
Palo Alto NetworksCertified XDR Analyst
Domain 1Objective 2
1.2 Explain the Alert Prioritization Handling Process XDR-ANALYST Practice Questions (Page 2)
Part of the Alerting and Detection Processes domain, which accounts for 23% of the XDR-ANALYST exam.
20questions here
4free pages
4concepts
23%of the exam
Questions 6–10
- 6
In the Palo Alto Networks XDR alert prioritization process, what does the incident score primarily determine?
Select an answer first - 7
A SOC has a custom prioritization rule that subtracts 10 points from alerts involving the 'Guest' asset group. An alert is generated for a guest user's device with a default incident score of 45. However, the alert involves a known advanced persistent threat (APT) that the default scoring model does not account for. The SOC manager wants this alert to be investigated despite the custom rule. What is the most effective way to handle this situation?
Select an answer first - 8
Which of the following is a valid action when configuring a custom prioritization rule in Palo Alto Networks XDR?
Select an answer first - 9
Which of the following is an example of a featured field in the Palo Alto Networks XDR alert view?
Select an answer first - 10
An analyst wants to customize the alert view to show the asset criticality and the incident score for each alert. This will help the analyst quickly identify which alerts involve the most important assets and have the highest risk. Which featured fields should the analyst add to the view?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.