Certs Vault
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Create account

Palo Alto Networks XDR Analyst XDR-Analyst Exam Questions

Preparing for the XDR-Analyst exam is simple with Certs Vault. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.

At Certs Vault, we keep our XDR-Analyst practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.

Download Exam View Entire Exam
Page: 1 / 1
Question #1 (Topic: Demo Questions)

An XDR platform generates an alert showing a PowerShell process spawning immediately after a Microsoft Word document opened. The PowerShell command is heavily obfuscated and connects to an external IP address.

What should be the analyst's highest priority initial action?

A.

Delete the Word document from the endpoint.

B.

Validate the alert by reviewing process lineage and command-line activity.

C.

Ignore the alert if the antivirus did not trigger.

D.

Reboot the endpoint immediately.

Correct Answer: B
Explanation:

Before taking remediation actions, an analyst should verify whether the alert represents malicious behavior. Reviewing the process tree, parent-child relationships, and PowerShell command line helps determine if the activity is legitimate or malicious.

Question #2 (Topic: Demo Questions)

An organization is investigating lateral movement inside its network. Which XDR telemetry sources would provide the most valuable evidence?

(Choose TWO.)

A.

Authentication logs

B.

Endpoint process events

C.

Printer usage statistics

D.

Network connection telemetry

Correct Answer: A, D
Explanation:

Authentication logs reveal suspicious login attempts and credential usage, while network telemetry helps identify remote connections and communication between hosts. Together they provide strong evidence of lateral movement.

Question #3 (Topic: Demo Questions)

During triage, an analyst notices that an alert has a high confidence score but affects only a single workstation with no evidence of persistence or additional compromise.

What is the most appropriate next step?

A.

Escalate immediately as a major incident.

B.

Close the alert without investigation.

C.

Perform additional endpoint investigation before determining severity.

D.

Disconnect the organization's internet connection.

Correct Answer: C
Explanation:

A high-confidence alert still requires investigation to understand its scope and impact. The analyst should gather additional evidence

before deciding whether escalation or containment is necessary.

Question #4 (Topic: Demo Questions)

An analyst wants to reduce false positives in the XDR environment while maintaining visibility into genuine threats.

Which actions are appropriate?

(Choose TWO.)

A.

Tune detection rules using known legitimate behavior.

B.

Disable all endpoint telemetry collection.

C.

Create allowlists for verified business applications.

D.

Lower every alert threshold to the minimum possible value.

Correct Answer: A, C
Explanation:

Detection tuning and allowlisting trusted applications reduce unnecessary alerts while preserving visibility into malicious activity.

Disabling telemetry or excessively lowering thresholds negatively impacts detection quality.

Question #5 (Topic: Demo Questions)

After confirming ransomware activity on a workstation, what should the analyst perform first to limit further damage?

A.

Archive the investigation report.

B.

Isolate the affected endpoint from the network.

C.

Delete all security logs.

D.

Reimage every endpoint in the organization.

Correct Answer: B
Explanation:

Containing the compromised endpoint is the highest priority. Network isolation helps prevent ransomware

from spreading while preserving evidence for further investigation and response.

Download Exam
Page: 1 / 1
Next Page