
SOC Fundamentals · Incident Response & Threat Intel · Cortex XDR Investigations · XSOAR Automation · XSIAM Analytics
60 questions · 90 min · 70% Techclick practice target
⚠️ Exam Rules
| Questions in this Techclick bank | 60 |
|---|---|
| Timer | 90 min |
| Techclick practice target | 70% |
| Official exam code | SecOps-Pro |
A SOC manager is measuring whether analysts are containing intrusions faster after a tooling change. Which metric most directly reflects containment speed rather than detection speed?
Correct: D. Mean time to respond captures the interval in which the analyst actually acts to contain the threat, which is what a containment improvement should move. Mean time to detect measures visibility rather than response, alert volume describes workload, and false positive rate describes tuning quality, so none of those isolate containment speed.
An analyst investigating an intrusion maps observed behaviour to ATT&CK and finds the adversary dumped LSASS memory. Which ATT&CK tactic does that behaviour belong to?
Correct: C. LSASS holds authentication material, so dumping it maps to Credential Access under the OS Credential Dumping technique. It is not Initial Access because the adversary already has code execution, it is not Exfiltration until the material actually leaves the network, and it is not Impact because the system keeps functioning normally.
A SOC lead is defining what belongs in a tier-1 triage runbook versus tier-2 investigation. Select the TWO activities that belong in tier-1 triage. (Choose TWO)
Correct: C and D. Tier-1 triage is about rapid validation and enrichment so that genuine incidents escalate quickly and known-benign noise is closed with evidence. Reverse engineering and detection engineering are specialist tier-2 or tier-3 work, and disclosure negotiation is an incident management responsibility outside the triage queue entirely.
During a tabletop exercise the team debates when the eradication phase begins. According to the standard incident response lifecycle, what must be true before eradication starts?
Correct: A. Eradication follows containment because removing artefacts while an adversary still holds active access simply invites immediate re-entry. The post-incident report belongs to lessons learned, rebuilding systems is part of recovery which comes after eradication, and attribution is useful intelligence but is not a gate for removing the threat.
An analyst receives an alert for outbound traffic to a domain first registered four hours ago, with low request volume and regular timing. Which adversary behaviour does this pattern most strongly suggest?
Correct: D. Low volume with regular timing to a very recently registered domain is the classic signature of implant check-in traffic. Bulk exfiltration produces large asymmetric transfers, internal reconnaissance stays inside the network rather than reaching an external domain, and credential stuffing generates high request volume against a known service.
Last updated:
Yes. You can start, finish and score it for free, and download the Techclick practice certificate.
This bank has 60 original scenario-based questions with a 90-minute timer and a 70% Techclick practice target.
The official exam code is SecOps-Pro (Palo Alto Networks).
No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.
Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Palo Alto Networks certification.
Related practice tests: Palo Alto Networks PCXSA, Palo Alto Networks XSOAR-ANALYST, Palo Alto Networks NetSec-Pro, Palo Alto Networks NGFW, Palo Alto PCCET, Palo Alto Networks PCCSE (linked below).

You earned it — let the world know!
