Practice XDR-Analyst Evidence Review And Response Actions questions with full explanations on every answer.
Start practicing
Evidence Review And Response Actions — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to automate a remediation workflow so that whenever a specific critical alert severity is triggered, Cortex XDR automatically runs a script to collect forensic artifacts. Where must this automation be configured?
2An analyst identifies a custom, benign internal tool that is continuously flagged by a BIOC rule in Cortex XDR. To prevent future alerts without disabling the entire rule globally, what is the best practice method to create an exception?
3An analyst reviewing an incident in Cortex XDR notices a suspicious scheduled task created by an attacker. What is the primary purpose of examining the scheduled task evidence?
4An analyst is reviewing identity analytics data in Cortex XDR and notices an impossible travel alert for a user account. Which evidence artifact should the analyst primarily inspect to validate the login locations?
5While reviewing a compromised host in the Cortex XDR Incident Viewer, an analyst wants to isolate the endpoint from the network to prevent lateral movement while maintaining administrative access. Which response action should the analyst initiate?
6An analyst wants to terminate a malicious process and all of its spawned child processes across a targeted endpoint directly from the Cortex XDR incident view. Which response action accomplishes this?
7An analyst determines that a malicious file was executed on multiple endpoints within the environment. Using the Cortex XDR Query Builder (XQL Search), how can the analyst quickly locate all other instances of this specific file across the organization?
8An analyst is investigating an endpoint alert in Cortex XDR and needs to review the process hierarchy that led to the execution of a suspicious PowerShell command. Which Cortex XDR view should the analyst examine?
9An analyst needs to gather a memory dump and running process list from a remote endpoint for deep forensic analysis. Which Cortex XDR feature enables this collection?
10When reviewing incident details in Cortex XDR, an analyst sees the 'MITRE ATT&CK' tab. What value does this tab provide during evidence review?
11An organization uses Cortex XDR and wants to ensure that a known internal penetration testing tool is never blocked or alerted upon by Cortex XDR protection modules. Where should the exclusion be defined to affect all agents globally?
12An analyst notices that a malicious binary dropped multiple secondary payloads and modified registry keys. The analyst decides to initiate a remediation action to undo these changes. Which Cortex XDR capability supports automatic remediation of file drops and registry modifications?
13An analyst wants to view all security events associated with a specific user account across multiple devices over the last 7 days. Which Cortex XDR module provides user-centric investigation capabilities?
14An organization experiences a false positive alert caused by a legitimate administrative script executed via PowerShell. The analyst wants to create an exception that applies specifically to this script's command-line arguments without whitelisting PowerShell entirely. What type of exception should be configured?
15An analyst is investigating an alert where an attacker attempted credential dumping via LSASS. To understand the exact API calls and techniques used by the process, which evidence source within Cortex XDR provides low-level OS event telemetry?
16An analyst receives an incident containing multiple related alerts across different machines. What is the primary benefit of the Cortex XDR Incident Viewer grouping these alerts together?
17An analyst identifies a malicious persistence mechanism utilizing a Run registry key. After removing the threat, the analyst wants to verify whether any other machines have this exact registry key populated. Which tool should the analyst use?
18An analyst is investigating an alert and wants to check if the file was analyzed by WildFire. Where in the Cortex XDR console can the analyst view the WildFire sandbox verdict and analysis report?
19During incident response, an analyst isolates a host using Cortex XDR. The user on the machine reports that they can no longer reach internal file shares, but the analyst still has visibility and control over the agent. How is this achieved?
20When configuring a Response Playbook in Cortex XDR to automatically remediate an incident, what condition must be met for the playbook to execute successfully on an endpoint?
21An analyst wants to prevent Cortex XDR from generating alerts on a specific signature-based detection (such as a known vulnerability scanner tool) across a specific endpoint group. Where should this exclusion be created?
22An analyst reviewing an incident sees an indicator labeled as an 'IP Connection'. What information does this artifact provide?
23An analyst is investigating a suspected phishing attack and needs to review the command line arguments passed to a suspicious email attachment execution. Where can the analyst find this evidence in Cortex XDR?
24An analyst wants to ensure that any file evaluated with a specific SHA-256 hash is immediately blocked from execution across all endpoints managed by Cortex XDR, regardless of its WildFire verdict. Where should this hash be added?
25An analyst needs to change the status of an incident from 'Under Investigation' to 'Resolved' after completing remediation. Which section of the Incident View allows updating the incident status?
26An analyst is investigating an incident and wants to export the full incident report and associated artifact list for compliance reporting. Which option should the analyst select in Cortex XDR?
27An analyst writes an XQL query to investigate lateral movement. Which dataset table in Cortex XDR contains comprehensive network connection telemetry across endpoints?
28An analyst is reviewing a cloud-based incident in Cortex XDR (such as AWS or Azure activity). Which evidence source provides the primary forensic logs for cloud resource modifications?
29An analyst identifies that a legitimate software updater is triggering behavioral alerts due to spawning child processes typical of Living-off-the-Land binaries. To prevent alerts for this specific signed binary when executed from its legitimate path, what exception configuration is recommended?
