
Palo Alto NetworksCertified XDR Analyst
Domain 3Objective 5
3.5 Identify, Hunt, and Investigate Leads and Indicators of Compromise (IOCs) XDR-ANALYST Practice Questions (Page 2)
Part of the Data Analysis domain, which accounts for 28% of the XDR-ANALYST exam.
29questions here
6free pages
5concepts
28%of the exam
Questions 6–10
- 6
An analyst is investigating an alert about a suspicious PowerShell command that was executed on a server. The command is not on any blocklist, but it does download a file from an external IP. The analyst wants to determine if this is a true positive. Which evidence would be most convincing?
Select an answer first - 7
How does threat intelligence help an analyst correlate an IOC with a known threat actor?
Select an answer first - 8
What is a key characteristic of well-structured documentation for an IOC investigation?
Select an answer first - 9
A threat intelligence report mentions a new malware family that uses a specific user-agent string and communicates with a set of command-and-control (C2) domains. An analyst wants to proactively hunt for this malware in the network. Which approach would be most effective?
Select an answer first - 10
When investigating a lead, what is the first step an analyst should take to determine its relevance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.