Exam SecOps-Pro Topic 1 Question 123 Discussion
Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 123
Topic #: 1
Question #: 123
Topic #: 1
An advanced persistent threat (APT) group has successfully breached a large organization's network, and the SOC is in the 'eradication' phase. They have identified several compromised endpoints and a C2 server that the attackers were using. The APT group is known for using custom malware variants and sophisticated evasion techniques. Which of the following set of actions and Palo Alto Networks tools, when combined, offers the most robust and proactive approach to eradicating the threat, preventing re-infection, and improving future detection capabilities?
Suggested Answer: C Vote an answer
This question requires a multi-faceted approach to address an APT in the eradication phase, focusing on preventing re-infection and improving future detection.
1. Network Segmentation/Micro-segmentation: Crucial for preventing lateral movement and containing future breaches. By segmenting the network, even if one segment is compromised, the blast radius is limited. While NSX is mentioned, the core concept is micro-segmentation, which Palo Alto NGFWs can also enforce.
2. WildFire for Custom Threat Intelligence: Since the APT uses custom malware, WildFire is essential for analyzing these unique samples, generating new signatures and IOCs.
3. Pushing IOCs to all Security Controls (MineMeId/Custom Integration): This is paramount for proactive defense. Newly generated IOCs from WildFire must be immediately pushed to the NGFW (for blocking at the perimeter/internal segments), Cortex XDR (for endpoint detection and prevention), and the SIEM (for correlation and alerting). MineMeld is a Palo Alto Networks tool for sharing and consuming threat intelligence.
4. XQL Hunt in Cortex XDR: An APT attack implies a persistent, broader compromise. An XQL hunt across the entire environment is essential to find any other instances of the attack, un-identified compromised systems, or remnants of the APT activity. This moves beyond simple eradication to ensuring full scope and preventing re-infection from overlooked components.
Let's evaluate other options:
A: While good, simply deploying XDR and blocking IPs is insufficient for an APT that uses evasive custom malware and potentially dynamic C2s.
B: Re-imaging is part of eradication, but updating AV signatures alone won't protect against custom, zero-day malware.
D: Blocking all outbound traffic is too disruptive and not sustainable. MFA is crucial but a preventative measure, not an eradication strategy for an active APT.
E: Disabling accounts and vulnerability scans are important steps but not comprehensive enough for eradicating a sophisticated APT and building future resilience.
1. Network Segmentation/Micro-segmentation: Crucial for preventing lateral movement and containing future breaches. By segmenting the network, even if one segment is compromised, the blast radius is limited. While NSX is mentioned, the core concept is micro-segmentation, which Palo Alto NGFWs can also enforce.
2. WildFire for Custom Threat Intelligence: Since the APT uses custom malware, WildFire is essential for analyzing these unique samples, generating new signatures and IOCs.
3. Pushing IOCs to all Security Controls (MineMeId/Custom Integration): This is paramount for proactive defense. Newly generated IOCs from WildFire must be immediately pushed to the NGFW (for blocking at the perimeter/internal segments), Cortex XDR (for endpoint detection and prevention), and the SIEM (for correlation and alerting). MineMeld is a Palo Alto Networks tool for sharing and consuming threat intelligence.
4. XQL Hunt in Cortex XDR: An APT attack implies a persistent, broader compromise. An XQL hunt across the entire environment is essential to find any other instances of the attack, un-identified compromised systems, or remnants of the APT activity. This moves beyond simple eradication to ensuring full scope and preventing re-infection from overlooked components.
Let's evaluate other options:
A: While good, simply deploying XDR and blocking IPs is insufficient for an APT that uses evasive custom malware and potentially dynamic C2s.
B: Re-imaging is part of eradication, but updating AV signatures alone won't protect against custom, zero-day malware.
D: Blocking all outbound traffic is too disruptive and not sustainable. MFA is crucial but a preventative measure, not an eradication strategy for an active APT.
E: Disabling accounts and vulnerability scans are important steps but not comprehensive enough for eradicating a sophisticated APT and building future resilience.
by Walter at Oct 01, 2026, 03:42 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).