Exam SecOps-Pro Topic 1 Question 84 Discussion

Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 84
Topic #: 1
A SOC analyst observes a sudden, significant increase in outbound DNS queries from an internal host to unusual top-level domains (TLDs) that are not typically accessed by the organization. The host is an unpatched legacy server. Which of the following SOC functions is primarily responsible for detecting and initiating the response to this activity, and what is the most immediate, high-priority action they should recommend?

Suggested Answer: B Vote an answer

The primary function responsible for detecting such anomalies in real-time is Security Monitoring & Alerting. The most immediate and critical high-priority action for a suspected compromise, especially with unusual outbound C2-like traffic, is to isolate the host to prevent further spread or data exfiltration. While other options are valid SOC functions, their priority in this immediate scenario is lower. Threat Intelligence would follow the initial detection, Incident Response would encompass the isolation and subsequent steps, Vulnerability Management addresses the root cause but not the immediate threat, and Forensics comes after containment.

by Albert at Jul 24, 2026, 01:24 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10