Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 1

2.1 Review and Investigate Alert Evidence XDR-ANALYST Practice Questions (Page 2)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
8concepts
34%of the exam

Questions 6–10

  1. 6foundation · easy

    An analyst is correlating events on a timeline and observes that a user logged in from a new device, then immediately accessed a sensitive file share, and then the file share was encrypted. What pattern does this sequence reveal?

    Select an answer first
  2. 7foundation · easy

    An analyst is building a causality chain and sees that 'Process A' launched 'Process B', which then created a file. How should the analyst represent this relationship in the chain?

    Select an answer first
  3. 8foundation · easy

    When creating a timeline from alert evidence, which data point is most essential to include for each event?

    Select an answer first
  4. 9application · medium

    An organization has implemented ITDR to enhance its security posture. An analyst receives an alert about a user account that was used to access a sensitive database from an unusual location. The analyst wants to understand how ITDR contributes to the investigation. Which statement best describes ITDR's role in this scenario?

    Select an answer first
  5. 10foundation · easy

    How does a causality chain help an analyst understand the progression of an attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.