
Palo Alto NetworksCertified XDR Analyst
Domain 2Objective 1
2.1 Review and Investigate Alert Evidence XDR-ANALYST Practice Questions (Page 1)
Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.
33questions here
7free pages
8concepts
34%of the exam
Questions 1–5
- 1
An analyst is explaining to a colleague why a causality chain is useful in an investigation. The colleague asks, 'How does a causality chain differ from a simple list of events?' Which response is most accurate?
Select an answer first - 2
During an investigation of a privilege escalation alert, an analyst sees that a standard user account was added to the 'Domain Admins' group. Which piece of identity-focused evidence would be most important to correlate with this event to understand the attack?
Select an answer first - 3
An analyst is investigating an alert that indicates a process injected code into another process. The analyst needs to preserve the evidence for further analysis. Which forensic evidence should the analyst collect first to ensure the injected code is preserved?
Select an answer first - 4
An analyst is correlating events across a timeline and finds that a user logged in at 10:00, a file was downloaded at 10:05, and a process executed at 10:10. However, the analyst also finds a network connection to an external IP at 09:55, before the logon. What should the analyst conclude from this correlation?
Select an answer first - 5
When constructing a causality chain from alert evidence, what is the first step an analyst should take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.