Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 1

2.1 Review and Investigate Alert Evidence XDR-ANALYST Practice Questions (Page 5)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
8concepts
34%of the exam

Questions 21–25

  1. 21application · medium

    An analyst is investigating an alert that shows a service account was used to log into multiple servers in quick succession. The analyst suspects lateral movement. Which evidence would best support this hypothesis?

    Select an answer first
  2. 22foundation · easy

    What is a causality chain in the context of XDR incident investigation?

    Select an answer first
  3. 23foundation · easy

    What is the primary purpose of creating a timeline during an incident investigation?

    Select an answer first
  4. 24expert · hard

    An analyst is investigating an alert that shows a user account was used to log into a server and then execute a privilege escalation command. The analyst suspects the account was compromised. Which combination of evidence would best confirm the compromise and reveal the attack's progression?

    Select an answer first
  5. 25application · medium

    An analyst is creating a timeline for an incident and has events from multiple sources: endpoint logs, network logs, and authentication logs. The analyst notices that the timestamps from different sources are not synchronized. What should the analyst do to ensure the timeline is accurate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.