Palo Alto Networks SecOps-Generalist 시험 개요:
| 인증 벤더: | Palo Alto Networks |
|---|---|
| 시험명: | Palo Alto Networks 보안 운영 일반 전문가 시험 |
| 시험 번호: | SecOps-Generalist |
| 자격증 유효 기간: | 2년 |
| 관련 자격증: | Palo Alto Networks 사이버보안 실무자 Palo Alto Networks 인증 보안 운영 전문가 |
| 실제 시험 문항 수: | 75~90문항 |
| 시험 형식: | 순서 배열형, 객관식, 매칭형 |
| 합격 점수: | 860점 (조정 점수 범위 300~1000점) |
| 지원 언어: | 영어 |
| 응시료: | 200달러 |
| 시험 시간: | 90분 |
| 권장 교육: | Palo Alto Networks 보안 운영 일반 전문가 교육 과정 Cortex 제품 기술 문서 |
| 시험 등록: | Pearson VUE 등록 절차 |
| 샘플 문제: | Palo Alto Networks SecOps-Generalist 샘플 문제 |
| 응시 방법: | Pearson VUE 시험 센터에서 현장 응시 가능; 온라인 감독 방식은 2025년 5월 1일부로 중단됨 |
| 전제 조건: | 필수 선수 요건은 없으며, SOC 운영 및 Palo Alto Cortex 제품에 대한 기본적인 이해가 권장됨 |
| 공식 요강 URL: | https://www.paloaltonetworks.com/services/education/palo-alto-networks-secops-generalist |
Palo Alto Networks SecOps-Generalist 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| 주제 1: Cortex XSOAR | 18% | - 실행 시나리오, 자동화 및 업무 연계 흐름 - 플랫폼 구조 및 핵심 구성 요소 - 연동 기능, 콘텐츠 팩 및 맞춤 설정 - 사건 관리 및 사고 대응 전 과정 자동화 - 위협 정보 관리 및 심층 분석 |
| 주제 2: 위협 정보 및 사고 대응 | 16% | - 위협 탐색 및 오탐/미탐 분석 - 위협 정보 출처: WildFire, Unit 42, 공개 정보 제공망 - 지표 유형: IP, 도메인, URL, 파일 해시, 행동 기반 지표 - 사고 분류, 우선순위 설정 및 처리 방안 - NIST 사고 대응 생애 주기 및 절차 |
| 주제 3: Cortex XDR | 23% | - 사고 조사, 대응 및 복구 조치 - 구성 방식, 센서 및 데이터 수집 - 로그 연계, 인과 관계 분석 및 가시성 확보 - 외부 솔루션 및 위협 정보 제공망과의 연동 - 탐지 규칙, 행동 분석 및 경보 관리 |
| 주제 4: Cortex XSIAM | 18% | - 규제 준수, 보고 및 운영 현황 파악 - 경보 분류, 조사 및 위협 탐지 - 콘텐츠 팩, 규칙 및 분석 모델 - 자동화 기능, 실행 시나리오 및 대응 조치 - 데이터 수집, 정규화 및 상관 관계 분석 |
| 주제 5: 보안 운영 기초 | 25% | - 보고서 작성, 대시보드 및 분석 기능 - 규제 준수 체계 및 데이터 보호 - 로그 관리, 데이터 수집 및 보관 - SOC의 역할, 책임 및 업무 흐름 - 보안 운영에서의 인공지능 및 기계 학습 활용 |
최신 Security Operations Generalist SecOps-Generalist 무료샘플문제
문제 #1
Which Palo Alto Networks Cloud-Delivered Security Services (CDSS) require a firewall to send metadata or copies of suspicious content to a cloud-based analysis or intelligence platform to perform their primary security function? (Select all that apply)
A. Threat Prevention (specifically threat intelligence feeds)
B. WildFire analysis
C. URL Filtering (specifically URL category lookups)
D. App-ID
E. User-ID
문제 #2
A global company is implementing granular control over SaaS application usage using Palo Alto Networks Strata NGFWs at branch offices and Prisma Access for remote users. They have configured decryption policies to inspect SSL/TLS traffic for sanctioned SaaS applications like Office 365 and Salesforce. However, users accessing unsanctioned shadow IT applications via encrypted channels are still successfully bypassing security controls. Additionally, some legitimate applications are experiencing functionality issues after decryption is enabled. What are potential reasons for these issues and necessary steps to address them?
