01. A detection rule is technically accurate but generates alerts for low-risk activity that does not require analyst action.
What should the architect recommend?
a) Increase dashboard visibility for the low-risk alert category
b) Migrate the alert unchanged to preserve detection volume
c) Tune the detection use case to align with operational value
d) Disable all telemetry sources that contribute to the alert
02. An architect is explaining to stakeholders why a proposed agentic-automation capability differs from the deterministic playbooks the SOC already runs.
Which statement BEST captures what distinguishes agentic automation for this decision?
a) It eliminates the SOC's dependence on reliable telemetry
b) It adapts its investigation actions to the context of each incident
c) It executes only fixed, predefined steps with no contextual decisions
d) It removes the governance and oversight required for response actions
03. A retailer is formalizing how detection content reaches production safely.
Which two practices support safe production deployment of detection content?
(Choose two.)
a) Validate rule behavior in a development tenant first
b) Follow approved release and change-control processes
c) Remove analyst review from every detection change
d) Deploy experimental rules directly into production tenants
e) Disable telemetry validation once a rule is deployed
04. A SOC team wants to migrate legacy SIEM rules into Cortex XSIAM but discovers that several rules depend on telemetry sources not yet onboarded.
Which migration approach BEST reduces detection gaps?
a) Enable all migrated rules immediately using available partial data
b) Prioritize onboarding required telemetry before enabling migrated rules
c) Disable all legacy detections before validating Cortex XSIAM rules
d) Replace missing telemetry requirements with dashboard-only reporting
05. A SOC plans to deploy a detection use case that requires endpoint, cloud, and identity telemetry. Cloud telemetry onboarding is incomplete.
What should the architect recommend?
a) Complete required telemetry onboarding before production enablement
b) Replace detection logic with dashboard-only visualization
c) Disable endpoint telemetry until cloud onboarding is complete
d) Enable the use case immediately using partial telemetry coverage
06. A fast-growing software company has a small detection-engineering team and far more candidate use cases than it can build.
What is the primary purpose of prioritizing detection use cases in this situation?
a) Ensure equal engineering time is spent on every candidate use case
b) Direct limited engineering effort to the highest-risk, highest-value threats first
c) Remove the need to validate telemetry quality for each use case
d) Decide the retention period for the data each detection uses
07. A biotech's detection engineers need to iterate rapidly on new rules and tune them against realistic data without any chance of disrupting live monitoring.
What is the primary benefit of giving them a development tenant?
a) It replaces production telemetry with synthetic data for live monitoring
b) It lets faulty rules run in production while engineers debug them
c) It removes change-control requirements from production releases
d) They can test and tune detection logic safely before promoting it to production
08. At a cloud-native fintech, a privilege-escalation detection only produces alerts when the identity logs it depends on arrive on time; delayed logs cause missed detections.
Which architecture issue should the architect address?
a) The reliability and ingestion timing of the identity telemetry
b) Whether identity logs are stored in a hot or cold retention tier
c) The order in which identity sources were originally onboarded
d) The severity label assigned to the detection rule
09. A legacy SIEM detection uses a custom field that is transformed differently in Cortex XSIAM.
What should the architect do BEFORE enabling the migrated detection?
a) Route the legacy rule output only to executive dashboards
b) Disable normalization for that telemetry source permanently
c) Enable the rule unchanged to preserve legacy alert behavior
d) Validate field mapping and update detection logic accordingly
10. A SaaS provider's SOC handles a high daily volume of near-identical phishing-report triage, each following the same investigative steps.
Which capability is best suited to this work?
a) A dashboard filter that displays the reports without executing steps
b) Unrestricted manual investigation by each individual analyst
c) A deterministic playbook that executes the defined triage workflow
d) An open-ended agentic assistant that decides the steps case by case