Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Analyst

Domain 2Objective 1

2.1 Review and Investigate Alert Evidence XDR-ANALYST Practice Questions (Page 7)

Part of the Incident Handling and Response domain, which accounts for 34% of the XDR-ANALYST exam.

33questions here
7free pages
8concepts
34%of the exam

Questions 31–33

  1. 31expert · hard

    An analyst is building a causality chain for an incident and has identified the following events: a user received a phishing email, clicked a link, downloaded a file, executed the file, and the file established a C2 connection. The analyst needs to determine the most critical point for prevention. Which event should be considered the best target for preventive controls?

    Select an answer first
  2. 32application · medium · select all that apply

    An analyst is investigating an alert that involves a compromised user account. The analyst needs to collect forensic evidence to determine the scope of the compromise. Which of the following evidence sources should the analyst collect? (Select all that apply.)

    Select an answer first
  3. 33foundation · easy

    While correlating events on an investigation timeline, an analyst notices a 30-minute gap between the initial compromise and the next observed action. What is the most likely significance of this gap?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to XDR-ANALYST

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ANALYST” is a trademark of its owner, used for identification only.