SecOps-Pro Exam Question 31
What can be used to triage and determine if an artifact in Cortex XDR is malicious?
SecOps-Pro Exam Question 32
An organization requires a security solution that offers comprehensive threat visibility across their entire digital ecosystem, including firewalls, cloud environments, and user authentication logs, not just endpoint data. Which Palo Alto Networks solution is best suited to meet this extended requirement?
SecOps-Pro Exam Question 33
An incident in Cortex XSIAM displays alerts for "Lsass Memory Dump" originating from a process named proc_dump.exe. The process is unsigned, has an unknown reputation, and was launched from a temporary directory. Which initial verdict applies to this incident?
SecOps-Pro Exam Question 34
A custom script activity, previously categorized as non-malicious, suddenly begins executing a series of unusual file operations and network connections. Cortex XDR detects this change, aggregates the sequence of abnormal events, and immediately raises a high-severity alert. Which Cortex XDR capability uses statistical baselining and machine learning to specifically identify this type of activity?
SecOps-Pro Exam Question 35
What are two ways a security team assigns priority to security incidents in Cortex XDR? (Choose two.)