30An analyst notices suspicious network connections originating from an unknown process on an endpoint. To block outbound communication for this process without isolating the entire host, what action can be taken?
31Which TWO automated or manual response actions can be executed directly on an endpoint from the Cortex XDR Incident Response toolbox? (Choose two)
32When reviewing an incident in Cortex XDR, which TWO types of artifacts are commonly available for inspection within the alert details? (Choose two)
33An analyst is reviewing the Causality Chain for an alert. Which TWO key insights does this view provide? (Choose two)
34Which TWO actions should an analyst take when conducting evidence review for a suspected credential dumping incident? (Choose two)
35When configuring exceptions in Cortex XDR to suppress false positives, which THREE parameters can typically be leveraged to define the exception scope? (Choose three)
36Which TWO pieces of information are displayed in the Incident summary dashboard of Cortex XDR? (Choose two)
37When managing exclusions and exceptions in Cortex XDR, which THREE best practices should an analyst follow to maintain security posture? (Choose three)
38During incident investigation, an analyst identifies an unauthorized script executed via WMI (Windows Management Instrumentation). Which TWO telemetry artifacts should the analyst examine to trace the activity? (Choose two)
39An analyst is configuring a Response Playbook in Cortex XDR to handle automated containment. Which THREE actions can be automated within the playbook workflow? (Choose three)
40Which TWO features in Cortex XDR assist an analyst in scoping an incident across the entire enterprise? (Choose two)
41An analyst wants to ensure that a newly discovered legitimate application is excluded from Cortex XDR behavioral analysis without compromising overall security. Which THREE steps or considerations are essential? (Choose three)
42When reviewing identity alerts in Cortex XDR, which TWO anomalous behaviors might indicate compromised credentials? (Choose two)
43Which TWO actions can an analyst take when closing an incident in Cortex XDR? (Choose two)
44Which TWO forensic logs or artifacts are most valuable when investigating a suspected ransomware attack on an endpoint? (Choose two)
45An analyst is performing advanced threat hunting in Cortex XDR using XQL. Which THREE clauses or functions are commonly used when constructing analytical queries for evidence review? (Choose three)
46Which TWO details are typically reviewed when inspecting an alert in the Cortex XDR Incident Viewer? (Choose two)
47An analyst is investigating an advanced persistent threat (APT) that established persistence using multiple techniques. Which THREE persistence mechanisms should the analyst specifically check via Cortex XDR telemetry? (Choose three)
48When an endpoint is isolated during an incident response action in Cortex XDR, which TWO types of network traffic are generally permitted to ensure continued management and minimal disruption? (Choose two)
49When responding to a malware alert, an analyst decides to quarantine the offending file. Which TWO outcomes occur when Cortex XDR performs a file quarantine? (Choose two)
50Which TWO views or tabs in Cortex XDR provide insight into forensic artifacts collected from endpoints? (Choose two)
51An analyst is investigating an alert involving suspicious PowerShell execution. To thoroughly review the evidence, which THREE investigative steps should the analyst take within Cortex XDR? (Choose three)
52Which TWO actions are available to an analyst when managing an incident's assignment in Cortex XDR? (Choose two)
53An administrator needs to configure automated incident response actions in Cortex XDR. Which THREE components are critical for building a successful automated response workflow? (Choose three)
54Which TWO details does the Cortex XDR Incident Graph display during evidence review? (Choose two)
55Which TWO evidence sources help an analyst investigate whether an unauthorized user accessed a compromised workstation locally? (Choose two)
56An analyst discovers that a malicious payload communicated with an external Command and Control (C2) server. Which TWO evidence sources should the analyst review to identify the C2 communication details? (Choose two)
57When conducting a comprehensive post-incident review and remediation verification in Cortex XDR, which THREE actions should an analyst perform? (Choose three)
58An analyst is investigating an incident where a malicious file was dropped via email. Which TWO evidence artifacts should the analyst inspect to correlate the email vector with the endpoint execution? (Choose two)
59An analyst wants to create a robust incident response workflow in Cortex XDR that incorporates both manual analyst review and automated remediation. Which THREE capabilities support this integrated approach? (Choose three)
60Which TWO actions can be performed directly from the Cortex XDR Incident Details page when reviewing evidence? (Choose two)
61When investigating an endpoint compromise, an analyst suspects DLL sideloading was used to execute malicious code. Which TWO telemetry indicators should the analyst examine? (Choose two)
62An organization wants to configure Cortex XDR to automatically respond to high-severity ransomware alerts. Which THREE elements must be correctly configured to ensure successful automated mitigation? (Choose three)
63Which TWO views in Cortex XDR are primarily used to monitor overall alert and incident status across the SOC? (Choose two)
The Evidence Review And Response Actions domain covers the key concepts tested in this area of the XDR-Analyst exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all XDR-Analyst domains — no account required.
The Courseiva XDR-Analyst question bank contains 63 questions in the Evidence Review And Response Actions domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Evidence Review And Response Actions domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included