Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

Exam SecOps-Pro Topic 1 Question 62 Discussion

Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 62
Topic #: 1
A global financial institution uses Cortex XDR and XSOAR. They have a stringent regulatory requirement to provide a monthly report detailing all successful and unsuccessful attempts to access sensitive financial applications (identified by specific process names and network destinations) from endpoints outside of their corporate VPN, along with the geo-location of the originating IP addresses. This report must differentiate between attempts originating from managed vs. unmanaged devices. The report needs to be immutable and archived for 7 years in a tamper-proof manner. Which combination of Cortex capabilities, data enrichment, and data handling processes would satisfy these complex requirements?

Suggested Answer: B Vote an answer

Option B is the most complete and compliant solution. Leveraging XQL in CDL provides direct access to the raw security logs. XDR endpoint data is readily available for managed/unmanaged status. Geo-location can be achieved through XQL lookups or XSOAR integration. Critically, XSOAR provides the orchestration for automation, digital signing (for non-repudiation and immutability), and integration with cloud storage like S3 with WORM policies, which is essential for meeting stringent regulatory archiving requirements for 7 years.

by Sylvia at May 15, 2026, 10:28 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.