Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 4

2.4 Identify and Explain Exclusions and Exceptions XDR-ANALYST Practice Questions (Page 3)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
9concepts
34%of the exam

Questions 11–15

  1. 11expert · hard

    A security team is managing XDR for a global organization. They have a correlation rule that alerts when a user accesses a sensitive folder from a new location. The team wants to suppress alerts for a group of executives who frequently travel, but they still want to be alerted if an executive's account is used from a location that is not in their travel history. What is the most appropriate exception to create?

    Select an answer first
  2. 12foundation · easy

    What is the impact of an exception on the detection and alerting process?

    Select an answer first
  3. 13expert · hard

    A security administrator is troubleshooting an exclusion that is not suppressing alerts as expected. The exclusion is a path-based exclusion for a directory where a legitimate application stores logs. The administrator verifies that the path is correct and the exclusion is enabled. However, alerts are still being generated for files in that directory. What is the most likely cause of this issue?

    Select an answer first
  4. 14application · medium

    A security analyst notices that the XDR platform is generating alerts for a legitimate internal vulnerability scanner. The scanner's IP address is known and static. The analyst wants to suppress alerts from this specific source while still allowing the detection engine to analyze the scanner's behavior for anomalies. What is the most appropriate exception type to create?

    Select an answer first
  5. 15application · medium

    A security administrator is reviewing the XDR platform's exclusion list and notices that an exclusion created for a legacy application is no longer needed because the application was decommissioned. The administrator wants to ensure the exclusion does not continue to suppress detections. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.