PALO ALTO NETWORKS certification preparation
XSIAM-Analyst Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- XSIAM-Analyst
- Provider
- PALO ALTO NETWORKS
- Full set
- 50 questions
- Last Update Check
A SOC team member implements an incident starring configuration, but incidents created before this
configuration were not starred.
What is the cause of this behavior?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
An incident in Cortex XSIAM contains the following series of alerts:
10:24:17 AM - Informational Severity - XDR Analytics BIOC - Rare process execution in organization
10:24:18 AM - Low Severity - XDR BIOC - Suspicious AMSI DLL load location
10:24:20 AM - Medium Severity - XDR Agent - WildFire Malware
11:57:04 AM - High Severity - Correlation - Suspicious admin account creation
Which alert was responsible for the creation of the incident?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A Cortex XSIAM analyst in a SOC is reviewing an incident involving a workstation showing signs of a
potential breach. The incident includes an alert from Cortex XDR Analytics Alert source "Remote
service command execution from an uncommon source." As part of the incident handling process,
the analyst must apply response actions to contain the threat effectively.
Which initial Cortex XDR agent response action should be taken to reduce attacker mobility on the
network?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
What is the expected behavior when querying a data model with no specific fields specified in the
query?
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A Cortex XSIAM analyst is reading a blog that references an unfamiliar critical zero-day vulnerability.
This vulnerability has been weaponized, and there is evidence that it is being exploited by threat
actors targeting a customer's industry. Where can the analyst go within Cortex XSIAM to learn more
about this vulnerability and any potential impacts on the customer environment?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Which two actions will allow a security analyst to review updated commands from the core pack and
interpret the results without altering the incident audit? (Choose two)
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Which interval is the duration of time before an analytics detector can raise an alert?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
SCENARIO:
A security analyst has been assigned a ticket from the help desk stating that users are experiencing
errors when attempting to open files on a specific network share. These errors state that the file
format cannot be opened. IT has verified that the file server is online and functioning, but that all
files have unusual extensions attached to them.
The security analyst reviews alerts within Cortex XSIAM and identifies malicious activity related to a
possible ransomware attack on the file server. This incident is then escalated to the incident response
team for further investigation.
Upon reviewing the incident, the responders confirm that ransomware was successfully executed on
the file server. Other details of the attack are noted below:
• An unpatched vulnerability on an externally facing web server was exploited for initial access
• The attackers successfully used Mimikatz to dump sensitive credentials that were used for privilege
escalation
• PowerShell was used on a Windows server for additional discovery, as well as lateral movement to
other systems
• The attackers executed SystemBC RAT on multiple systems to maintain remote access
• Ransomware payload was downloaded on the file server via an external site "file io"
QUESTION STATEMENT:
Which hunt collection category in Cortex XSIAM should the incident responders use to identify all
systems where the attackers established persistence during the attack?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
In the Endpoint Data context menu of the Cortex XSIAM endpoints table, where will an analyst be
able to determine which users accessed an endpoint via Live Terminal?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
When a sub-playbook loops, which task tab will allow an analyst to determine what data the sub-
playbook used in each iteration of the loop?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
