Exam SecOps-Pro Topic 1 Question 6 Discussion

Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 6
Topic #: 1
A Security Operations Center (SOC) analyst is investigating a suspected ransomware incident using Cortex XSOAR. The incident was triggered by a SIEM alert indicating unusual file encryption activity on a critical server. The analyst needs to rapidly gather forensic data, isolate the compromised host, and enrich the incident with threat intelligence. Which of the following XSOAR features and functionalities would be most effective in automating these initial response steps and accelerating the investigation?

Suggested Answer: B Vote an answer

Option B is the most effective. Cortex XSOAR's strength lies in automation and orchestration. An out-of-the-box integration with a forensic tool (like Velociraptor) allows for automated data collection. A custom script within a playbook can dynamically modify firewall rules for host isolation based on incident context, demonstrating advanced automation. This directly addresses the need for rapid forensic data gathering and host isolation, which are critical initial response steps for ransomware. Options A, C, D, and E are valuable XSOAR features but do not directly address the immediate automation of forensic collection, isolation, and enrichment as effectively as B in the context of rapid initial response.

by Theobald at Oct 04, 2026, 04:59 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10