XSIAM-ANALYST Exam Questions
60 real XSIAM-ANALYST exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Playbook Development and Automation
Which type of task can be used to create a decision tree in a playbook?
playbook tasksconditional taskdecision treeplaybook automation - Question #2Incident Investigation and Response
A Cortex XSIAM analyst is investigating a security incident involving a workstation after having deployed a Cortex XDR agent for 45 days. The incident details include the Cortex XD...
incident responseendpoint isolationscheduled task creationthreat containment - Question #3Endpoint Management and Agent Administration
Which Cytool command will re-enable protection on an endpoint that has Cortex XDR agent protection paused?
Cytoolagent protectionendpoint managementCLI commands - Question #4Threat Intelligence Management
A Cortex XSIAM analyst is reading a blog that references an unfamiliar critical zero-day vulnerability. This vulnerability has been weaponized, and there is evidence that it is bei...
threat intelligencezero-day vulnerabilityAttack SurfaceThreat Response Center - Question #5Threat Intelligence Management
While investigating an alert, an analyst notices that a URL indicator has a related alert from a previous incident. The related alert has the same URL, but it resolved to a differe...
indicator enrichmentURL indicatorindicator relationshipsthreat intelligence - Question #6Incident Investigation and Response
Which two actions will allow a security analyst to review updated commands from the core pack and interpret the results without altering the incident audit? (Choose two.)
playground CLIWar Roomcore pack commandsincident audit - Question #7Malware Analysis and Threat Detection
Based on the artifact details in the image below, what can an analyst infer from the hexagon- shaped object with the exclamation mark (!) at the center?
artifact verdictWildFiremalware verdictverdict change indicator - Question #8Incident Investigation and Response
An analyst is responding to a critical incident involving a potential ransomware attack. The analyst immediately initiates full isolation on the compromised endpoint using Cortex X...
endpoint isolationforensic evidenceransomware responseincident containment - Question #9Threat Intelligence Management
In addition to defining the Rule Name and Severity Level, which step or set of steps accurately reflects how an analyst should configure an indicator prevention rule before reviewi...
indicator prevention rulesprevention profilesrule configurationIOC management - Question #10Threat Intelligence Management
During an investigation, an analyst runs the reputation script for an indicator that is listed as Suspicious. The new reputation results display in the War Room as Malicious; howev...
indicator verdictmanual verdict overridereputation scriptWar Room - Question #11Threat Intelligence Management
Which two statements apply to IOC rules? (Choose two.)
IOC rulesREST APIregistry key detectionalert exclusions - Question #12Alert Management and Correlation
What is the cause when alerts generated by a correlation rule are not creating an incident?
correlation rulesincident creationalert severityalert suppression - Question #13Playbook Development and Automation
While investigating an incident on the Incident Overview page, an analyst notices that the playbook encountered an error. Upon playbook work plan review, it is determined that the...
playbook error handlingtask timeoutplaybook executionanalyst permissions - Question #14Alert Management and Correlation
Which configuration will ensure any alert involving a specific critical asset will always receive a score of 100?
risk scoring policycritical assetsalert scoringasset management - Question #15Playbook Development and Automation
How would Incident Context be referenced in an alert War Room task or alert playbook task?
incident contextplaybook variablesWar Room tasksalert playbook - Question #16Incident Investigation and Response
Which feature terminates a process during an investigation?
process terminationLive Terminalendpoint responseinvestigation actions - Question #17Playbook Development and Automation
Which statement applies to a low-severity alert when a playbook trigger has been configured?
playbook triggersalert severitylow-severity alertsautomated playbook execution - Question #18Threat Hunting and XQL Queries
A threat hunter discovers a true negative event from a zero-day exploit that is using privilege escalation to launch "Malware.pdf.exe." Which XQL query will always show the correct...
XQL queryprivilege escalationuser contextthreat hunting - Question #19Incident Investigation and Response
Based on the image below, which two additional steps should a SOC analyst take to secure the endpoint? (Choose two.)
endpoint isolationIP blockingSOC responseincident containment - Question #20Threat Intelligence Management
During an investigation of an alert with a completed playbook, it is determined that no indicators exist from the email "[email protected]" in the Key Assets & Artifacts tab of th...
indicator extractionemail indicatorcheckIndicatorExtractionplaybook diagnostics - Question #21Endpoint Management and Response
In the Endpoint Data context menu of the Cortex XSIAM endpoints table, where will an analyst be able to determine which users accessed an endpoint via Live Terminal?
Live TerminalEndpoint ActionsCortex XSIAM UIEndpoint Management - Question #22Incident Investigation and Response
A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors...
Ransomware InvestigationShell HistoryForensic ArtifactsIncident Response - Question #23Endpoint Protection Policies
A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors...
Ransomware ProtectionKnown Vulnerable ProcessExploit ProtectionEndpoint Security - Question #24Incident Management
Two security analysts are collaborating on complex but similar incidents. The first analyst merges the two incidents into one for easier management. The other analyst immediately d...
Incident MergingCustom FieldsIncident ManagementData Integrity - Question #25Alert Analysis and Triage
Which type of analytics will trigger the alert on the image shown?
