Sign In
Home/Palo Alto/Palo Alto Networks Certified Security Operations Professional/Free questions

Palo Alto Networks Certified Security Operations Professional — Free Practice Questions

10 free sample questions from a bank of 85, with the correct answers and explanations. No signup required — start practising right now.

1Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
  • File search and destroy
  • Live Terminal session initiation
  • Running a script
  • Halting network access
Answer: A

The short version

A — File search and destroy is unavailable on Linux. Live Terminal, script execution, and network isolation are supported on Linux, while file search and destroy is a Windows-oriented remediation flow.

Key concepts in this question

  • Response actions: analyst-initiated containment and remediation from an incident or endpoint view.
  • Live Terminal: interactive remote shell for investigation on supported endpoints including Linux.
  • Network isolation: halting endpoint network access while retaining agent-to-console connectivity.

Why A is correct

Cortex XSIAM exposes Live Terminal sessions, running scripts or commands, and host isolation for Linux servers. File search and destroy, which searches for and deletes malicious files across endpoints, is documented as unavailable for Linux in this workflow. The straightforward mechanism is platform coverage: the Linux agent supports terminal, script, and isolation actions, but not that particular file-destroy flow.

Why the others are wrong

  • B. Live Terminal initiation is a core Linux investigation action for inspecting processes, files, and system state.
  • C. Running a script is supported on Linux for custom collection or containment steps.
  • D. Halting network access, or host isolation, is a standard Linux containment action.

SecOps Pro exam tip

Remember response actions by OS: if an option names file search and destroy against Linux, treat it as the unavailable outlier.

2What is the role of content packs in Cortex XSOAR?
  • To provide rebuilt bundles for supporting security orchestration use cases
  • To support technical support teams with relevant information required to troubleshoot
  • To serve as a central location for installing, exchanging, and contributing content
  • To serve as a major software versioning update
Answer: A

The short version

A — Content packs are prebuilt bundles supporting security orchestration use cases. They package playbooks, integrations, scripts, and related objects so a SOC can adopt a use case quickly.

Key concepts in this question

  • Content packs: versioned bundles of XSOAR/XSIAM automation content for a use case or vendor.
  • Orchestration use case: an end-to-end workflow such as phishing triage or endpoint containment.
  • Marketplace: the central location where packs are sourced and installed.

Why A is correct

Content packs exist to operationalize orchestration use cases without building every integration, playbook, and script from scratch. Installing a pack delivers the rebuilt, tested bundle for that purpose, such as a vendor integration plus its playbooks and automations. That directly matches the banked key: bundles for supporting security orchestration use cases.

Why the others are wrong

  • B. Helping technical support troubleshoot is not their role; they deliver SOC automation content, not support diagnostics.
  • C. Being a central install and exchange location describes the Marketplace itself, not what a content pack is.
  • D. A major software versioning update describes platform releases, not a content pack.

SecOps Pro exam tip

Link pack to purpose: pack equals use-case bundle, while Marketplace equals the store where packs live.

3Which two types of content can be installed or upgraded through a Cortex XSIAM content pack? (Choose two.)
  • Analytics alerts
  • Playbook triggers
  • Data Model rules
  • Behavioral Threat Protection (BTP)
Answer: A, C

The short version

A and C — Analytics alerts and Data Model rules ship through content packs. They are portable detection and normalization content, while triggers and the BTP engine are not pack-installed items.

Key concepts in this question

  • Analytics alerts: detection rules that generate alerts from modeled data in XSIAM.
  • Data Model rules: mapping and normalization logic that structures ingested data for analytics.
  • Content packs: the distribution vehicle for installing or upgrading detection content.

Why A and C are correct

XSIAM content packs install and upgrade detection-related content such as analytics alert definitions and data model rules. Both are dataset-driven objects that must be versioned and updated as coverage expands. The mechanism is straightforward: packs carry the analytics and modeling content analysts depend on, so upgrading the pack upgrades those detections and mappings together.

Why the others are wrong

  • B. Playbook triggers are configuration linking alerts to playbooks, not versioned installable pack content in this pairing.
  • D. Behavioral Threat Protection is a prevention and detection engine capability, not something installed or upgraded through a content pack.

SecOps Pro exam tip

Associate packs with portable analytics: alerts plus data models travel in packs, engines and trigger assignments do not.

4Which component of Cortex XDR is designed to detect insider threats?
  • Forensics
  • Identity Analytics
  • Cloud Identity Engine
  • Host Insights
Answer: B

The short version

B — Identity Analytics detects insider threats. It profiles user and authentication behavior to surface account misuse, privilege abuse, and anomalous access.

