XSIAM-Analyst · domain
Endpoint Security Management
Practise Certified XSIAM Analyst (XSIAM-Analyst) Endpoint Security Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Endpoint Security Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Endpoint Security Management
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).
SLAAC vs DHCPv6 vs stateful assignment.
Neighbor Discovery Protocol replacing ARP.
IPv6 routing differences and dual-stack coexistence.
Watch out for
Common Endpoint Security Management exam traps
- ▸Link-local addresses are not routable beyond the local link.
- ▸SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
- ▸NDP uses ICMPv6, not ARP.
- ▸An IPv6 prefix is /64 for most host subnets, not /24.
Question index
All Endpoint Security Management questions (33)
Click any question to see the full explanation, or start a practice session above.
An administrator is troubleshooting an endpoint where the Cortex XDR agent is failing to connect to the XSIAM tenant through a corporate proxy server. Which THREE proxy configuration parameters must be correctly supplied to the agent installation or policy to ensure successful connectivity? (Choose three)
Hard2An organization requires that all endpoints check in with the XSIAM management console at least every 2 hours. If an endpoint fails to check in within this window, an alert should be generated. Where is this heartbeat threshold and associated notification rule configured?
Hard3An administrator is preparing to deploy Cortex XDR agents across a mixed Windows and macOS environment. Which TWO prerequisites must be validated to ensure successful deployment and full functionality of the agent? (Choose two)
Medium4An administrator is configuring the automatic uninstallation protection and security settings for the Cortex XDR agent. Which THREE protection features can be enforced via the Agent Settings profile to secure the agent against tampering? (Choose three)
Hard5A security analyst is investigating an endpoint in XSIAM and notices that telemetry is delayed and some security profiles are not applying. Which XSIAM built-in tool or view should the analyst check first to verify the current operational status, connected broker/gateway, and heartbeat connectivity of the Cortex XDR agent?
Medium6An analyst notices that a specific registry modification performed by a legitimate software installer is triggering a 'Suspicious Registry Modification' alert in XSIAM. The analyst wants to suppress this specific alert across all endpoints without disabling the underlying Behavioral Threat Protection module. What is the correct way to build this exception?
Hard7An enterprise is experiencing high CPU utilization on a subset of developer endpoints running specialized compilation software. The Cortex XDR agent is suspected to be causing file-system scanning overhead. Which specific configuration setting should be adjusted in the Endpoint Security profile to safely reduce resource utilization without entirely disabling threat prevention?
Hard8When investigating an endpoint alert in XSIAM, an analyst wants to understand the full scope of potential compromise. Which THREE key data artifacts are typically available within the Causality Analysis View (CAV) for a suspicious process execution? (Choose three)
Hard9An analyst wants to check the details of a specific security alert triggered on an endpoint, including the process tree and causality chain. Which XSIAM module contains the Causality Analysis View (CAV)?
Easy10An administrator needs to manage endpoint security profiles in XSIAM. Which TWO types of prevention profiles can be configured and assigned to endpoints? (Choose two)
Easy11An administrator has created a new endpoint profile for a subset of point-of-sale (POS) terminals. After saving and assigning the profile, the administrator notices that terminals are not reflecting the updated policy settings. What is the most likely reason for this delay?
Medium12An analyst notices that a custom PowerShell script used by system administrators is repeatedly blocked by the Cortex XDR agent as a suspicious execution. The analyst has verified the script's safety and wants to prevent future blocks without weakening overall script security for other scripts. How should this exception be configured in XSIAM?
Hard13An analyst needs to isolate a compromised workstation immediately from the XSIAM management console to prevent lateral movement. Where is the Network Isolation action executed for an individual asset?
Easy14An enterprise requires continuous monitoring of endpoint security posture. Which TWO metrics or statuses are actively tracked in the XSIAM endpoint asset inventory? (Choose two)
Medium15During a routine audit, an analyst notices that several endpoints have an agent status of 'Unmanaged' or 'Disconnected' for over 30 days. What is the standard behavior of XSIAM regarding endpoints that remain disconnected for extended periods?
