Practice XSIAM-Analyst Endpoint Security Management questions with full explanations on every answer.
Start practicing
Endpoint Security Management — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise is experiencing high CPU utilization on a subset of developer endpoints running specialized compilation software. The Cortex XDR agent is suspected to be causing file-system scanning overhead. Which specific configuration setting should be adjusted in the Endpoint Security profile to safely reduce resource utilization without entirely disabling threat prevention?
2An analyst observes that a specific endpoint has stopped generating endpoint telemetry events (such as process execution and file creation logs) into XSIAM, although the endpoint is powered on and connected to the corporate network. Upon checking the agent, the service is running. Which troubleshooting step should the analyst perform next to diagnose endpoint event streaming issues?
3A security engineer is configuring a new Exploit Prevention profile in XSIAM. The requirement is to ensure that attempts to inject code into legitimate processes (DLL injection) are blocked and logged. Which section of the profile configuration controls memory protection techniques?
4An analyst needs to verify which endpoints have out-of-date Cortex XDR agent versions across the organization. Where should the analyst navigate in XSIAM to view a summary dashboard of agent versions and deployment health?
5A security analyst is investigating an endpoint in XSIAM and notices that telemetry is delayed and some security profiles are not applying. Which XSIAM built-in tool or view should the analyst check first to verify the current operational status, connected broker/gateway, and heartbeat connectivity of the Cortex XDR agent?
6An analyst needs to isolate a compromised workstation immediately from the XSIAM management console to prevent lateral movement. Where is the Network Isolation action executed for an individual asset?
7An administrator has created a new endpoint profile for a subset of point-of-sale (POS) terminals. After saving and assigning the profile, the administrator notices that terminals are not reflecting the updated policy settings. What is the most likely reason for this delay?
8An administrator needs to deploy the Cortex XDR agent to a large fleet of Windows endpoints via Group Policy. Where can the administrator download the latest signed agent installer package and associated transform file from the XSIAM management console?
9An organization requires that all endpoints check in with the XSIAM management console at least every 2 hours. If an endpoint fails to check in within this window, an alert should be generated. Where is this heartbeat threshold and associated notification rule configured?
10An administrator wants to review all endpoints running an outdated operating system version to plan an upgrade cycle. Which XSIAM feature provides grouped inventory data on operating system distribution?
11During a routine audit, an analyst notices that several endpoints have an agent status of 'Unmanaged' or 'Disconnected' for over 30 days. What is the standard behavior of XSIAM regarding endpoints that remain disconnected for extended periods?
12An administrator is planning a staged rollout of a new Cortex XDR agent version across the enterprise. To mitigate risk, the administrator wants to deploy the new version to a test group of endpoints first. How is this staged deployment managed in XSIAM?
13An administrator needs to verify whether disk encryption (BitLocker / FileVault) is active and reporting status correctly across managed endpoints in XSIAM. Where can this compliance status be monitored?
14An analyst wants to check the details of a specific security alert triggered on an endpoint, including the process tree and causality chain. Which XSIAM module contains the Causality Analysis View (CAV)?
15An analyst notices that a specific registry modification performed by a legitimate software installer is triggering a 'Suspicious Registry Modification' alert in XSIAM. The analyst wants to suppress this specific alert across all endpoints without disabling the underlying Behavioral Threat Protection module. What is the correct way to build this exception?
16An analyst notices that a custom PowerShell script used by system administrators is repeatedly blocked by the Cortex XDR agent as a suspicious execution. The analyst has verified the script's safety and wants to prevent future blocks without weakening overall script security for other scripts. How should this exception be configured in XSIAM?
17An organization deploys Cortex XDR agents to Linux servers. Certain critical database files residing on custom mount points are experiencing I/O latency due to agent monitoring. How should the administrator configure file integrity monitoring (FIM) or malware scan paths to exclude these specific mount points on Linux endpoints?
18A security analyst is reviewing endpoint telemetry and needs to find all execution events where a command shell (cmd.exe or powershell.exe) was spawned by a web server process (such as w3wp.exe). Which XSIAM tool is best suited for constructing and running this forensic query across historical endpoint data?
19An enterprise uses Broker VMs to proxy agent traffic from an isolated internal network segment to the XSIAM cloud. Several endpoints have stopped reporting via the Broker VM. Where should the administrator check to verify the health and connectivity between the Broker VM and the internal endpoints?
20An analyst needs to retrieve running process information from a specific active endpoint in real time without waiting for scheduled telemetry uploads. Which XSIAM feature should the analyst use?
21An endpoint has been compromised and cleaned, and the analyst wants to restore network connectivity for the host which was previously isolated. How should the analyst lift the network isolation in XSIAM?
22An administrator is configuring password protection for the Cortex XDR agent on endpoints to prevent unauthorized users or malware from stopping the agent service or modifying its configuration locally. Where is this agent uninstallation/tamper protection password configured in XSIAM?
23An administrator is preparing to deploy Cortex XDR agents across a mixed Windows and macOS environment. Which TWO prerequisites must be validated to ensure successful deployment and full functionality of the agent? (Choose two)
24When investigating an endpoint alert in XSIAM, an analyst wants to understand the full scope of potential compromise. Which THREE key data artifacts are typically available within the Causality Analysis View (CAV) for a suspicious process execution? (Choose three)
25An administrator is reviewing endpoint agent diagnostic tools available within XSIAM. Which THREE actions can be performed directly from the XSIAM console to troubleshoot or manage an endpoint agent? (Choose three)
26An administrator needs to manage endpoint security profiles in XSIAM. Which TWO types of prevention profiles can be configured and assigned to endpoints? (Choose two)
27An enterprise requires continuous monitoring of endpoint security posture. Which TWO metrics or statuses are actively tracked in the XSIAM endpoint asset inventory? (Choose two)
28An analyst is configuring behavioral threat protection rules and exceptions in XSIAM. Which THREE parameters can typically be used to define a precise exclusion rule for a benign application exhibiting suspicious behavior? (Choose three)
29An administrator is troubleshooting an endpoint where the Cortex XDR agent is failing to connect to the XSIAM tenant through a corporate proxy server. Which THREE proxy configuration parameters must be correctly supplied to the agent installation or policy to ensure successful connectivity? (Choose three)
30An administrator wants to ensure high availability and load distribution for endpoint agent reporting within a segmented enterprise network. Which TWO architectural components or features can be utilized in XSIAM to achieve this? (Choose two)
31An analyst is reviewing endpoint security alerts and needs to filter events by specific threat categories. Which TWO threat categories are commonly associated with Cortex XDR endpoint prevention modules? (Choose two)
32An administrator is configuring the automatic uninstallation protection and security settings for the Cortex XDR agent. Which THREE protection features can be enforced via the Agent Settings profile to secure the agent against tampering? (Choose three)
33An analyst is investigating an incident where an endpoint downloaded a suspicious file. Which TWO XSIAM tools or views can the analyst use to inspect the file's characteristics, hash, and reputation across the tenant? (Choose two)
The Endpoint Security Management domain covers the key concepts tested in this area of the XSIAM-Analyst exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all XSIAM-Analyst domains — no account required.
The Courseiva XSIAM-Analyst question bank contains 33 questions in the Endpoint Security Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Security Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included