
Palo Alto NetworksCertified XDR Analyst
Domain 1Objective 3
1.3 Explain the Incident Creation Process XDR-ANALYST Practice Questions (Page 3)
Part of the Alerting and Detection Processes domain, which accounts for 23% of the XDR-ANALYST exam.
34questions here
7free pages
7concepts
23%of the exam
Questions 11–15
- 11
A SOC manager wants to ensure that when a high-severity incident is created, the incident commander is notified via SMS, while lower-severity incidents only send an email to the general SOC mailbox. What should be configured?
Select an answer first - 12
During triage, an analyst opens an incident and needs to quickly understand the affected hosts, users, and files, as well as the current status and severity. Where should the analyst look within the incident view?
Select an answer first - 13
An organization has two separate security tools that generate alerts: one for endpoint and one for network. The XDR platform is ingesting alerts from both. Currently, the same attack may generate two separate incidents because the alerts are not being correlated. The SOC wants to ensure that alerts from the same attack are grouped into a single incident. What is the most effective way to achieve this?
Select an answer first - 14
An organization has a detection rule that generates an alert for any outbound connection to a known malicious IP. Recently, the SOC has been overwhelmed by a high volume of alerts from a single compromised host, each creating a separate incident. What is the most effective way to reduce the number of incidents while still detecting the threat?
Select an answer first - 15
A SOC manager wants to ensure that when a specific type of alert is detected, an incident is automatically created and assigned to a particular analyst group, and a notification is sent. What should the manager configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.