SecOps-Pro Exam Question 86

A zero-day vulnerability in a widely used web application is actively being exploited, leading to immediate concern for your organization's internet-facing servers. While vendor patches are not yet available, your Palo Alto Networks NGFW is deployed. Which temporary compensating control, leveraging NGFW capabilities, would offer the best immediate protection against this zero-day exploit without disrupting legitimate traffic or requiring custom signatures?
  • SecOps-Pro Exam Question 87

    A sophisticated phishing attack bypasses initial email gateways. An XSOAR playbook is designed to analyze suspicious URLs found in incident dat a. The playbook needs to:
    1. Extract all URLs from the incident details.
    2. For each unique URL, perform a reputation check against multiple threat intelligence feeds (e.g., VirusTotal, URLscan.io).
    3. If any URL is deemed malicious, automatically create a block rule on the Web Application Firewall (WAF) and update relevant proxy servers.
    4. If a URL is suspicious but not definitively malicious, submit it to an isolated analysis environment (sandbox) and await results.
    5. Consolidate all findings into a structured incident note.
    Which XSOAR playbook component is best suited for iteratively processing each extracted URL, and what is a common programmatic approach to achieve this within XSOAR?
  • SecOps-Pro Exam Question 88

    A Security Operations Center (SOC) using Cortex XSIAM is investigating a novel, zero-day attack targeting their critical financial applications. The attack involves sophisticated evasion techniques and targets a custom-built ledger system. The SOC team needs to rapidly develop detection and response capabilities for this specific threat without waiting for an official content pack update from Palo Alto Networks. Which of the following approaches best leverages XSIAM's content pack capabilities for this immediate, custom threat response?
  • SecOps-Pro Exam Question 89

    A Zero-Day exploit targets a widely used application within an organization, leading to a successful initial compromise. The security team detects anomalous network traffic patterns via their Palo Alto Networks Next-Generation Firewall (NGFW) and identifies the specific compromised host. During the 'Containment' phase of the NIST Incident Response Plan, which strategic and tactical action(s) should be prioritized to limit the blast radius and gather critical threat intelligence simultaneously, considering the zero-day nature of the attack?
    (Select all that apply)
  • SecOps-Pro Exam Question 90

    A Security Operations Professional is analyzing a 'Living-off-the-Land' (LotL) attack where an attacker utilized 'certutil.exe' to download a malicious payload from a legitimate-looking cloud storage service and then used 'forfiles.exe' to execute it. Cortex XDR has generated an XDR Story for this activity. When leveraging the Causality View, which of the following aspects are critical to focus on to accurately identify the malicious intent and differentiate it from legitimate system administrator activities, and why might this be challenging?