Anomaly AnalyticsAlert TypesAnalytics DetectionXSIAM Alerts - Question #26XQL Query and Data Analysis
What can be used to filter out empty values in the query results table?
XQL QueryData FilteringQuery SyntaxNull Values - Question #27Automation and Playbooks
An alert for malware propagation triggers an incident. The associated playbook isolates the endpoint and notifies the SOC team. What advantages does this approach provide? (Choose...
Playbook AutomationIncident ResponseMTTR ReductionSOC Automation - Question #28Identity Threat Detection and Response
In the Identity Threat Detection and Response (ITDR) module, what does "compromised identity" typically indicate?
ITDRCompromised IdentityIdentity SecurityUnauthorized Access - Question #29Attack Surface Management
Which option allows continuous monitoring and triage of evolving threats?
Attack Surface ManagementThreat MonitoringASMContinuous Monitoring - Question #30Threat Hunting
You are hunting for endpoints that have recently executed PowerShell commands. Which two XQL query steps are appropriate?
XQL Threat HuntingPowerShell DetectionProcess DataCommand-Line Analysis - Question #31Data Management and Ingestion
Which dataset should an analyst search when looking for Palo Alto Networks NGFW logs?
NGFW LogsXQL DatasetData IngestionPalo Alto Networks - Question #32Threat Intelligence Management
In which two locations can mapping be configured for indicators? (Choose two.)
Indicator MappingFeed IntegrationClassification and MappingThreat Intelligence - Question #33Endpoint Investigation
An analyst conducting a threat hunt needs to collect multiple files from various endpoints. The analyst begins the file retrieval process by using the Action Center, but upon revie...
File RetrievalAction CenterEndpoint Policy RestrictionsKernel Files - Question #34Analytics and Detection
Which interval is the duration of time before an analytics detector can raise an alert?
Analytics DetectorActivation PeriodAlert TimingDetection Configuration - Question #35Alert Tuning and Optimization
Which two actions can an analyst take to reduce the number of false positive alerts generated by a custom BIOC? (Choose two.)
BIOC RulesFalse Positive ReductionAlert ExclusionRule Exception - Question #36Automation and Playbooks
For a critical incident, Cortex XSIAM suggests several playbooks which should have been executed automatically. Why were the playbooks not executed?
Playbook TriggersAutomation ConfigurationAlert MappingIncident Playbooks - Question #37Incident Investigation
What information is provided in the timeline view of Cortex XSIAM?
Timeline ViewIncident LifecycleEvent SequenceXSIAM UI - Question #38XQL Query and Data Analysis
Which two methods can be used to create and share queries into the Query Library? (Choose two.)
Query LibraryXQL SearchQuery CenterQuery Management - Question #39Attack Surface Management
You observe that a CVE is impacting multiple assets. How can you use ASM to investigate further? (Choose two)
ASMCVE InvestigationAsset TagsAttack Surface Rules - Question #40Threat Detection and Analytics
An alert fires indicating lateral movement between endpoints. It was triggered after evaluating multiple unrelated activities, such as credential access and abnormal port scanning....
Lateral MovementCorrelation RulesBehavioral DetectionMulti-stage Detection - Question #41Incident Investigation and Response
An alert involves credential dumping. Reviewing the causality chain, you notice the following: - lsass.exe is accessed by powershell.exe - Prior to this, cmd.exe launched the Power...
credential dumpingcausality chaindefense evasionMITRE ATT&CK - Question #42Alert Triage and Investigation
Based on the image below, which two determinations can be made from the causality chain? (Choose two.)
causality chainmalware profilealert generationprocess execution - Question #43Alert Management
How can a SOC analyst highlight alerts generated on C-level executive hosts?
executive accountsasset rolesalert prioritizationSOC workflow - Question #44Threat Hunting
Which query will hunt for only incoming traffic from 99.99.99.99 when all log sources have been mapped to XDM?
XQLXDMnetwork huntingdata model - Question #45User and Entity Behavior Analytics
Which pane in the User Risk View will identify the country from which a user regularly logs in, based on the past few weeks of data?
User Risk Viewcommon locationsUEBAauthentication - Question #46Alert Management
Which attributes can be used as featured fields?
featured fieldsalert customizationhostnamesIP addresses - Question #47Incident Management
A SOC team member implements an incident starring configuration, but incidents created before this configuration were not starred. What is the cause of this behavior?
incident starringalert configurationincident creationSOC workflow - Question #48Incident Management
An incident in Cortex XSIAM contains the following series of alerts: 10:24:17 AM - Informational Severity - XDR Analytics BIOC - Rare process execution in organization 10:24:18 AM...
incident creationalert severityBIOCincident grouping - Question #49Attack Surface Management
Which attribution evidence will have the lowest confidence level when evaluating assets to determine if they belong to an organization's attack surface?
attack surface managementasset attributionCortex Xpanseconfidence levels - Question #50Automation and Orchestration
When a sub-playbook loops, which task tab will allow an analyst to determine what data the sub- playbook used in each iteration of the loop?
sub-playbookloop iterationplaybook automationinput results