Key concepts in this question

  • Insider threat: malicious or risky activity by legitimate identities rather than external malware.
  • Identity Analytics: UEBA-style detection over logons, access patterns, and privilege use.
  • Forensics vs identity: host artifacts versus user-behavior baselines.

Why B is correct

Insider activity often looks normal at the endpoint but abnormal for the identity, such as impossible logons, unusual resource access, or privilege escalation. Identity Analytics is the component designed for that lens because it baselines identities and raises analytics around suspicious logins and access. The other options address host visibility or directory sync, not user-behavior detection.

Why the others are wrong

  • A. Forensics provides endpoint artifact investigation, not identity-centric insider detection.
  • C. Cloud Identity Engine syncs identity context for policy and visibility; it is not the insider-threat detector itself.
  • D. Host Insights reports endpoint posture and inventory details, not anomalous user behavior.

SecOps Pro exam tip

Map threat to sensor: insider plus user behavior equals Identity Analytics, while malware plus process equals endpoint engines.

5A file hash is evaluated a Cortex XSOAR by using two unique threat feeds: VirusTotal feed (rating of B- usually reliable) and the file verdict is malicious AlienVault feed (rating of B- usually reliable) and the file verdict is benign What is the file verdict in XSOAR?
  • Benign
  • Malicious
  • Unknown
  • Suspicious
Answer: B

The short version

B — The file verdict is Malicious. With equal feed reliability ratings, XSOAR favors the more severe verdict rather than letting benign cancel a malicious finding.

Key concepts in this question

  • Indicator verdict: benign, suspicious, malicious, or unknown assigned to an IOC.
  • Feed reliability rating: letter-grade trust weight such as B for usually reliable.
  • Verdict precedence: how conflicting feed judgments are reconciled.

Why B is correct

Both feeds carry the same B, usually reliable rating, so neither outranks the other on trust. XSOAR then resolves the conflict by severity: a malicious judgment is preserved because treating the file as benign would suppress needed investigation and containment. The straightforward mechanism is conservative security precedence, where malicious wins ties to avoid a false negative.

Why the others are wrong

  • A. Benign is incorrect because one equally trusted feed reports malicious; benign does not override it.
  • C. Unknown would apply when there is no usable verdict, not when two rated feeds disagree with one malicious.
  • D. Suspicious is a middle state, but an explicit rated malicious verdict pushes the outcome to malicious, not suspicious.

SecOps Pro exam tip

For equal-reliability feed conflicts, choose the higher-severity verdict; malicious beats benign on a tie.

6A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?
  • Log stitching
  • User authentication management
  • Indicator of compromise (IOC) rule
  • Analytics
Answer: A

The short version

A — Log stitching correlates firewall network logs with endpoint data. It joins network and endpoint telemetry into one causal narrative for the same activity.

Key concepts in this question

  • Log stitching: automated correlation of endpoint, network, and identity events into unified stories.
  • Network-to-endpoint correlation: matching firewall connections to the processes that initiated them.
  • Causality: linking disparate logs to one incident timeline.

Why A is correct

Unusual traffic plus a malicious process is exactly the cross-source case log stitching solves. It associates firewall network logs with endpoint process, file, and connection data so the analyst sees which endpoint process produced the suspicious traffic. The mechanism is identity, time, IP, and process correlation, producing a cohesive incident rather than isolated firewall and endpoint alerts.

Why the others are wrong

  • B. User authentication management handles access and roles, not network-endpoint log correlation.
  • C. An IOC rule matches known indicators; it does not broadly stitch firewall and endpoint logs together.
  • D. Analytics is too generic here; the specific stitching function performs this correlation.

SecOps Pro exam tip

When the stem pairs firewall logs with endpoint processes, answer log stitching for the correlation function.

7Where can an administrator begin to grant a new non-SSO user access to a Cortex XDR tenant?
  • Cortex XDR tenant settings under Access Management
  • Cortex Gateway
  • Customer Support Portal
  • IT Service Portal
Answer: A

The short version

A — Start in tenant settings under Access Management. Non-SSO local user provisioning and role assignment begin in the Cortex tenant console.

Key concepts in this question

  • Tenant access management: where Cortex XDR user accounts and roles are administered.
  • Non-SSO user: a locally authenticated account created in the tenant rather than via identity provider SSO.
  • RBAC assignment: granting least-privilege roles after account creation.

