
Palo Alto NetworksCertified XSIAM Analyst
Domain 5Objective 4
5.4 Respond to Endpoint Alerts and Incidents XSIAM-ANALYST Practice Questions (Page 3)
Part of the Endpoint Security Management domain, which accounts for 12% of the XSIAM-ANALYST exam.
14questions here
3free pages
4concepts
12%of the exam
Questions 11–14
- 11
A security analyst detects a suspicious process on a Windows endpoint that is actively communicating with an external command-and-control server. The analyst needs to stop the threat from spreading to other hosts while preserving the ability to run diagnostic commands on the affected machine. Which action should the analyst take first?
Select an answer first - 12
Which XSIAM action is specifically used to contain a threat by preventing an endpoint from communicating with other devices on the network?
Select an answer first - 13
An analyst needs to run a command directly on an endpoint to check for active network connections during an investigation. Which XSIAM feature allows the analyst to do this in real time?
Select an answer first - 14
A macOS endpoint is suspected of being infected with malware that evaded the initial prevention controls. The analyst needs to identify any malicious files or processes on the system and then verify the findings by inspecting the running processes. Which combination of actions should the analyst perform?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to XSIAM-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSIAM-ANALYST” is a trademark of its owner, used for identification only.