
Palo Alto NetworksCertified XDR Analyst
Domain 3Objective 5
3.5 Identify, Hunt, and Investigate Leads and Indicators of Compromise (IOCs) XDR-ANALYST Practice Questions (Page 5)
Part of the Data Analysis domain, which accounts for 28% of the XDR-ANALYST exam.
29questions here
6free pages
5concepts
28%of the exam
Questions 21–25
- 21
What is the value of linking an IOC to a known threat actor or campaign?
Select an answer first - 22
An analyst has completed an investigation into a suspicious domain and determined it is benign. The analyst needs to document the findings for future reference. What is the most important information to include in the documentation?
Select an answer first - 23
An analyst is investigating an alert about a suspicious process that is making outbound connections to an IP address. The IP is not on any blocklist, but it is in a country where the company has no business operations. The process is a legitimate system tool that is often abused by attackers. What should the analyst do next?
Select an answer first - 24
An analyst is investigating an alert about a user account that was locked out multiple times. The analyst suspects a brute-force attack. Which evidence would most strongly support this suspicion?
Select an answer first - 25
An analyst receives an alert about a file hash that matches a known malware signature. The file was detected on a single workstation that is used by the marketing department. Before taking action, the analyst wants to assess the potential impact. Which step should the analyst take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.