Why A is correct

Granting a new non-SSO user access is a tenant identity task, so the administrator begins in the Cortex XDR tenant settings under Access Management. That is where local users are added and mapped to roles. The gateway, support portal, and IT service portal do not provision tenant analyst accounts.

Why the others are wrong

  • B. Cortex Gateway provides connectivity and data forwarding, not tenant user provisioning.
  • C. The Customer Support Portal manages support cases and licensing, not day-to-day tenant analyst access.
  • D. An IT Service Portal handles general IT requests, not Cortex tenant access management.

SecOps Pro exam tip

User access questions point to Access Management in tenant settings; gateways move data, they do not create users.

8Which two statements apply to creating scripts in Cortex XSOAR? (Choose two.)
  • They can be protected using a password.
  • They can be scheduled to run at a later time and day.
  • They can be written using Java.
  • They can be executed with higher permissions.
Answer: A, D

The short version

A and D — XSOAR scripts can be password-protected and run with elevated permissions. Scheduling and Java authorship are not the script-creation attributes tested here.

Key concepts in this question

  • XSOAR scripts: reusable automation blocks called by playbook tasks.
  • Script protection: restricting viewing or editing of sensitive logic.
  • Elevated execution: running automation with higher permissions when the workflow requires it.

Why A and D are correct

Scripts encapsulate sensitive or privileged automation, so XSOAR supports protecting them with a password and executing them with higher permissions. Protection controls who can inspect or modify the code, while elevated execution lets the automation perform actions the invoking analyst role alone could not. Together they explain safe reuse of powerful automation across playbooks.

Why the others are wrong

  • B. Scheduled recurring execution is handled by jobs that run playbooks, not an intrinsic script-creation property.
  • C. XSOAR scripts are written in Python or JavaScript, not Java, so Java authorship is incorrect.

SecOps Pro exam tip

Pair scripts with code controls: password protection plus elevated execution, and reserve scheduling for jobs.

9Which two types of tasks are supported in Cortex XSIAM playbooks? (Choose two.)
  • Sub-playbook
  • Script creation
  • Conditional
  • Data collection
Answer: C, D

The short version

C and D — Conditional and Data collection are supported XSIAM playbook task types. They control branching and structured evidence gathering inside the workflow.

Key concepts in this question

  • Conditional tasks: branch logic based on prior outputs or incident fields.
  • Data collection tasks: prompt or gather structured inputs during playbook execution.
  • Playbook structure: tasks orchestrated to triage, investigate, and contain.

Why C and D are correct

Playbooks need decisions and inputs, not only linear commands. Conditional tasks evaluate conditions and route execution down different paths, while data collection tasks collect information needed for later steps. Both are native task constructs in XSIAM playbooks, so they are the two supported types in this pairing.

Why the others are wrong

  • A. A sub-playbook is a reusable nested workflow invoked from a playbook, not one of the two task types keyed here.
  • B. Script creation is authoring automation content, not a playbook task type executed on the canvas.

SecOps Pro exam tip

Think tasks by function: conditional decides the path, data collection gathers the facts, standard tasks do the work.

10Which scripting language would create a custom widget in Cortex XDR that shows the top five accounts with failed Windows logons in the past 24 hours?
  • XQL
  • JavaScript
  • Python
  • PowerShell
Answer: A

The short version

A — Use XQL for the custom failed-logon widget. Cortex XDR dashboards and widgets query endpoint and log data with XQL.

Key concepts in this question

  • XQL: Cortex query language for searching datasets and building dashboard widgets.
  • Custom widget: a dashboard visualization backed by a saved query.
  • Windows logon auditing: account and failed-logon events aggregated in Cortex data.

Why A is correct

A top-five accounts widget over failed Windows logons in 24 hours requires aggregating and sorting security event data, which is exactly what XQL does in Cortex XDR dashboards. The analyst writes an XQL query grouping by account, filtering failed logons and the time window, then renders it as a widget. No general-purpose language replaces that query role.

Why the others are wrong

  • B. JavaScript is used for XSOAR scripting and UI extensions, not Cortex XDR dashboard queries.
  • C. Python is used for XSOAR automations and integrations, not XDR widget queries.
  • D. PowerShell administers Windows hosts and can be run via Live Terminal, but it does not define XDR widgets.

SecOps Pro exam tip

Widget plus top-N aggregation in XDR always signals XQL; scripts and shells are distractors.

Want the full bank of 85 questions for Palo Alto Networks Certified Security Operations Professional? See all practice exams.