About the Exam

Validates job-ready skills for applying Palo Alto Networks Cortex products and related technologies in a security operations center (SOC). It covers SOC concepts and tasks including threats, alerts, incidents, vulnerabilities, and compliance. It is intended for security operations administrators, analysts, incident responders, threat researchers, and others validating Cortex product knowledge.

Exam Topics

  • Security Operations Fundamentals25%
  • Threat Intelligence and Incident Response16%
  • Cortex XDR23%
  • Cortex XSOAR16%
  • Cortex XSIAM20%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 5, 2026 at 4:57 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Threat Intelligence and Incident Response

What role does incident response have in managing cybersecurity incidents?

  • A Scheduling regular software updates and maintenance to prevent potential cyber threats
  • B Providing structured methods for investigating, containing, and eradicating cyber threats
  • C Notifying external authorities and stakeholders immediately after a cyber threat is detected
  • D Monitoring network traffic and creating comprehensive Security policies
Explanation

Incident response provides a structured process for investigating an incident, containing its effects, eradicating the threat, and supporting recovery.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Cortex XSIAM

Which sensor does Cortex XSIAM use to detect and collect DNS queries, HTTP headers, and DHCP information?

  • A Windows Event Collector logs
  • B Directory Sync logs
  • C Pathfinder data collector
  • D Enhanced application logs
Explanation

Enhanced Application Logs (EAL) is the sensor/telemetry source that supplies the analytics engine with high-fidelity network context, including DNS queries, HTTP header (User-Agent) fields, and DHCP information generated by the NGFW. Palo Alto documentation and the analytics-sensors material state that enhanced application logs are designed to increase visibility by capturing DNS, DHCP, and URL/HTTP data that basic traffic logs miss. The Pathfinder data collector (C) is different: it interrogates unmanaged hosts/endpoints for risky software, not DNS/HTTP/DHCP network telemetry. Directory Sync (B) provides identity/AD data, and Windows Event Collector logs (A) are host event logs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Cortex XSIAM

Which task is mainly handled by Identity Analytics?

  • A Policy enforcement
  • B Threat intelligence ingestion
  • C Credential phishing detection
  • D Suspicious login identification
Explanation

Identity Analytics analyzes authentication and identity activity for abnormal behavior and can alert on suspicious logins, such as a successful login following several failed attempts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Cortex XDR

An incident response team must correlate suspicious events across NGFW logs, cloud-workload alerts, and compromised user-account activity reported by the identity provider (IdP).

Which capability makes Cortex XDR the superior tool for these investigations compared with endpoint detection and response (EDR) solutions offered elsewhere?

  • A Ability to perform forensic data collection directly on the host
  • B Unified ingestion and normalization of data from non-endpoint sources like network and cloud platforms
  • C Reliance on signature-based prevention for known malware
  • D Requirement for a separate Security Information and Event Management (SIEM) solution for speed and efficiency
Explanation

Cortex XDR extends investigation and correlation beyond endpoint telemetry by ingesting and normalizing relevant network, cloud, and identity-source data. This enables analysts to connect activity across NGFW logs, cloud workloads, and IdP-reported account compromise in one investigation.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Cortex XSIAM

An organization needs a security solution that provides comprehensive threat visibility across its full digital ecosystem—including firewalls, cloud environments, and user-authentication logs—rather than only endpoint data.

Which Palo Alto Networks solution is best suited to satisfy this expanded requirement?

  • A Cortex endpoint protection platform (EPP)
  • B Cortex XDR
  • C Cortex Cloud Identity Engine
  • D Cortex XSIAM
Explanation

Cortex XSIAM centralizes and normalizes security telemetry from endpoints, firewalls and other network devices, cloud audit sources, identity systems, and third-party tools. Its onboarding guidance specifically covers next-generation firewall data, cloud audit logs, and identity/user data, making it the appropriate platform for full-ecosystem threat visibility rather than endpoint-focused protection.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home