SecOps-Pro Exam Question 26
Which component of Cortex XDR would allow an analyst to determine if suspicious user activity deviates from normal user activity?
SecOps-Pro Exam Question 27
An organization requires a specific user to have the ability to investigate alerts and perform remediation tasks, such as terminating malicious processes and isolating compromised hosts, without having full administrative control over the tenant settings. Which predefined role should be assigned to this user in Cortex XDR?
SecOps-Pro Exam Question 28
What is involved in the day-to-day role of a triage specialist?
SecOps-Pro Exam Question 29
A threat intelligence team produces a report on a new APT group known for targeting specific industry sectors using novel obfuscation techniques. This report includes IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures). How should this intelligence be integrated into an organization's incident categorization and prioritization process to maximize its impact?
SecOps-Pro Exam Question 30
A new incident in Cortex XSIAM contains WildFire malware and Behavioral Threat Protection (BTP) alertsout an unsigned process attempting to dump the memory of Isass.exe. Which initial verdict applies to this incident?
