Courseiva

XSIAM-Analyst · domain

Endpoint Security Management

Practise Certified XSIAM Analyst (XSIAM-Analyst) Endpoint Security Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

33 questions9 easy13 medium11 hard

Focused practice

Practice Endpoint Security Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Endpoint Security Management

IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.

IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).

SLAAC vs DHCPv6 vs stateful assignment.

Neighbor Discovery Protocol replacing ARP.

IPv6 routing differences and dual-stack coexistence.

Watch out for

Common Endpoint Security Management exam traps

  • Link-local addresses are not routable beyond the local link.
  • SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
  • NDP uses ICMPv6, not ARP.
  • An IPv6 prefix is /64 for most host subnets, not /24.

Question index

All Endpoint Security Management questions (33)

Click any question to see the full explanation, or start a practice session above.

1

An administrator is troubleshooting an endpoint where the Cortex XDR agent is failing to connect to the XSIAM tenant through a corporate proxy server. Which THREE proxy configuration parameters must be correctly supplied to the agent installation or policy to ensure successful connectivity? (Choose three)

Hard
2

An organization requires that all endpoints check in with the XSIAM management console at least every 2 hours. If an endpoint fails to check in within this window, an alert should be generated. Where is this heartbeat threshold and associated notification rule configured?

Hard
3

An administrator is preparing to deploy Cortex XDR agents across a mixed Windows and macOS environment. Which TWO prerequisites must be validated to ensure successful deployment and full functionality of the agent? (Choose two)

Medium
4

An administrator is configuring the automatic uninstallation protection and security settings for the Cortex XDR agent. Which THREE protection features can be enforced via the Agent Settings profile to secure the agent against tampering? (Choose three)

Hard
5

A security analyst is investigating an endpoint in XSIAM and notices that telemetry is delayed and some security profiles are not applying. Which XSIAM built-in tool or view should the analyst check first to verify the current operational status, connected broker/gateway, and heartbeat connectivity of the Cortex XDR agent?

Medium
6

An analyst notices that a specific registry modification performed by a legitimate software installer is triggering a 'Suspicious Registry Modification' alert in XSIAM. The analyst wants to suppress this specific alert across all endpoints without disabling the underlying Behavioral Threat Protection module. What is the correct way to build this exception?

Hard
7

An enterprise is experiencing high CPU utilization on a subset of developer endpoints running specialized compilation software. The Cortex XDR agent is suspected to be causing file-system scanning overhead. Which specific configuration setting should be adjusted in the Endpoint Security profile to safely reduce resource utilization without entirely disabling threat prevention?

Hard
8

When investigating an endpoint alert in XSIAM, an analyst wants to understand the full scope of potential compromise. Which THREE key data artifacts are typically available within the Causality Analysis View (CAV) for a suspicious process execution? (Choose three)

Hard
9

An analyst wants to check the details of a specific security alert triggered on an endpoint, including the process tree and causality chain. Which XSIAM module contains the Causality Analysis View (CAV)?

Easy
10

An administrator needs to manage endpoint security profiles in XSIAM. Which TWO types of prevention profiles can be configured and assigned to endpoints? (Choose two)

Easy
11

An administrator has created a new endpoint profile for a subset of point-of-sale (POS) terminals. After saving and assigning the profile, the administrator notices that terminals are not reflecting the updated policy settings. What is the most likely reason for this delay?

Medium
12

An analyst notices that a custom PowerShell script used by system administrators is repeatedly blocked by the Cortex XDR agent as a suspicious execution. The analyst has verified the script's safety and wants to prevent future blocks without weakening overall script security for other scripts. How should this exception be configured in XSIAM?

Hard
13

An analyst needs to isolate a compromised workstation immediately from the XSIAM management console to prevent lateral movement. Where is the Network Isolation action executed for an individual asset?

Easy
14

An enterprise requires continuous monitoring of endpoint security posture. Which TWO metrics or statuses are actively tracked in the XSIAM endpoint asset inventory? (Choose two)

Medium
15

During a routine audit, an analyst notices that several endpoints have an agent status of 'Unmanaged' or 'Disconnected' for over 30 days. What is the standard behavior of XSIAM regarding endpoints that remain disconnected for extended periods?

