
Palo Alto NetworksCertified XDR Analyst
Domain 2Objective 4
2.4 Identify and Explain Exclusions and Exceptions XDR-ANALYST Practice Questions (Page 6)
Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.
33questions here
7free pages
9concepts
34%of the exam
Questions 26–30
- 26
In the context of XDR, what is the primary purpose of an exclusion?
Select an answer first - 27
A security analyst creates an alert exception to suppress a false positive for a specific user's login activity. The exception is configured with the user's username and a specific source IP. After a week, the analyst notices that alerts are appearing for the same user from a different source IP. The exception is still enabled and the username matches. What is the most likely reason the exception is not suppressing the new alerts?
Select an answer first - 28
In the XDR platform, what does the 'scope' of an exclusion define?
Select an answer first - 29
A security analyst creates a file-path exclusion for a directory where a development team stores build artifacts. After the exclusion is applied, the analyst notices that alerts for a specific malware family are no longer appearing, but the team confirms the malware is not present in the build directory. What is the most likely reason for the missing alerts?
Select an answer first - 30
In the XDR platform, how can an analyst temporarily stop an exclusion from being applied without deleting it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.