XDR-ANALYST Exam Questions
105 real XDR-ANALYST exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Cortex XDR Licensing and Architecture
What license would be required for ingesting external logs from various vendors?
licensinglog ingestionthird-party logsPro per TB - Question #52Endpoint Protection and Agent Capabilities
An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?
Dylib HijackingmacOS protectiondynamic librariesCortex XDR modules - Question #53Cortex XDR Platform Overview
What is the purpose of the Unit 42 team?
Unit 42threat researchmalware analysisthreat hunting - Question #54Threat Intelligence and IOC Management
Which Type of IOC can you define in Cortex XDR?
IOC typesindicators of compromisefull paththreat intelligence - Question #55Incident Management and Investigation
When viewing the incident directly, what is the "assigned to" field value of a new Incident that was just reported to Cortex?
incident managementassignment statusCortex XDR consoleincident triage - Question #56Incident Management and Investigation
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
incident widgetsstarred incidentsdashboard filteringCortex XDR UI - Question #57Incident Management and Investigation
Where would you view the WildFire report in an incident?
WildFire reportincident detailskey artifactsmalware analysis - Question #58Reporting and Dashboards
What does the following output tell us?
dashboard widgetsTop 10 hostsmalware reportingCortex XDR analytics - Question #59Cortex XDR Detection and Analytics
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
Causality Analysis Enginealert aggregationincident creationalert stitching - Question #60XQL and Query Investigation
What occurs if a lookup table referenced in an XQL query is deleted from Cortex XDR?
XQL querieslookup tablesquery executionCortex XDR - Question #61XQL and Query Investigation
What is the main benefit of using the Query Library in Cortex XDR?
Query LibraryXQLquery reuseinvestigation - Question #62Third-Party Integrations and Data Sources
What are two key characteristics of alerts generated from third-party integrations in Cortex XDR?
third-party integrationsexternal alertsalert stitchingCortex XDR - Question #63Endpoint Protection and Agent Capabilities
What is the primary purpose of Host Insights in Cortex XDR?
Host Insightsendpoint visibilityrisk indicatorsendpoint health - Question #64Cortex XDR Architecture and Communication
When is the wss (WebSocket Secure) protocol used?
WebSocket Securewss protocolagent communicationbidirectional channel - Question #65Licensing and Deployment
With a Cortex XDR Prevent license, which objects are considered to be sensors?
Cortex XDR Preventsensorsagent licensingendpoint agents - Question #66Licensing and Deployment
Which license is required when deploying Cortex XDR agent on Kubernetes Clusters as a DaemonSet?
KubernetesDaemonSetcloud licenseCortex XDR Cloud per Host - Question #67Threat Landscape and Attack Techniques
What kind of the threat typically encrypts user files?
ransomwarefile encryptionthreat typesmalware - Question #68Endpoint Response and Remediation
When using the "File Search and Destroy" feature, which of the following search hash type is supported?
File Search and DestroySHA256hash typesendpoint response - Question #69Cortex XDR Architecture and Communication
If you have an isolated network that is prevented from connecting to the Cortex Data Lake, which type of Broker VM setup can you use to facilitate the communication?
Broker VMisolated networkLocal Agent ProxyCortex Data Lake - Question #70Threat Landscape and Attack Techniques
What is by far the most common tactic used by ransomware to shut down a victim's operation?
ransomwarefile encryptionvictim impactattack tactics - Question #71Cortex XDR Detection and Analytics
Cortex XDR Analytics can alert when detecting activity matching the following MITRE ATT&CKTM techniques.
Cortex XDR AnalyticsMITRE ATT&CKlateral movementdetection techniques - Question #72Incident Management and Triage
When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)
incident managementbulk actionsXDR consoleincident triage - Question #73Alert Triage and Investigation
A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?
