Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 4

2.4 Identify and Explain Exclusions and Exceptions XDR-ANALYST Practice Questions (Page 4)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
9concepts
34%of the exam

Questions 16–20

  1. 16foundation · easy

    An analyst wants to exclude a specific file from detection because it is a known benign executable. Which type of exclusion should they use?

    Select an answer first
  2. 17foundation · easy

    An analyst notices that an exclusion is not suppressing alerts as expected. What is the most likely cause?

    Select an answer first
  3. 18application · medium

    A security analyst needs to create an exclusion for a specific file that is known to be benign but triggers a false positive. The analyst wants to ensure the exclusion is applied only to the endpoint where the file is known to be legitimate. What is the most appropriate scope to configure when creating the exclusion?

    Select an answer first
  4. 19expert · hard

    A security operations team is configuring XDR for a new subsidiary. The subsidiary uses a legacy application that creates files with a consistent naming pattern but in different directories across multiple servers. The team wants to suppress alerts for these files without creating a broad exclusion that could hide a real threat. They also want to ensure that if the application is compromised, the exclusion does not prevent detection of malicious files with the same naming pattern. What is the most appropriate approach?

    Select an answer first
  5. 20application · medium

    A financial services firm deploys a proprietary trading application that writes large, frequently-updated binary files to a dedicated server. The security team has confirmed the application's behavior is benign via sandbox analysis. However, the XDR platform is generating a high volume of alerts because the binary files match a known malware hash signature. The team wants to stop the alert noise without disabling detection for the rest of the environment. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.