최신 Security Operations Generalist SecOps-Pro 무료샘플문제:
1. A security analyst is tuning Cortex XDR after a custom application, which uses the mshta.exe utility with a legitimate internal script, triggers a behavioral threat alert. The administrator must ensure the legitimate script runs without detection. Which set of criteria must be included in the new exception rule to prevent future false positives while maintaining protection against similar malicious activity?
A) Signature or signer of the mshta.exe binary
B) Alert exclusion that is based on the name of the threat
C) File name hash (SHA256) of the mshta.exe file
D) Exception based on the process path and script command-line arguments
2. What are two outcomes of threat intelligence in a SOC? (Choose two.)
A) Reduction of the number of alerts observed in an incident
B) Enablement of security operations teams to reduce workload through automation
C) Identification and detection of known threat verdicts to improve company security posture
D) Mitigation of potential risks to systems and data
3. Which two statements apply to creating scripts in Cortex XSOAR? (Choose two.)
A) They can be executed with higher permissions.
B) They can be protected using a password.
C) They can be scheduled to run at a later time and day.
D) They can be written using Java.
4. Which function eliminates the need for manual analysis in an organization with multiple data sensors?
A) Log stitching
B) Event log query
C) Log correlation
D) Log forwarding
5. Which query language will perform a deep investigation into a series of potential endpoint attacks by searching across all collected event data using Cortex XDR Query Builder?
A) XQL
B) KQL
C) SPL
D) SQL
질문과 대답:
| 질문 # 1 정답: D | 질문 # 2 정답: C,D | 질문 # 3 정답: A,C | 질문 # 4 정답: C | 질문 # 5 정답: A |














773 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
