
Palo Alto NetworksCertified XDR Analyst
Domain 2Objective 2
2.2 Identify and Analyze Security Events and Incidents XDR-ANALYST Practice Questions (Page 2)
Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.
34questions here
7free pages
7concepts
34%of the exam
Questions 6–10
- 6
Why is accurate incident documentation important in incident handling?
Select an answer first - 7
A security analyst discovers that a database containing customer payment information was accessed by an unauthorized user. The analyst determines that the data was likely exfiltrated. What should the analyst do to classify the incident?
Select an answer first - 8
What is the primary purpose of correlating security events from multiple sources?
Select an answer first - 9
An analyst is investigating an alert about a suspicious process that is making outbound connections to an IP address that is not on any threat intelligence feed. The process is signed by a legitimate vendor. What should the analyst do to determine the nature of the threat?
Select an answer first - 10
An analyst discovers a malware infection on a single non-critical workstation. The malware has not spread and no sensitive data has been accessed. According to common incident classification practices, how should this incident be categorized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.