Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 1

2.1 Review and Investigate Alert Evidence XDR-ANALYST Practice Questions (Page 4)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
8concepts
34%of the exam

Questions 16–20

  1. 16application · medium

    An analyst is presenting an incident to management and wants to show how a single phishing email led to a ransomware deployment. The analyst has a list of events but needs to show the cause-and-effect relationships. Which approach should the analyst use?

    Select an answer first
  2. 17application · medium

    During an investigation, an analyst identifies a series of events: a phishing email was opened, a macro executed, a payload was downloaded, and a backdoor was installed. The analyst wants to present this as a single narrative to management. Which concept best describes this linked sequence of events?

    Select an answer first
  3. 18expert · hard

    An analyst is constructing a causality chain from an alert that shows a user clicked a link in an email, which led to a browser download, which then executed a script that created a scheduled task. The analyst needs to identify the root cause of the incident. Which element should be considered the root cause in this chain?

    Select an answer first
  4. 19application · medium

    A security analyst notices an alert for a user account that successfully authenticated from a new geographic location and then immediately attempted to access a high-privilege resource. The analyst wants to understand if this is an identity-based threat. Which XDR feature is specifically designed to detect and respond to such identity-related anomalies?

    Select an answer first
  5. 20foundation · easy

    During an XDR alert investigation, an analyst needs to examine the original command-line arguments passed to a suspicious process. Which type of forensic evidence in the alert would most directly provide this information?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.