Medium16An administrator needs to verify whether disk encryption (BitLocker / FileVault) is active and reporting status correctly across managed endpoints in XSIAM. Where can this compliance status be monitored?
Easy17A security analyst is reviewing endpoint telemetry and needs to find all execution events where a command shell (cmd.exe or powershell.exe) was spawned by a web server process (such as w3wp.exe). Which XSIAM tool is best suited for constructing and running this forensic query across historical endpoint data?
Medium18An analyst observes that a specific endpoint has stopped generating endpoint telemetry events (such as process execution and file creation logs) into XSIAM, although the endpoint is powered on and connected to the corporate network. Upon checking the agent, the service is running. Which troubleshooting step should the analyst perform next to diagnose endpoint event streaming issues?
Hard19An organization deploys Cortex XDR agents to Linux servers. Certain critical database files residing on custom mount points are experiencing I/O latency due to agent monitoring. How should the administrator configure file integrity monitoring (FIM) or malware scan paths to exclude these specific mount points on Linux endpoints?
Hard20An administrator is configuring password protection for the Cortex XDR agent on endpoints to prevent unauthorized users or malware from stopping the agent service or modifying its configuration locally. Where is this agent uninstallation/tamper protection password configured in XSIAM?
Medium21An analyst is reviewing endpoint security alerts and needs to filter events by specific threat categories. Which TWO threat categories are commonly associated with Cortex XDR endpoint prevention modules? (Choose two)
Easy22An administrator is reviewing endpoint agent diagnostic tools available within XSIAM. Which THREE actions can be performed directly from the XSIAM console to troubleshoot or manage an endpoint agent? (Choose three)
Medium23An analyst is configuring behavioral threat protection rules and exceptions in XSIAM. Which THREE parameters can typically be used to define a precise exclusion rule for a benign application exhibiting suspicious behavior? (Choose three)
Hard24An administrator wants to review all endpoints running an outdated operating system version to plan an upgrade cycle. Which XSIAM feature provides grouped inventory data on operating system distribution?
Easy25An administrator needs to deploy the Cortex XDR agent to a large fleet of Windows endpoints via Group Policy. Where can the administrator download the latest signed agent installer package and associated transform file from the XSIAM management console?
Easy26An endpoint has been compromised and cleaned, and the analyst wants to restore network connectivity for the host which was previously isolated. How should the analyst lift the network isolation in XSIAM?
Medium27An analyst is investigating an incident where an endpoint downloaded a suspicious file. Which TWO XSIAM tools or views can the analyst use to inspect the file's characteristics, hash, and reputation across the tenant? (Choose two)
Medium28An enterprise uses Broker VMs to proxy agent traffic from an isolated internal network segment to the XSIAM cloud. Several endpoints have stopped reporting via the Broker VM. Where should the administrator check to verify the health and connectivity between the Broker VM and the internal endpoints?
Hard29A security engineer is configuring a new Exploit Prevention profile in XSIAM. The requirement is to ensure that attempts to inject code into legitimate processes (DLL injection) are blocked and logged. Which section of the profile configuration controls memory protection techniques?
Medium30An analyst needs to verify which endpoints have out-of-date Cortex XDR agent versions across the organization. Where should the analyst navigate in XSIAM to view a summary dashboard of agent versions and deployment health?
Easy31An administrator is planning a staged rollout of a new Cortex XDR agent version across the enterprise. To mitigate risk, the administrator wants to deploy the new version to a test group of endpoints first. How is this staged deployment managed in XSIAM?
Medium32An analyst needs to retrieve running process information from a specific active endpoint in real time without waiting for scheduled telemetry uploads. Which XSIAM feature should the analyst use?
Easy33An administrator wants to ensure high availability and load distribution for endpoint agent reporting within a segmented enterprise network. Which TWO architectural components or features can be utilized in XSIAM to achieve this? (Choose two)
MediumOther domains
All XSIAM-Analyst exam domains
Frequently asked questions
- What does the Endpoint Security Management domain cover on the XSIAM-Analyst exam?
- IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
- How many questions are in this domain?
- This page lists all 33 Endpoint Security Management questions in the XSIAM-Analyst question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Endpoint Security Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.