SecOps-Pro Exam Question 6

Which action is performed as the final step of the NIST incident response plan?
  • SecOps-Pro Exam Question 7

    A file hash is evaluated a Cortex XSOAR by using two unique threat feeds:
    - VirusTotal feed (rating of B- usually reliable) and the file verdict
    is malicious
    - AlienVault feed (rating of B- usually reliable) and the file verdict
    is benign
    What is the file verdict in XSOAR?
  • SecOps-Pro Exam Question 8

    Which attribute is an advantage of SOAR over SIEM?
  • SecOps-Pro Exam Question 9

    A security analyst is reviewing a comprehensive list of newly ingested indicators of compromise (IOCs) from various threat intelligence feeds in Cortex XSOAR. The analyst needs to quickly filter and sort the IOCs to determine which ones pose the greatest immediate risk to the organization, regardless of their source. Which indicator attribute in Cortex XSOAR is the most direct and efficient mechanism for this prioritization task?
  • SecOps-Pro Exam Question 10

    A SOC uses Palo Alto Networks Cortex XDR for endpoint detection and response. A new custom behavioral threat detection rule is implemented to identify suspicious PowerShell activity, specifically focusing on encoded commands and attempts to disable security features. Days after deployment, the SOC is inundated with alerts, most of which are traced back to legitimate IT administration scripts or software installers. This flood of alerts significantly impacts the team's ability to respond to actual threats. Which of the following statements accurately describes this situation and the most effective strategic adjustment?