
Palo Alto NetworksCertified XDR Analyst
Domain 3Objective 5
3.5 Identify, Hunt, and Investigate Leads and Indicators of Compromise (IOCs) XDR-ANALYST Practice Questions (Page 4)
Part of the Data Analysis domain, which accounts for 28% of the XDR-ANALYST exam.
29questions here
6free pages
5concepts
28%of the exam
Questions 16–20
- 16
A security analyst is reviewing a set of alerts and needs to identify which are indicators of compromise (IOCs). Which item should be classified as an IOC?
Select an answer first - 17
An analyst is documenting an investigation where a suspicious IP was found to be a false positive. The analyst wants to ensure the documentation is useful for future reference. Which element should be included?
Select an answer first - 18
During an investigation, an analyst finds an IP address that is part of a known botnet infrastructure. The analyst wants to determine if this IP is related to a specific threat actor group. Which action would be most useful?
Select an answer first - 19
Why is it important to document the reasoning behind each conclusion in an IOC investigation?
Select an answer first - 20
A security analyst at a mid-sized company notices a spike in outbound DNS queries to a domain that was recently registered and is not on any blocklist. The analyst wants to determine if this is a true indicator of compromise (IOC) before escalating. Which combination of evidence would most strongly support classifying the domain as an IOC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.