Courseiva
Back to Certified XDR Analyst (XDR-Analyst) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified XDR Analyst (XDR-Analyst) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
XDR-Analyst
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related XDR-Analyst topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which TWO attributes are typically displayed by default or through featured fields in the Cortex XDR Incident View grid? (Choose two)

Question 2mediummulti select
Full question →

Which TWO mechanisms are used by Cortex XDR to prevent alert fatigue during the raw-alert-to-incident lifecycle? (Choose two)

Question 3mediummulti select
Full question →

Which TWO factors directly influence how Cortex XDR calculates the overall severity score of an incident? (Choose two)

Question 4hardmulti select
Full question →

Which THREE actions are appropriate when an analyst determines that a recurring raw alert is a confirmed false positive and wishes to prevent future incident pollution? (Choose three)

Question 5hardmulti select
Full question →

During an investigation, an analyst examines the Causality Chain and Incident Graph. What THREE key insights do these visualization tools provide into the incident lifecycle? (Choose three)

Question 6hardmulti select
Full question →

Which TWO methods can an administrator use to customize or enhance the visibility of metadata in the Cortex XDR Incident View? (Choose two)

Question 7mediummulti select
Full question →

Which TWO actions can an analyst perform to manage and highlight specific findings during an incident investigation in Cortex XDR? (Choose two)

What THREE conditions can cause data stitching failures between network logs and endpoint telemetry in Cortex XDR? (Choose three)

Question 9hardmulti select
Full question →

What THREE criteria are evaluated by Cortex XDR when determining whether incoming raw alerts should be grouped into an existing incident or spawn a new one? (Choose three)

Question 10mediummulti select
Full question →

Which TWO states represent valid stages in the standard lifecycle of an incident within Cortex XDR? (Choose two)

Question 11mediummulti select
Full question →

Which TWO actions can an administrator take to tune incident scoring for high-value assets? (Choose two)

Question 12hardmulti select
Full question →

When managing the alert lifecycle in Cortex XDR, analysts can perform various triage and prioritization tasks. Which THREE features or options are available to analysts when managing active incidents and alerts? (Choose three)

Question 13mediummulti select
Full question →

Which TWO tasks can be performed directly from the Incident View in Cortex XDR? (Choose two)

During incident investigation, an analyst identifies an unauthorized script executed via WMI (Windows Management Instrumentation). Which TWO telemetry artifacts should the analyst examine to trace the activity? (Choose two)

Question 15mediummulti select
Full question →

Which TWO actions should an analyst take when conducting evidence review for a suspected credential dumping incident? (Choose two)

Question 16hardmulti select
Read the full Ansible explanation →

An analyst is configuring a Response Playbook in Cortex XDR to handle automated containment. Which THREE actions can be automated within the playbook workflow? (Choose three)

Question 17hardmulti select
Full question →

An administrator needs to configure automated incident response actions in Cortex XDR. Which THREE components are critical for building a successful automated response workflow? (Choose three)

Question 18easymulti select
Full question →

When reviewing an incident in Cortex XDR, which TWO types of artifacts are commonly available for inspection within the alert details? (Choose two)

Question 19mediummulti select
Full question →

Which TWO automated or manual response actions can be executed directly on an endpoint from the Cortex XDR Incident Response toolbox? (Choose two)

Question 20mediummulti select
Full question →

When reviewing identity alerts in Cortex XDR, which TWO anomalous behaviors might indicate compromised credentials? (Choose two)

These XDR-Analyst practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style XDR-Analyst questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.