SecOps-Pro Sample Questions & Answers
Pulls together SOC fundamentals like reporting, dashboards and log management, the single biggest weight, plus Cortex XDR agent management, Cortex XSIAM's components and use cases, NIST incident response, threat intelligence, and Cortex XSOAR scripts versus jobs.
Launch the full SecOps-Pro simulator →Showing 6 of 12 free samples.
- Question 1Advanced
Security Operations Fundamentals · Differentiate between AI and machine learning (ML) in Security Operations
In the context of Cortex XDR and XSIAM, which statement accurately distinguishes between Artificial Intelligence (AI) and Machine Learning (ML)?
Show answer & explanation
Correct answer: B
This is the correct technical distinction. In Cortex products, ML is specifically used for Behavioral Threat Protection (BTP) and analytics (learning baselines to find anomalies). AI is the overarching umbrella term. The other options reverse the relationship or misapply the terms to static signatures.
- Question 2Beginner
Cortex XDR · Identify and explain the use of key Cortex XDR elements
A security analyst is investigating a potential data exfiltration incident. They need to visualize the sequence of network connections and process executions to determine if the 'svchost.exe' process spawned a suspicious PowerShell script. Which Cortex XDR feature provides this specific visualization?
Show answer & explanation
Correct answer: B
The Causality View (or Causality Chain) is the primary visualization tool in Cortex XDR that displays the parent-child relationships of processes, file modifications, and network connections, allowing analysts to trace the root cause and sequence of an attack.
- Question 3BeginnerSelect 2
Security Operations Fundamentals · Common Components and Functions of a Security Operations Center (SOC)
Select TWO key components that are typically integrated into a modern Security Operations Center (SOC) architecture to enhance automation and visibility.
Show answer & explanation
Correct answers: B, C
SIEM systems are foundational to the SOC for aggregating logs, correlating events, and providing a centralized view of security alerts.
SOAR platforms (like Cortex XSOAR) are essential for automating incident response workflows and orchestrating actions across disparate tools.
- Question 4Intermediate
Security Operations Fundamentals · Users, Roles, Log Management, Compliance, and Data Protection in Cortex XDR
True or False: Cortex XDR automatically masks sensitive data fields (such as credit card numbers) in logs at the time of ingestion into the Data Lake without any additional configuration.
Show answer & explanation
Correct answer: B
False. While Cortex XDR supports data privacy features, automatic masking of specific sensitive fields usually requires explicit configuration of Data Loss Prevention (DLP) profiles or specific masking rules on the Broker VM or ingestion pipeline. It is not a default 'out-of-the-box' behavior for all log types without configuration.
- Question 5Intermediate
Security Operations Fundamentals · Users, Roles, Log Management, Compliance, and Data Protection in Cortex XDR
During a security audit, an administrator notices that a user with the 'Investigator' role is unable to access a specific set of endpoint logs needed for a case. The logs are present in the Data Lake. What is the MOST likely cause of this access issue?
Show answer & explanation
Correct answer: B
Cortex XDR uses Scoped Access to restrict what data specific users can see. Even if a user has the 'Investigator' role, if their scope is limited to 'London Office' endpoints, they cannot view logs from 'New York Office' endpoints. This is a common configuration issue in multi-site deployments.
- Question 6Beginner
Threat Intelligence and Incident Response · Identify and explain the steps of the NIST incident response plan
A SOC analyst is reviewing the NIST Incident Response lifecycle. After a malware infection is confirmed and analyzed (Detection & Analysis), the team moves to stop the spread of the infection. Which phase of the NIST lifecycle does this activity fall under?
Show answer & explanation
Correct answer: B
Stopping the spread of an infection (e.g., isolating a host, blocking a port) is the definition of Containment, which is the first part of the 'Containment, Eradication, and Recovery' phase in the NIST SP 800-61 framework.
Ready for the real thing?
The full SecOps-Pro simulator has every exam-style question, timed mode, and instant scoring.