SecOps-Professional Sample Questions

SecOps-Professional Sample Questions & Answers

Ranges across Cortex XDR elements and agent management tied closely with SOC fundamentals, plus Cortex XSIAM's components, processes and capabilities, NIST-based incident response and threat intelligence, and the difference between Cortex XSOAR scripts and jobs.

Launch the full SecOps-Professional simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Security Operations Fundamentals · Reports and dashboards creation

    While configuring a scheduled report in Cortex XDR, an analyst wants to ensure the report is generated every Monday at 8:00 AM and emailed to the compliance team. Which configuration setting handles the timing and distribution?

    Show answer & explanation

    Correct answer: A

    The Scheduling Settings within the report configuration specifically define the recurrence pattern (Frequency) and the distribution list (Recipients).

  2. Question 2Advanced

    Security Operations Fundamentals · AI and Machine Learning in SecOps

    An organization is using Cortex XDR Analytics. Which of the following best describes how the analytics engine establishes a baseline for 'normal' user behavior?

    Show answer & explanation

    Correct answer: B

    Cortex XDR Analytics uses unsupervised machine learning to observe specific environmental activity over time, creating unique baselines for users and entities rather than relying on generic global baselines.

  3. Question 3Intermediate

    Security Operations Fundamentals · SOC components and functions

    A SOC team is experiencing 'alert fatigue' due to a high volume of low-fidelity alerts. Which feature in the Cortex portfolio is designed to group related alerts into a single actionable item to reduce analyst workload?

    Show answer & explanation

    Correct answer: D

    Cortex XDR and XSIAM group related alerts into 'Incidents' using SmartGrouping logic. This stitches together alerts that share causality, time, or entities, presenting the analyst with a single incident rather than dozens of individual alerts.

  4. Question 4Advanced

    Security Operations Fundamentals · Cortex XDR user, role, and log management

    Case Study: An organization has three distinct SOC teams: Tier 1 (Triage), Tier 2 (Investigation), and Tier 3 (Threat Hunting/Engineering).

    The Tier 2 team needs access to create and modify dashboards to track specific malware campaigns but should not be able to modify global server configurations.

    Which RBAC strategy is most appropriate?

    Show answer & explanation

    Correct answer: D

    This custom role precisely matches the requirements: allowing dashboard modification while restricting configuration changes to read-only, preventing accidental disruption of global settings.

  5. Question 5Intermediate

    Security Operations Fundamentals · Cortex XDR user, role, and log management

    What is the primary function of the 'Broker VM' in a Cortex XDR deployment regarding log management?

    Show answer & explanation

    Correct answer: D

    The Broker VM serves as a local concentrator that ingests logs from various on-premise sources (Syslog, Windows Events, etc.) and securely forwards them to the cloud-based Cortex Data Lake.

  6. Question 6Intermediate

    Security Operations Fundamentals · Reports and dashboards creation

    Which reporting feature would you use to automatically notify a specific user group when a 'Critical' severity incident remains in 'New' status for more than 4 hours?

    Show answer & explanation

    Correct answer: A

    Notification Rules allow for real-time or logic-based alerting based on incident attributes (Severity, Status) and duration, ideal for SLA breach notifications.

  7. Question 7Advanced

    Security Operations Fundamentals · AI and Machine Learning in SecOps

    When integrating Machine Learning (ML) models into security operations, what is a primary risk of 'over-tuning' a model to a specific dataset?

    Show answer & explanation

    Correct answer: C

    Overfitting (over-tuning) occurs when a model learns the training data too well, including noise, making it unable to generalize to new, unseen threats, which is critical in security where threats constantly evolve.

  8. Question 8Intermediate

    Threat Intelligence and Incident Response · NIST incident response plan

    According to the NIST Incident Response lifecycle, during which phase would an analyst utilize Cortex XDR's 'Network Isolation' feature to stop a ransomware propagation?

    Show answer & explanation

    Correct answer: A

    Network Isolation is a containment action designed to prevent the spread of a threat while keeping the asset available for investigation. This maps directly to the Containment phase of the NIST framework.

    flowchart LR P[Preparation] --> DA[Detection & Analysis] DA --> C[Containment] C --> E[Eradication] E --> R[Recovery] R --> PA[Post-Incident Activity] style C fill:#f96,stroke:#333,stroke-width:2px
  9. Question 9Intermediate

    Threat Intelligence and Incident Response · WildFire, Unit 42, and VirusTotal

    You receive a WildFire verdict of 'Grayware' for a specific file hash. What does this verdict indicate about the file?

    Show answer & explanation

    Correct answer: B

    Grayware refers to applications that may not be malicious in the traditional sense (like viruses) but are annoying or unwanted, such as adware, spyware, or browser toolbars.

  10. Question 10IntermediateSelect 2

    Threat Intelligence and Incident Response · Indicator types and usage

    In Cortex XDR, which of the following indicator types can be manually added to a Blocklist to prevent execution or communication? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    IP Addresses can be blocklisted to prevent network communication with malicious hosts.

    File Hashes (SHA256) are a primary indicator type for blocklisting to prevent file execution.

Ready for the real thing?

The full SecOps-Professional simulator has every exam-style question, timed mode, and instant scoring.