Medium
16

An administrator needs to verify whether disk encryption (BitLocker / FileVault) is active and reporting status correctly across managed endpoints in XSIAM. Where can this compliance status be monitored?

Easy
17

A security analyst is reviewing endpoint telemetry and needs to find all execution events where a command shell (cmd.exe or powershell.exe) was spawned by a web server process (such as w3wp.exe). Which XSIAM tool is best suited for constructing and running this forensic query across historical endpoint data?

Medium
18

An analyst observes that a specific endpoint has stopped generating endpoint telemetry events (such as process execution and file creation logs) into XSIAM, although the endpoint is powered on and connected to the corporate network. Upon checking the agent, the service is running. Which troubleshooting step should the analyst perform next to diagnose endpoint event streaming issues?

Hard
19

An organization deploys Cortex XDR agents to Linux servers. Certain critical database files residing on custom mount points are experiencing I/O latency due to agent monitoring. How should the administrator configure file integrity monitoring (FIM) or malware scan paths to exclude these specific mount points on Linux endpoints?

Hard
20

An administrator is configuring password protection for the Cortex XDR agent on endpoints to prevent unauthorized users or malware from stopping the agent service or modifying its configuration locally. Where is this agent uninstallation/tamper protection password configured in XSIAM?

Medium
21

An analyst is reviewing endpoint security alerts and needs to filter events by specific threat categories. Which TWO threat categories are commonly associated with Cortex XDR endpoint prevention modules? (Choose two)

Easy
22

An administrator is reviewing endpoint agent diagnostic tools available within XSIAM. Which THREE actions can be performed directly from the XSIAM console to troubleshoot or manage an endpoint agent? (Choose three)

Medium
23

An analyst is configuring behavioral threat protection rules and exceptions in XSIAM. Which THREE parameters can typically be used to define a precise exclusion rule for a benign application exhibiting suspicious behavior? (Choose three)

Hard
24

An administrator wants to review all endpoints running an outdated operating system version to plan an upgrade cycle. Which XSIAM feature provides grouped inventory data on operating system distribution?

Easy
25

An administrator needs to deploy the Cortex XDR agent to a large fleet of Windows endpoints via Group Policy. Where can the administrator download the latest signed agent installer package and associated transform file from the XSIAM management console?

Easy
26

An endpoint has been compromised and cleaned, and the analyst wants to restore network connectivity for the host which was previously isolated. How should the analyst lift the network isolation in XSIAM?

Medium
27

An analyst is investigating an incident where an endpoint downloaded a suspicious file. Which TWO XSIAM tools or views can the analyst use to inspect the file's characteristics, hash, and reputation across the tenant? (Choose two)

Medium
28

An enterprise uses Broker VMs to proxy agent traffic from an isolated internal network segment to the XSIAM cloud. Several endpoints have stopped reporting via the Broker VM. Where should the administrator check to verify the health and connectivity between the Broker VM and the internal endpoints?

Hard
29

A security engineer is configuring a new Exploit Prevention profile in XSIAM. The requirement is to ensure that attempts to inject code into legitimate processes (DLL injection) are blocked and logged. Which section of the profile configuration controls memory protection techniques?

Medium
30

An analyst needs to verify which endpoints have out-of-date Cortex XDR agent versions across the organization. Where should the analyst navigate in XSIAM to view a summary dashboard of agent versions and deployment health?

Easy
31

An administrator is planning a staged rollout of a new Cortex XDR agent version across the enterprise. To mitigate risk, the administrator wants to deploy the new version to a test group of endpoints first. How is this staged deployment managed in XSIAM?

Medium
32

An analyst needs to retrieve running process information from a specific active endpoint in real time without waiting for scheduled telemetry uploads. Which XSIAM feature should the analyst use?

Easy
33

An administrator wants to ensure high availability and load distribution for endpoint agent reporting within a segmented enterprise network. Which TWO architectural components or features can be utilized in XSIAM to achieve this? (Choose two)

Medium

Frequently asked questions

What does the Endpoint Security Management domain cover on the XSIAM-Analyst exam?
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
How many questions are in this domain?
This page lists all 33 Endpoint Security Management questions in the XSIAM-Analyst question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Endpoint Security Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-xsiam-analyst PANW-XSIAM-ANALYST endpoint security management Practice Questions