Palo Alto Networks XDR Analyst XDR-Analyst Exam Questions
An XDR platform generates an alert showing a PowerShell process spawning immediately after a Microsoft Word document opened. The PowerShell command is heavily obfuscated and connects to an external IP address.
What should be the analyst's highest priority initial action?
Correct Answer: B
Before taking remediation actions, an analyst should verify whether the alert represents malicious behavior. Reviewing the process tree, parent-child relationships, and PowerShell command line helps determine if the activity is legitimate or malicious.
An organization is investigating lateral movement inside its network. Which XDR telemetry sources would provide the most valuable evidence?
(Choose TWO.)
Correct Answer: A, D
Authentication logs reveal suspicious login attempts and credential usage, while network telemetry helps identify remote connections and communication between hosts. Together they provide strong evidence of lateral movement.
During triage, an analyst notices that an alert has a high confidence score but affects only a single workstation with no evidence of persistence or additional compromise.
What is the most appropriate next step?
Correct Answer: C
A high-confidence alert still requires investigation to understand its scope and impact. The analyst should gather additional evidence
before deciding whether escalation or containment is necessary.
An analyst wants to reduce false positives in the XDR environment while maintaining visibility into genuine threats.
Which actions are appropriate?
(Choose TWO.)
Correct Answer: A, C
Detection tuning and allowlisting trusted applications reduce unnecessary alerts while preserving visibility into malicious activity.
Disabling telemetry or excessively lowering thresholds negatively impacts detection quality.
After confirming ransomware activity on a workstation, what should the analyst perform first to limit further damage?
Correct Answer: B
Containing the compromised endpoint is the highest priority. Network isolation helps prevent ransomware
from spreading while preserving evidence for further investigation and response.