
B. Helping technical support troubleshoot is not their role; they deliver SOC automation content, not support diagnostics.
C. Being a central install and exchange location describes the Marketplace itself, not what a content pack is.
D. A major software versioning update describes platform releases, not a content pack.
SecOps Pro exam tip
Link pack to purpose: pack equals use-case bundle, while Marketplace equals the store where packs live.
3Which two types of content can be installed or upgraded through a Cortex XSIAM content pack? (Choose two.)
Analytics alerts
Playbook triggers
Data Model rules
Behavioral Threat Protection (BTP)
Answer: A, C
The short version
A and C — Analytics alerts and Data Model rules ship through content packs. They are portable detection and normalization content, while triggers and the BTP engine are not pack-installed items.
Key concepts in this question
Analytics alerts: detection rules that generate alerts from modeled data in XSIAM.
Data Model rules: mapping and normalization logic that structures ingested data for analytics.
Content packs: the distribution vehicle for installing or upgrading detection content.
Why A and C are correct
XSIAM content packs install and upgrade detection-related content such as analytics alert definitions and data model rules. Both are dataset-driven objects that must be versioned and updated as coverage expands. The mechanism is straightforward: packs carry the analytics and modeling content analysts depend on, so upgrading the pack upgrades those detections and mappings together.
Why the others are wrong
B. Playbook triggers are configuration linking alerts to playbooks, not versioned installable pack content in this pairing.
D. Behavioral Threat Protection is a prevention and detection engine capability, not something installed or upgraded through a content pack.
SecOps Pro exam tip
Associate packs with portable analytics: alerts plus data models travel in packs, engines and trigger assignments do not.
4Which component of Cortex XDR is designed to detect insider threats?
Forensics
Identity Analytics
Cloud Identity Engine
Host Insights
Answer: B
The short version
B — Identity Analytics detects insider threats. It profiles user and authentication behavior to surface account misuse, privilege abuse, and anomalous access.
Key concepts in this question
Insider threat: malicious or risky activity by legitimate identities rather than external malware.
Identity Analytics: UEBA-style detection over logons, access patterns, and privilege use.
Forensics vs identity: host artifacts versus user-behavior baselines.
Why B is correct
Insider activity often looks normal at the endpoint but abnormal for the identity, such as impossible logons, unusual resource access, or privilege escalation. Identity Analytics is the component designed for that lens because it baselines identities and raises analytics around suspicious logins and access. The other options address host visibility or directory sync, not user-behavior detection.
Why the others are wrong
A. Forensics provides endpoint artifact investigation, not identity-centric insider detection.
C. Cloud Identity Engine syncs identity context for policy and visibility; it is not the insider-threat detector itself.
D. Host Insights reports endpoint posture and inventory details, not anomalous user behavior.
SecOps Pro exam tip
Map threat to sensor: insider plus user behavior equals Identity Analytics, while malware plus process equals endpoint engines.
5A file hash is evaluated a Cortex XSOAR by using two unique threat feeds: VirusTotal feed (rating of B- usually reliable) and the file verdict is malicious AlienVault feed (rating of B- usually reliable) and the file verdict is benign What is the file verdict in XSOAR?
Benign
Malicious
Unknown
Suspicious
Answer: B
The short version
B — The file verdict is Malicious. With equal feed reliability ratings, XSOAR favors the more severe verdict rather than letting benign cancel a malicious finding.
Key concepts in this question
Indicator verdict: benign, suspicious, malicious, or unknown assigned to an IOC.
Feed reliability rating: letter-grade trust weight such as B for usually reliable.
Verdict precedence: how conflicting feed judgments are reconciled.
Why B is correct
Both feeds carry the same B, usually reliable rating, so neither outranks the other on trust. XSOAR then resolves the conflict by severity: a malicious judgment is preserved because treating the file as benign would suppress needed investigation and containment. The straightforward mechanism is conservative security precedence, where malicious wins ties to avoid a false negative.
Why the others are wrong
A. Benign is incorrect because one equally trusted feed reports malicious; benign does not override it.
C. Unknown would apply when there is no usable verdict, not when two rated feeds disagree with one malicious.
D. Suspicious is a middle state, but an explicit rated malicious verdict pushes the outcome to malicious, not suspicious.
SecOps Pro exam tip
For equal-reliability feed conflicts, choose the higher-severity verdict; malicious beats benign on a tie.
6A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?
Log stitching
User authentication management
Indicator of compromise (IOC) rule
Analytics
Answer: A
The short version
A — Log stitching correlates firewall network logs with endpoint data. It joins network and endpoint telemetry into one causal narrative for the same activity.
Key concepts in this question
Log stitching: automated correlation of endpoint, network, and identity events into unified stories.
Network-to-endpoint correlation: matching firewall connections to the processes that initiated them.
Causality: linking disparate logs to one incident timeline.
Why A is correct
Unusual traffic plus a malicious process is exactly the cross-source case log stitching solves. It associates firewall network logs with endpoint process, file, and connection data so the analyst sees which endpoint process produced the suspicious traffic. The mechanism is identity, time, IP, and process correlation, producing a cohesive incident rather than isolated firewall and endpoint alerts.
