
Palo Alto NetworksCertified XDR Analyst
Domain 1Objective 2
1.2 Explain the Alert Prioritization Handling Process XDR-ANALYST Practice Questions (Page 3)
Part of the Alerting and Detection Processes domain, which accounts for 23% of the XDR-ANALYST exam.
20questions here
4free pages
4concepts
23%of the exam
Questions 11–15
- 11
A SOC has a custom prioritization rule that adds 15 points to alerts from the 'Finance' asset group. An alert is generated for a Finance server with a default incident score of 70. However, the alert is a false positive that was triggered by a routine backup process. The SOC manager wants to prevent this type of alert from being prioritized in the future. What is the most effective way to handle this?
Select an answer first - 12
A junior analyst has been asked to flag a set of alerts that require further investigation by the senior team. The junior analyst wants to ensure these alerts are easily identifiable in the shared queue. What should the junior analyst do?
Select an answer first - 13
In Palo Alto Networks XDR, what is the purpose of configuring custom prioritization rules?
Select an answer first - 14
An organization has a custom prioritization rule that adds 20 points to any alert involving the 'Executive' asset group. An alert is generated for an executive's laptop that has a default incident score of 60. What is the final incident score for this alert?
Select an answer first - 15
What is the primary purpose of starring an alert in Palo Alto Networks XDR?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.