Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 1Objective 1

1.1 Identify and Explain Different Types of Alerts and Alert Sources XDR-ANALYST Practice Questions (Page 1)

Part of the Alerting and Detection Processes domain, which accounts for 23% of the XDR-ANALYST exam.

19questions here
4free pages
5concepts
23%of the exam

Questions 1–5

  1. 1expert · hard

    A SOC team is overwhelmed by a high volume of low-severity alerts from multiple sources. They want to reduce false positives and identify complex threats that span the network and endpoints. They have already implemented basic alert rules. Which approach would most effectively achieve their goal?

    Select an answer first
  2. 2application · medium

    A company uses an XDR platform that ingests data from its firewall, endpoint agents, and a third-party cloud access security broker (CASB). An analyst notices an alert that was generated solely from the CASB's log of an anomalous file download from a sanctioned cloud app. The endpoint agent and firewall did not report any related activity. What is the most likely source of this alert?

    Select an answer first
  3. 3application · medium

    A company's XDR platform receives alerts from its endpoint agents, network firewalls, and a third-party threat intelligence feed. An alert is generated when an endpoint's DNS query matches a domain from the threat intelligence feed. What is the primary source of this alert?

    Select an answer first
  4. 4application · medium

    A company uses an XDR platform that collects data from its network firewalls, endpoint agents, and a cloud access security broker (CASB). An alert is generated when a user uploads a file to a sanctioned cloud app that contains sensitive data. The alert is based on the CASB's data loss prevention (DLP) rules. What is the primary source of this alert?

    Select an answer first
  5. 5application · medium

    A security operations center (SOC) analyst is investigating an alert that was triggered when an endpoint executed a process that exactly matched a known malware signature. The alert is classified as critical. Which alert generation mechanism most likely produced this alert?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.