
Palo Alto NetworksCertified XSIAM Analyst
Domain 2Objective 2
2.2 Review and Investigate Alert Evidence XSIAM-ANALYST Practice Questions (Page 2)
Part of the Incident Handling and Response domain, which accounts for 20% of the XSIAM-ANALYST exam.
33questions here
7free pages
8concepts
20%of the exam
Questions 6–10
- 6
Which type of data is considered forensic evidence when investigating an alert?
Select an answer first - 7
An analyst is investigating a potential data breach and has constructed a timeline of events. The timeline shows that a user logged in, accessed a file share, and then exfiltrated data. However, the analyst notices that the file share access occurred before the login in the timeline. What is the most likely cause of this discrepancy?
Select an answer first - 8
An analyst is constructing a causality chain for an incident. The evidence shows: (1) a user opened a malicious attachment, (2) a macro ran, (3) PowerShell executed a script, (4) the script downloaded a payload, and (5) the payload established persistence. The analyst needs to identify the initial infection vector. What is the initial vector?
Select an answer first - 9
When building a causality chain from alert evidence, what is the first element an analyst should identify?
Select an answer first - 10
During an incident investigation, an analyst identifies the following events: (1) a phishing email was opened, (2) a macro executed PowerShell, (3) PowerShell downloaded a payload, (4) the payload created a scheduled task, and (5) the scheduled task ran a credential-dumping tool. The analyst needs to present the causality chain to management. Which representation is most accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSIAM-ANALYST” is a trademark of its owner, used for identification only.