A. Application functionality issues may arise if the application uses client-side certificates, pinned certificates, or relies on specific SSL/TLS negotiation steps that are disrupted by the decryption proxy.
B. Decryption is not properly configured for all relevant traffic zones, causing some encrypted traffic to pass through uninspected.
C. The firewall/Prisma Access might be encountering SSL/TLS protocol versions or cipher suites that are not supported for decryption, leading to decryption failures and fallback to non-decrypted paths (potentially allowing unsanctioned apps).
D. The security policy rules using App-ID are ordered incorrectly, allowing 'allow' rules for 'any' application to match encrypted traffic before the decryption policy is evaluated.
E. The applications identified by App-ID are not all being processed by the decryption policy before reaching security profiles.
문제 #3
A security administrator logging into the AIOps for NGFW dashboard needs a quick overview of the overall health, security posture, and potential operational issues across their fleet of managed firewalls. Which sections or widgets on the AIOps dashboard are designed to provide this high-level summary information?
A. Security Policy rule usage statistics.
B. Configuration logs viewer.
C. Best Practices Assessment score and findings summary.
D. Detailed threat log viewer.
E. Operational Status dashboard, showing critical alerts and key performance indicators (KPIs).
문제 #4
A company is deploying a new internal application that uses a standard web server (HTTPS on port 443) but needs specific security policy enforcement (different from general web browsing) and precise visibility into its usage. App-ID currently identifies this traffic as 'web-browsing'. How can an administrator configure the Palo Alto Networks NGFW (Strata/Prisma SASE) to identify this internal application separately and enable granular policy control?
A. Use a URL Filtering profile to categorize the internal application's URL and apply policy based on that category.
B. Define a custom App-ID signature based on unique characteristics of the application's traffic (e.g., specific HTTP headers, URL patterns), and use this custom App-ID in Security Policy rules.
C. Create a custom Service object for port 443 and use it in the Security policy rule instead of the default 'service-https'.
D. Modify the default 'web-browsing' App-ID signature to exclude traffic to the internal application's IP address.
E. Enable SSL Inbound Inspection for the internal application server and rely on Content-ID to differentiate the traffic.
문제 #5
A large enterprise is migrating some internal applications to a cloud-based Software-as-a-Service (SaaS) model and implementing a SASE architecture leveraging Palo Alto Networks Prisma Access. They are encountering issues with the correct identification and enforcement of policies for a specific custom internal web application that now runs on a standard HTTPS port (443) alongside other legitimate SaaS traffic. The security team needs to ensure this custom application is identified separately from general 'web-browsing' and enforce specific QOS and security profiles on it.
A. Rely on Content-ID to identify the specific application content and apply policies based on content signatures instead of App-ID.
B. Create a custom application signature using App-ID based on unique characteristics of the application's payload or behavior, then create a security policy rule matching this custom App-ID.
C. Configure a URL Filtering profile to block access to the custom application's URL, then allow it in a separate rule with the desired profiles.
D. Modify the default 'web-browsing' application signature to exclude traffic destined for the specific IP address/FQDN of the custom application.
E. Deploy a separate, dedicated Strata NGFW appliance specifically for this custom application traffic before it reaches Prisma Access.
질문과 대답:
| 문제 #1 정답: A,B,C | 문제 #2 정답: A,B,C | 문제 #3 정답: C,E | 문제 #4 정답: B | 문제 #5 정답: B |














1053 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
