
Palo Alto NetworksCertified XDR Analyst
Domain 2Objective 4
2.4 Identify and Explain Exclusions and Exceptions XDR-ANALYST Practice Questions (Page 5)
Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.
33questions here
7free pages
9concepts
34%of the exam
Questions 21–25
- 21
A security analyst creates an alert exception to suppress a known false positive. After a week, the analyst notices that the exception is no longer being applied and alerts are appearing again. The exception appears in the list as enabled. What is the most likely cause of this issue?
Select an answer first - 22
A large enterprise has a security operations team that manages XDR for 10,000 endpoints. The team is investigating a series of alerts for a legitimate software update tool. The tool's executable hash changes with each update, but the installation path is consistent. The team wants to suppress alerts for the tool without creating a broad security gap. They also need to ensure that if the tool's path is compromised, the exclusion does not hide the threat. What is the most appropriate approach?
Select an answer first - 23
A security team is investigating a series of alerts related to a legitimate internal tool that communicates with an external API. The tool's IP address changes frequently, but its domain name is static. The team wants to suppress alerts for the tool's network traffic while preserving detection for other traffic. What is the most appropriate exclusion type to use?
Select an answer first - 24
An organization wants to allow a specific user to run a particular administrative tool that is normally blocked by a security policy. Which type of exception should be created?
Select an answer first - 25
What is a recommended practice for maintaining exceptions to minimize security gaps?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.