
Palo Alto NetworksCertified XDR Analyst
Domain 2Objective 2
2.2 Identify and Analyze Security Events and Incidents XDR-ANALYST Practice Questions (Page 4)
Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.
34questions here
7free pages
7concepts
34%of the exam
Questions 16–20
- 16
A security analyst notices a high volume of outbound traffic from a server to a cloud storage provider. The traffic is encrypted and occurs during business hours. The server is not known to use cloud storage. What should the analyst do to determine if this is a security event?
Select an answer first - 17
What is the primary goal of threat analysis in the context of incident handling?
Select an answer first - 18
A company experienced a ransomware attack. The investigation reveals that the attacker gained access through a VPN account that did not have multi-factor authentication (MFA) enabled. The VPN account belonged to a former employee. What is the root cause of this incident?
Select an answer first - 19
An organization is experiencing a series of low-severity alerts: failed logins, port scans, and phishing emails. Individually, these are not significant. However, the analyst notices that they all originate from the same external IP range. What should the analyst do?
Select an answer first - 20
An analyst observes a series of outbound connections from a single host to a known malicious IP address on port 443. The connections occur every 5 minutes and the payloads are encrypted. What should the analyst do to determine the nature of the threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.