
Palo Alto NetworksCertified XSIAM Analyst
Domain 2Objective 2
2.2 Review and Investigate Alert Evidence XSIAM-ANALYST Practice Questions (Page 3)
Part of the Incident Handling and Response domain, which accounts for 20% of the XSIAM-ANALYST exam.
33questions here
7free pages
8concepts
20%of the exam
Questions 11–15
- 11
An organization has experienced a security incident, and the incident response team needs to collect forensic evidence. The team has identified a compromised server and needs to preserve volatile data. What is the most important action to take first?
Select an answer first - 12
An incident response team is documenting the sequence of events for a ransomware attack. They have logs from the firewall, endpoint, and email gateway. What is the most effective way to present the attack sequence to management?
Select an answer first - 13
How can timeline analysis support incident response decisions?
Select an answer first - 14
An analyst is reviewing a timeline of events for a potential data exfiltration incident. The timeline shows a user logging in, accessing files, and then sending an email with attachments. The analyst notices that the email was sent before the file access in the timeline. What should the analyst do first?
Select an answer first - 15
An analyst is building a causality chain for an incident. The evidence shows: (1) a user clicked a link in an email, (2) a browser downloaded a file, (3) the file was executed, (4) a process spawned a child process, and (5) the child process made a network connection. The analyst needs to identify the initial infection vector. Based on this chain, what is the initial vector?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSIAM-ANALYST” is a trademark of its owner, used for identification only.