Practice XDR-Analyst Identity Threat Detection And Response questions with full explanations on every answer.
Start practicing
Identity Threat Detection And Response — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An analyst needs to create a BIOC (Behavioral Indicator of Compromise) rule to detect suspicious use of 'whoami' execution by an authenticated domain user. Which data source should the rule evaluate?
2An analyst is configuring a BIOC rule to detect credential dumping via LSASS memory access. Which event characteristic must be monitored within the endpoint telemetry criteria?
3An organization wants to enrich Cortex XDR alerts with Active Directory context. Which component must be properly configured and running to collect user and group metadata for ITDR correlation?
4When investigating an identity-based alert in Cortex XDR, what information does the User View provide to the analyst?
5An administrator is reviewing compromised credentials in Cortex XDR. Where should they navigate to inspect identity analytics alerts specifically generated by user behavior analytics (UBA)?
6An analyst is reviewing an identity incident where an attacker performed a Kerberoasting attack. Which log source ingested by Cortex XDR is most critical for detecting requests for service tickets against high-privilege service principal names (SPNs)?
7What is the primary purpose of integrating Microsoft Entra ID (formerly Azure AD) logs into Cortex XDR?
8An organization experiences a Golden Ticket attack. How does Cortex XDR's identity analytics engine typically detect this type of Kerberos ticket manipulation?
9An ITDR rule in Cortex XDR triggers due to impossible travel detected for a user account. Upon investigation, the analyst discovers the source IP belongs to a corporate VPN egress node. How should the analyst prevent future false positives for this known infrastructure?
10An analyst is investigating a suspicious user account that accessed sensitive internal shares outside of normal business hours. Which Cortex XDR feature enables the analyst to review all actions taken by this user across endpoints and cloud services in a chronological timeline?
11Where can an administrator view the overall identity risk posture score across all users within the Cortex XDR management console?
12An administrator wants to configure automated response actions for high-severity ITDR alerts indicating active credential compromise. Which Cortex XDR feature allows automated actions such as disabling the compromised user account in Active Directory?
13An organization notices an increase in adversary reconnaissance using BloodHound to map Active Directory permissions. Which data telemetry in Cortex XDR can help detect the enumeration queries associated with this activity?
14Which log source is essential for Cortex XDR to track successful and failed interactive logon events on Windows workstations for ITDR analysis?
15What is the primary benefit of using Cortex XDR's identity correlation engine when triaging incidents?
16An organization wants to ensure that all administrative logon sessions are closely monitored for anomalous behaviors in Cortex XDR. Where should the administrator configure custom behavioral alert thresholds for privileged users?
17An analyst is investigating a suspected pass-the-ticket attack where an attacker injects a stolen Kerberos ticket into memory. Which endpoint telemetry data collected by the Cortex XDR Agent helps identify abnormal process behavior related to ticket injection tools (such as Mimikatz 'kerberos::ptt')
18An analyst is reviewing an XQL query designed to hunt for suspicious account creation followed by immediate group membership escalation in Active Directory. Which XQL construct is used to join Active Directory event datasets based on a common security identifier (SID)?
19A security analyst suspects an account compromise after noticing multiple rapid logins from geographically distant IP addresses within minutes. Which Cortex XDR feature automatically aggregates these related anomalous authentication indicators into a single incident?
20What role does the Cortex XDR Broker VM play regarding Active Directory and ITDR log collection?
21An attacker compromises a domain user account and attempts to enumerate domain admins using native Windows utilities (e.g., 'net group "Domain Admins" /domain'). Which Cortex XDR detection mechanism is specifically designed to catch such reconnaissance behaviors without relying solely on static signatures?
22Which TWO log sources are commonly ingested into Cortex XDR to support Identity Threat Detection and Response (ITDR)?
23Which THREE key components or features in Cortex XDR contribute directly to identifying and investigating compromised user credentials?
24An analyst notices that a service account is generating alerts for anomalous login locations. Upon review, the account is used by an automated batch script running from a newly provisioned server. How should the analyst resolve this alert while maintaining security best practices?
25Which TWO methods can an administrator use to ingest Active Directory logs into Cortex XDR?
26When reviewing identity analytics alerts in Cortex XDR, which THREE behavioral anomalies are typically flagged by the UBA engine as potential indicators of a compromised account?
27Which THREE features of Cortex XDR assist an analyst in conducting a deep-dive forensic investigation into an identity-based alert?
28Which THREE actions can be taken directly or via orchestration within Cortex XDR when responding to an active identity-based attack?
29Which TWO types of user accounts are critical to monitor closely for privilege abuse and anomalous behavior within an ITDR program?
30Which TWO metrics or components are typically included in a user's risk score calculation within Cortex XDR's identity analytics?
31Which THREE configuration steps are required to ensure Cortex XDR successfully correlates endpoint events with Active Directory user identities?
32An enterprise is facing credential stuffing attacks targeting its cloud and on-premises applications. Which TWO detection or mitigation strategies within Cortex XDR and integrated tools help address this threat?
33You are configuring integration between Cortex XDR and an external Identity Provider (IdP) to ingest user authentication logs for ITDR. Which component is primarily responsible for securely forwarding these IdP telemetry logs to the Cortex XDR data lake?
34Which TWO features in Cortex XDR assist analysts in communicating identity threat findings to stakeholders or compliance auditors?
35An analyst is investigating a compromised user account in Cortex XDR and wants to review identity-based alerts generated by Active Directory monitoring. Which specific view in the Cortex XDR management console provides a consolidated timeline of identity events and authentication anomalies for a specific user?
36An analyst is investigating an incident where an attacker leveraged compromised credentials to establish persistence via Active Directory object manipulation. Which TWO Active Directory event logs or actions captured by ITDR monitoring should the analyst examine?
37Which THREE indicators collected by Cortex XDR endpoint agents are crucial for identifying post-exploitation credential harvesting activities on a host?
38An organization notices an increase in credential dumping attacks against local Active Directory environments. They want to configure Cortex XDR Identity Analytics to trigger high-severity alerts when abnormal Kerberos ticket requests (such as potential Silver or Golden ticket activities) are detected. Where should the analyst enable or tune these specific identity behavior analytics rules?
39An analyst needs to verify whether Active Directory audit policies are correctly configured to supply Cortex XDR with the necessary event logs for Identity Threat Detection and Response. Which Windows Event ID range contains the core authentication and credential validation events required by Cortex XDR ITDR?
40While reviewing an incident involving suspicious lateral movement, an analyst notices that an adversary utilized compromised service account credentials. The analyst wants to use Cortex XDR response actions to immediately contain the threat without shutting down the entire domain controller. Which ITDR-related action can be executed directly from the Cortex XDR console for a compromised user account?
41Which TWO data sources can Cortex XDR leverage to build comprehensive user identity behavior profiles for ITDR? (Choose two)
42When deploying and troubleshooting the integration between Cortex XDR and Active Directory for ITDR, which TWO steps or configurations are critical to ensure successful telemetry collection? (Choose two)
43An administrator is setting up User Risk Scoring within Cortex XDR. They notice that certain service accounts with high volumes of automated authentications are skewing the risk calculations. How should the administrator handle these service accounts in Cortex XDR to prevent false-positive risk elevations?
44Which THREE key identity-based threat behaviors are typically detected and flagged by Cortex XDR Identity Analytics? (Choose three)
The Identity Threat Detection And Response domain covers the key concepts tested in this area of the XDR-Analyst exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all XDR-Analyst domains — no account required.
The Courseiva XDR-Analyst question bank contains 44 questions in the Identity Threat Detection And Response domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Identity Threat Detection And Response domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included