Why the others are wrong
B. User authentication management handles access and roles, not network-endpoint log correlation.
C. An IOC rule matches known indicators; it does not broadly stitch firewall and endpoint logs together.
D. Analytics is too generic here; the specific stitching function performs this correlation.
SecOps Pro exam tip
When the stem pairs firewall logs with endpoint processes, answer log stitching for the correlation function.
7Where can an administrator begin to grant a new non-SSO user access to a Cortex XDR tenant?
Cortex XDR tenant settings under Access Management
Cortex Gateway
Customer Support Portal
IT Service Portal
Answer: A
The short version
A — Start in tenant settings under Access Management. Non-SSO local user provisioning and role assignment begin in the Cortex tenant console.
Key concepts in this question
Tenant access management: where Cortex XDR user accounts and roles are administered.
Non-SSO user: a locally authenticated account created in the tenant rather than via identity provider SSO.
RBAC assignment: granting least-privilege roles after account creation.
Why A is correct
Granting a new non-SSO user access is a tenant identity task, so the administrator begins in the Cortex XDR tenant settings under Access Management. That is where local users are added and mapped to roles. The gateway, support portal, and IT service portal do not provision tenant analyst accounts.
Why the others are wrong
B. Cortex Gateway provides connectivity and data forwarding, not tenant user provisioning.
C. The Customer Support Portal manages support cases and licensing, not day-to-day tenant analyst access.
D. An IT Service Portal handles general IT requests, not Cortex tenant access management.
SecOps Pro exam tip
User access questions point to Access Management in tenant settings; gateways move data, they do not create users.
8Which two statements apply to creating scripts in Cortex XSOAR? (Choose two.)
They can be protected using a password.
They can be scheduled to run at a later time and day.
They can be written using Java.
They can be executed with higher permissions.
Answer: A, D
The short version
A and D — XSOAR scripts can be password-protected and run with elevated permissions. Scheduling and Java authorship are not the script-creation attributes tested here.
Key concepts in this question
XSOAR scripts: reusable automation blocks called by playbook tasks.
Script protection: restricting viewing or editing of sensitive logic.
Elevated execution: running automation with higher permissions when the workflow requires it.
Why A and D are correct
Scripts encapsulate sensitive or privileged automation, so XSOAR supports protecting them with a password and executing them with higher permissions. Protection controls who can inspect or modify the code, while elevated execution lets the automation perform actions the invoking analyst role alone could not. Together they explain safe reuse of powerful automation across playbooks.
Why the others are wrong
B. Scheduled recurring execution is handled by jobs that run playbooks, not an intrinsic script-creation property.
C. XSOAR scripts are written in Python or JavaScript, not Java, so Java authorship is incorrect.
SecOps Pro exam tip
Pair scripts with code controls: password protection plus elevated execution, and reserve scheduling for jobs.
9Which two types of tasks are supported in Cortex XSIAM playbooks? (Choose two.)
Sub-playbook
Script creation
Conditional
Data collection
Answer: C, D
The short version
C and D — Conditional and Data collection are supported XSIAM playbook task types. They control branching and structured evidence gathering inside the workflow.
Key concepts in this question
Conditional tasks: branch logic based on prior outputs or incident fields.
Data collection tasks: prompt or gather structured inputs during playbook execution.
Playbook structure: tasks orchestrated to triage, investigate, and contain.
Why C and D are correct
Playbooks need decisions and inputs, not only linear commands. Conditional tasks evaluate conditions and route execution down different paths, while data collection tasks collect information needed for later steps. Both are native task constructs in XSIAM playbooks, so they are the two supported types in this pairing.
Why the others are wrong
A. A sub-playbook is a reusable nested workflow invoked from a playbook, not one of the two task types keyed here.
B. Script creation is authoring automation content, not a playbook task type executed on the canvas.
SecOps Pro exam tip
Think tasks by function: conditional decides the path, data collection gathers the facts, standard tasks do the work.
10Which scripting language would create a custom widget in Cortex XDR that shows the top five accounts with failed Windows logons in the past 24 hours?
XQL
JavaScript
Python
PowerShell
Answer: A
The short version
A — Use XQL for the custom failed-logon widget. Cortex XDR dashboards and widgets query endpoint and log data with XQL.
Key concepts in this question
XQL: Cortex query language for searching datasets and building dashboard widgets.
Custom widget: a dashboard visualization backed by a saved query.
Windows logon auditing: account and failed-logon events aggregated in Cortex data.
Why A is correct
A top-five accounts widget over failed Windows logons in 24 hours requires aggregating and sorting security event data, which is exactly what XQL does in Cortex XDR dashboards. The analyst writes an XQL query grouping by account, filtering failed logons and the time window, then renders it as a widget. No general-purpose language replaces that query role.
Why the others are wrong
B. JavaScript is used for XSOAR scripting and UI extensions, not Cortex XDR dashboard queries.
C. Python is used for XSOAR automations and integrations, not XDR widget queries.
D. PowerShell administers Windows hosts and can be run via Live Terminal, but it does not define XDR widgets.
SecOps Pro exam tip
Widget plus top-N aggregation in XDR always signals XQL; scripts and shells are distractors.