Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

Exam SecOps-Pro Topic 1 Question 299 Discussion

Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 299
Topic #: 1
During an incident response, a SOC discovers that a critical application server is exhibiting unusual behavior, including high CPU usage and outbound connections to a known botnet C2. The server is not managed by an EDR solution. Which of the following 'Palo Alto Networks' tools would be most effective for rapid forensic analysis and eradication on this unmanaged server, and what key data would it provide?

Suggested Answer: C Vote an answer

Since the server is unmanaged by an EDR, Cortex XDR's 'Lite' or on-demand deployment capabilities are ideal for rapid forensic collection without a full agent installation. This allows for gathering crucial live data like memory dumps, running processes, and network artifacts. Cortex XDR Pro (A) requires prior deployment. NGFW (B) provides network-level visibility but not direct endpoint forensics. WildFire (D) is for file analysis. Prisma Cloud (E) is for cloud environments.

by Eden at Feb 01, 2026, 06:29 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.