Courseiva
Identity Threat Detection And ResponsehardMultiple SelectObjective-mapped

XDR-Analyst Identity Threat Detection And Response Practice Question

An analyst is investigating an incident where an attacker leveraged compromised credentials to establish persistence via Active Directory object manipulation. Which TWO Active Directory event logs or actions captured by ITDR monitoring should the analyst examine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Windows Security Event IDs related to security group membership changes (e.g., adding a user to Domain Admins)

Persistence via AD object manipulation is logged via Security Event ID 5136 (Directory Service Object was modified) and group membership additions (Event ID 4728/4732).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DHCP IP lease renewal event logs

    Why it's wrong here

    DHCP renewals track IP addresses, not Active Directory object modifications.

  • Windows Security Event IDs related to security group membership changes (e.g., adding a user to Domain Admins)

    Why this is correct

    Adding accounts to privileged groups is a standard persistence mechanism logged via specific group change event IDs.

  • Windows Security Event ID 5136 indicating a directory service object was modified

    Why this is correct

    Event 5136 records modifications to AD objects, which is common when setting up persistence (e.g., ACL modifications).

  • Network switch port duplex status logs

    Why it's wrong here

    Switch duplex logs relate to physical layer network connectivity.

  • Antivirus signature version update timestamps

    Why it's wrong here

    AV signatures are unrelated to AD persistence mechanisms.

About these practice questions

This XDR-Analyst question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This XDR-Analyst practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XDR-Analyst exam.