Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 1

2.1 Review and Investigate Alert Evidence XDR-ANALYST Practice Questions (Page 6)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
8concepts
34%of the exam

Questions 26–30

  1. 26expert · hard

    An analyst is investigating an alert that shows a user account was used to reset a password and then log into a domain controller. The analyst suspects privilege escalation. Which additional evidence would most strongly confirm the privilege escalation?

    Select an answer first
  2. 27foundation · easy

    An analyst is examining a suspicious PowerShell script captured in an XDR alert. Which forensic analysis technique would be most effective for understanding the script's obfuscated logic and its potential impact?

    Select an answer first
  3. 28foundation · easy

    What is the primary role of Identity Threat Detection and Response (ITDR) in an organization's security posture?

    Select an answer first
  4. 29foundation · easy

    How does ITDR integrate with XDR investigations to enhance the analysis of a potential identity-based attack?

    Select an answer first
  5. 30application · medium

    An analyst is reviewing an alert and has collected the following events: a logon at 10:00, a file download at 10:05, a process execution at 10:10, and a network connection at 10:15. The analyst needs to present these events in a way that shows the sequence of the attack. Which action should the analyst take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.