WildFireLocal Analysisfalse positivemalware verdict - Question #74Incident Management and Triage
In Cortex XDR, what action is taken once an incident is confirmed as benign?
incident resolutionfalse positiveincident statuscase management - Question #75XQL Query and Threat Hunting
Which of the following are valid use cases for using XQL in Cortex XDR? (Choose two)
XQLthreat huntingcustom dashboardsquery language - Question #76Endpoint Agent Management
Why is it important to regularly update Cortex XDR agents?
agent updatesdetection enginescontent managementendpoint agent - Question #77Troubleshooting and Technical Support
When reaching out to TAC for additional technical support related to a Security Event; what are two critical pieces of information you need to collect from the Agent? (Choose Two)
TAC supportagent diagnosticsprevention archivetroubleshooting - Question #78Endpoint Response Actions
What types of actions you can execute with live terminal session?
live terminalendpoint responsePython scriptsprocess management - Question #79Endpoint Response Actions
Which version of python is used in live terminal?
live terminalPython 3scriptingstandard libraries - Question #80Threat Intelligence and Malware Analysis
What kind of malware uses encryption, data theft, denial of service, and possibly harassment to take advantage of a victim?
ransomwaremalware typesdata theftdenial of service - Question #81Endpoint Response Actions
Which function describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed?
quarantinefile remediationmalware responseendpoint protection - Question #82Detection and Analytics
To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR A...
Cortex XDR Analyticsbehavioral detectionattack patternendpoint detection - Question #83Incident Response and Remediation
Cortex XDR is deployed in the enterprise and you notice a cobalt strike attack via an ongoing supply chain compromise was prevented on 1 server. What steps can you take to ensure t...
IOC creationCobalt Strikesupply chain attackthreat containment - Question #84XQL Query and Threat Hunting
What is the difference between presets and datasets in XQL?
XQLdatasetspresetsdata sources - Question #85Threat Hunting and Investigation
What should you do to automatically convert leads into alerts after investigating a lead?
IOC ruleslead investigationalert creationthreat hunting - Question #86Threat Intelligence and IOC Management
Which type of IOC can you define in Cortex XDR?
IOCdestination IP addressindicators of compromisethreat intelligence - Question #87Endpoint Response Actions
Which of the following Live Terminal options are available for Android systems?
live terminalAndroidmobile endpointremote response - Question #88Endpoint Response Actions
Which search methods is supported by File Search and Destroy?
File Search and Destroyendpoint remediationfile managementresponse actions - Question #89XQL Query and Threat Hunting
What is the primary purpose of using lookup tables in Cortex XDR?
lookup tablesdata enrichmentXQLquery results - Question #90Reporting and Dashboards
Which reports can be generated or scheduled from the Cortex XDR dashboard? (Choose two)
reportingdashboardsXQL scheduled reportsexecutive summary - Question #91XQL Query and Threat Hunting
What are two purposes of using the Pre-defined Query Builder Template in Cortex XDR? (Choose two)
Query BuilderXQL templatesfield selectionsyntax assistance - Question #92Cortex XDR Query and Reporting
Which features are supported by scheduled queries in Cortex XDR? (Choose two)
scheduled queriesXQLdashboard integrationrecurring execution - Question #93Cortex XDR Monitoring and Reporting
Which statement accurately describes the purpose of the Cortex XDR dashboard?
dashboardsecurity metricsthreat visualizationmonitoring - Question #94Threat Intelligence and Hunting
When conducting threat hunting using IOC data, what actions are typically taken? (Choose two)
threat huntingIOCthreat intelligencetelemetry analysis - Question #95Alert Analysis and Investigation
Which two elements are part of alert evidence in Cortex XDR? (Choose two)
alert evidenceprocess executionfile hashalert analysis - Question #96Threat Intelligence and Attack Frameworks
Phishing belongs to which of the following MITRE ATT&CK tactics?
MITRE ATT&CKphishingInitial AccessReconnaissance - Question #97Detection and Response Rules
When creating a BIOC rule, which XQL query can be used?
BIOC ruleXQL querybehavioral detectiondataset - Question #98Cortex XDR Monitoring and Reporting
Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
MTTRincident managementdashboardexecutive reporting - Question #99Prevention and Response
What are two purposes of "Respond to Malicious Causality Chains" in a Cortex XDR Windows Malware profile? (Choose two.)
malware profilecausality chainsprocess terminationmalicious activity response - Question #100Cortex XDR Query and Reporting
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
XQLwidget librarydashboard customizationquery management