Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 3Objective 5

3.5 Identify, Hunt, and Investigate Leads and Indicators of Compromise (IOCs) XDR-ANALYST Practice Questions (Page 2)

Part of the Data Analysis domain, which accounts for 28% of the XDR-ANALYST exam.

29questions here
6free pages
5concepts
28%of the exam

Questions 6–10

  1. 6application · medium

    An analyst is investigating an alert about a suspicious PowerShell command that was executed on a server. The command is not on any blocklist, but it does download a file from an external IP. The analyst wants to determine if this is a true positive. Which evidence would be most convincing?

    Select an answer first
  2. 7foundation · easy

    How does threat intelligence help an analyst correlate an IOC with a known threat actor?

    Select an answer first
  3. 8foundation · easy

    What is a key characteristic of well-structured documentation for an IOC investigation?

    Select an answer first
  4. 9application · medium

    A threat intelligence report mentions a new malware family that uses a specific user-agent string and communicates with a set of command-and-control (C2) domains. An analyst wants to proactively hunt for this malware in the network. Which approach would be most effective?

    Select an answer first
  5. 10foundation · easy

    When investigating a lead, what is the first step an analyst should take to determine its relevance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.