Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 3Objective 5

3.5 Identify, Hunt, and Investigate Leads and Indicators of Compromise (IOCs) XDR-ANALYST Practice Questions (Page 1)

Part of the Data Analysis domain, which accounts for 28% of the XDR-ANALYST exam.

29questions here
6free pages
5concepts
28%of the exam

Questions 1–5

  1. 1expert · hard

    During an investigation, an analyst finds a domain that is used by a known APT group. The domain is also used by a commodity malware family. The analyst needs to determine the severity of the threat. Which factor would most increase the severity?

    Select an answer first
  2. 2foundation · easy

    What does it mean for an analyst to 'triage' a lead during an investigation?

    Select an answer first
  3. 3application · easy

    A security analyst is reviewing a list of potential IOCs from a threat intelligence feed. Which item is a network-based indicator of compromise?

    Select an answer first
  4. 4foundation · easy

    Which of the following is a common type of indicator of compromise (IOC)?

    Select an answer first
  5. 5application · medium

    A security team wants to proactively hunt for signs of a known ransomware family that uses a specific file name and a unique registry key. The team has access to endpoint detection and response (EDR) logs and firewall logs. Which search strategy would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.