Palo Alto Networks Certified XDR Analyst Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 197 questions. Use the simulator for timed and flashcard mode.

Try Simulator

xdr-analyst Sample Questions

  1. Question 1

    Q1

    A SOC analyst at a financial services firm is investigating a high-severity incident originating from a database server. The causality chain indicates that a legitimate, signed administrative tool, db_admin_util.exe, was used to spawn a PowerShell process that connected to a known malicious IP address. The firm's policy prohibits isolating this critical server. Which response action in Cortex XDR would be most effective at containing the immediate threat while adhering to the policy?

    Show answer & explanation

    Correct answer: B

    Terminating the specific malicious process is the most precise action. It stops the active threat (the C2 connection) without disrupting the legitimate administrative tool or the server's primary function, thus adhering to the policy against isolation. Blocking the legitimate tool's hash would cause operational disruption. Isolating the host is explicitly forbidden. Adding the IP to a block list is a good secondary step but doesn't stop the already running process.

  2. Question 2

    Q2Multiple answers

    A security team is deploying Cortex XDR agents to a new fleet of developer workstations. To minimize false positives from custom-built applications and scripts, the team creates a specific Security Profile for this group. Which two settings within the Malware Protection profile are most appropriate for allowing legitimate, internally developed tools to run without triggering alerts, while still maintaining a strong security posture? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Adding the signer certificate is a secure and scalable way to trust all applications signed by the internal development team. This avoids having to allow-list every single file hash.

    Creating process exceptions for specific directories is a common and effective method to prevent alerts on known-good applications running from a controlled location. This is more targeted than disabling entire modules.

  3. Question 3

    Q3

    An analyst needs to create a scheduled XQL query that runs daily to identify any process that creates a file with a '.ps1' extension in a user's 'Downloads' directory. Which XQL query correctly accomplishes this?

    Show answer & explanation

    Correct answer: C

    This query correctly uses the xdr_data dataset, filters for the specific Enum.FileCreated event type, checks that the action_file_path contains 'Downloads', and uses the ends_with function to accurately find files with the '.ps1' extension. This is the most precise and correct syntax among the options.

  4. Question 4

    Q4

    During an incident investigation, an analyst observes that Cortex XDR has automatically stitched together alerts from an endpoint, a firewall, and an identity provider into a single incident. What is the primary mechanism that enables this cross-domain data stitching?

    Show answer & explanation

    Correct answer: C

    The Causality Analysis Engine is the core component that processes data from all sources (endpoint, network, cloud, identity) and builds a comprehensive picture of an attack. It identifies relationships between events, such as a process on an endpoint making a network connection that is logged by a firewall, and stitches them together into a unified incident view.

  5. Question 5

    Q5

    True or False: In Cortex XDR, using the 'Isolate Host' response action will immediately terminate all network connections, including the agent's connection back to the Cortex XDR console, preventing any further remote actions.

    Show answer & explanation

    Correct answer: B

    The 'Isolate Host' action is designed to block all network traffic except for the essential communication between the Cortex XDR agent and the XDR console. This ensures that the analyst maintains control over the isolated endpoint and can perform further actions like running Live Terminal commands, collecting forensic data, or removing the isolation.

  6. Question 6

    Q6

    An analyst is reviewing the Host Insights data for a critical server and notices that the 'OS Version' field is listed as 'Unsupported'. What is the most significant security implication of this status?

    Show answer & explanation

    Correct answer: C

    When an OS is marked as 'Unsupported', it means Palo Alto Networks no longer develops or tests new agent versions and content for that OS. While the existing agent might continue to function, it will not receive updates, leaving the endpoint increasingly vulnerable to new threats that are addressed in later content versions.

  7. Question 7

    Q7

    A manufacturing company is concerned about intellectual property theft. A security analyst is tasked with creating a proactive threat hunting query to find evidence of large data exfiltration over DNS. Which XQL query would be most effective for this purpose?

    Show answer & explanation

    Correct answer: C

    This advanced query effectively hunts for DNS tunneling. It filters for DNS events, calculates the length of the DNS query name (where exfiltrated data is often encoded), filters for unusually long queries (e.g., > 100 characters), and then aggregates the count of unique long queries by the process that initiated them. A high count of unique, long queries from a single process is a strong indicator of data exfiltration.

  8. Question 8

    Q8

    An XDR analyst is troubleshooting why a new exploit protection module is not being applied to a specific group of servers. The servers have the correct agent version installed and are connected to the console. What is the most likely reason for this issue?

    Show answer & explanation

    Correct answer: B

    Exploit protection modules and other security logic are delivered via content updates, which are versioned separately from the agent software itself. A policy can be configured to use the 'latest' content or pinned to a specific, older version. If the policy is pinned to a content version released before the new module was available, the endpoints will not receive or apply it, even if the agent software is up to date.

  9. Question 9

    Q9

    While investigating an incident, an analyst needs to retrieve a suspicious executable from a remote endpoint for sandboxing. The endpoint is currently isolated. Which is the correct sequence of steps to retrieve the file using Live Terminal?

    Show answer & explanation

    Correct answer: A

    The correct process is to first initiate the file retrieval from the endpoint using the get-file command in the Live Terminal session. Once the agent has successfully uploaded the file to the Cortex XDR backend, the analyst must go to the 'Action Center' to find the completed action and download the retrieved file to their local machine for analysis.

  10. Question 10

    Q10

    What is the primary function of a lookup table in Cortex XDR data analysis?

    Show answer & explanation

    Correct answer: D

    Lookup tables are used to enrich data within XQL queries. An analyst can upload a CSV file containing contextual information (e.g., a list of critical assets, user-to-department mappings, or known malicious indicators) and then use the lookup command in an XQL query to join this external data with the event data stored in Cortex XDR, providing more meaningful results.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the xdr-analyst sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 197 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon