
Palo Alto NetworksCertified XDR Analyst
Domain 3Objective 5
3.5 Identify, Hunt, and Investigate Leads and Indicators of Compromise (IOCs) XDR-ANALYST Practice Questions (Page 1)
Part of the Data Analysis domain, which accounts for 28% of the XDR-ANALYST exam.
29questions here
6free pages
5concepts
28%of the exam
Questions 1–5
- 1
During an investigation, an analyst finds a domain that is used by a known APT group. The domain is also used by a commodity malware family. The analyst needs to determine the severity of the threat. Which factor would most increase the severity?
Select an answer first - 2
What does it mean for an analyst to 'triage' a lead during an investigation?
Select an answer first - 3
A security analyst is reviewing a list of potential IOCs from a threat intelligence feed. Which item is a network-based indicator of compromise?
Select an answer first - 4
Which of the following is a common type of indicator of compromise (IOC)?
Select an answer first - 5
A security team wants to proactively hunt for signs of a known ransomware family that uses a specific file name and a unique registry key. The team has access to endpoint detection and response (EDR) logs and firewall logs. Which search strategy would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.