xdr-analyst Sample Questions

xdr-analyst Sample Questions & Answers

You'll be tested on reviewing evidence and responding to security incidents, the single biggest weight, plus querying datasets with XQL, how alerts are typed and prioritized, creating incidents, and endpoint prevention policies with agent management.

Launch the full xdr-analyst simulator →

Free xdr-analyst Sample Questions with Answers

Real questions from the Palo Alto Networks Certified XDR Analyst practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Data Analysis · Explain the use of Host Insights information

    An analyst is reviewing the Host Insights data for a critical server and notices that the 'OS Version' field is listed as 'Unsupported'. What is the most significant security implication of this status?

    Show answer & explanation

    Correct answer: C

    When an OS is marked as 'Unsupported', it means Palo Alto Networks no longer develops or tests new agent versions and content for that OS. While the existing agent might continue to function, it will not receive updates, leaving the endpoint increasingly vulnerable to new threats that are addressed in later content versions.

  2. Question 2Advanced

    Data Analysis · Identify, hunt, and investigate leads and indicators of compromise (IOCs)

    A manufacturing company is concerned about intellectual property theft. A security analyst is tasked with creating a proactive threat hunting query to find evidence of large data exfiltration over DNS. Which XQL query would be most effective for this purpose?

    Show answer & explanation

    Correct answer: C

    This advanced query effectively hunts for DNS tunneling. It filters for DNS events, calculates the length of the DNS query name (where exfiltrated data is often encoded), filters for unusually long queries (e.g., > 100 characters), and then aggregates the count of unique long queries by the process that initiated them. A high count of unique, long queries from a single process is a strong indicator of data exfiltration.

  3. Question 3Intermediate

    Endpoint Security Management · Identify and validate the impact of agent version and content update

    An XDR analyst is troubleshooting why a new exploit protection module is not being applied to a specific group of servers. The servers have the correct agent version installed and are connected to the console. What is the most likely reason for this issue?

    Show answer & explanation

    Correct answer: B

    Exploit protection modules and other security logic are delivered via content updates, which are versioned separately from the agent software itself. A policy can be configured to use the 'latest' content or pinned to a specific, older version. If the policy is pinned to a content version released before the new module was available, the endpoints will not receive or apply it, even if the agent software is up to date.

  4. Question 4Intermediate

    Incident Handling and Response · Forensics

    While investigating an incident, an analyst needs to retrieve a suspicious executable from a remote endpoint for sandboxing. The endpoint is currently isolated. Which is the correct sequence of steps to retrieve the file using Live Terminal?

    Show answer & explanation

    Correct answer: A

    The correct process is to first initiate the file retrieval from the endpoint using the get-file command in the Live Terminal session. Once the agent has successfully uploaded the file to the Cortex XDR backend, the analyst must go to the 'Action Center' to find the completed action and download the retrieved file to their local machine for analysis.

  5. Question 5Beginner

    Data Analysis · Use lookup tables

    What is the primary function of a lookup table in Cortex XDR data analysis?

    Show answer & explanation

    Correct answer: D

    Lookup tables are used to enrich data within XQL queries. An analyst can upload a CSV file containing contextual information (e.g., a list of critical assets, user-to-department mappings, or known malicious indicators) and then use the lookup command in an XQL query to join this external data with the event data stored in Cortex XDR, providing more meaningful results.

  6. Question 6Advanced

    Incident Handling and Response · Identity Threat Detection and Response (ITDR)

    An analyst is reviewing an Identity Threat Detection and Response (ITDR) alert. The alert details show that a user account, 'svc_backup', attempted to access the domain controller using Kerberos, but the request used the RC4-HMAC encryption type. This behavior is flagged as suspicious. Why is the use of RC4-HMAC in a Kerberos request considered a potential indicator of compromise?

    Show answer & explanation

    Correct answer: C

    Attackers performing a Kerberoasting attack will specifically request a Kerberos ticket for a service account using the weaker RC4-HMAC encryption. Because the ticket is encrypted with a key derived from the service account's password, the attacker can take the ticket offline and use brute-force methods to crack the password. Modern systems default to stronger AES encryption, so a request for RC4 is a strong indicator of this specific attack technique.

  7. Question 7Intermediate

    Data Analysis · Demonstrate understanding of Cortex XDR dashboards and reports

    A SOC manager wants to create a custom dashboard widget that displays the top 10 processes launching PowerShell scripts across all endpoints in the last 7 days. Which of the following is the correct element to use for building this widget?

    Show answer & explanation

    Correct answer: C

    Custom dashboard widgets are powered by XQL queries. The analyst would first construct the appropriate XQL query (e.g., filtering for PowerShell as a child process and aggregating by the parent process) and then use this query as the data source for a new widget within the dashboard management interface, setting the time frame to 'Last 7 Days'.

  8. Question 8Intermediate

    Incident Handling and Response · Identify and explain exclusions and exceptions

    When an analyst creates an exclusion for a specific alert, they have the option to apply it to the Alert, the specific Endpoint, or the entire Policy. Which scenario justifies creating an exclusion at the Policy level?

    Show answer & explanation

    Correct answer: B

    A policy-level exclusion is appropriate when a legitimate behavior or application, which is common to all endpoints governed by that specific policy (e.g., the 'IT Staff' policy), is causing false positives. This applies the exclusion broadly to the intended group without affecting other endpoints (like servers or standard user workstations) that are under different policies.

  9. Question 9Intermediate

    Endpoint Security Management · Identify and validate the impact of agent operational states

    A Cortex XDR agent on a domain controller is showing an operational status of 'Protected (Kernel Mode)'. What does this status signify about the agent's capabilities on this endpoint?

    Show answer & explanation

    Correct answer: B

    The 'Protected (Kernel Mode)' status is the ideal operational state. It indicates that the agent is fully connected, has successfully loaded its kernel-level driver, and can enforce all configured security policies, including advanced exploit and malware protection mechanisms that require deep OS integration.

  10. Question 10Advanced

    Data Analysis · Use XQL to query datasets

    An analyst needs to find all network connections made to IP addresses within the 10.0.0.0/8 private range that did NOT originate from the svchost.exe process. Which where clause in an XQL query correctly represents this logic?

    Show answer & explanation

    Correct answer: B

    This query is correct. It uses the cidr() function to properly filter for IP addresses within the specified subnet. It also uses the correct field names action_remote_ip and actor_process_image_name from the XDR schema and the standard not-equal operator !=.

Ready for the real thing?

The full xdr-analyst simulator has every exam-style question, timed mode, and instant scoring.