Sample questions
Certified XDR Analyst (XDR-Analyst) practice questions
While investigating an alert in Cortex XDR, an analyst notices that a network-layer alert and an endpoint-layer alert have not been stitched into the same incident despite sharing…
An analyst needs to customize the Incident View columns to display specific custom IOC tags prominently next to the incident name. Which configuration area in Cortex XDR supports t…
An administrator notices that legitimate administrative scripts are repeatedly generating low-level behavioral alerts, cluttering the incident queue. How should the administrator h…
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →Which role-based permission is typically required for an analyst to change the status of an incident from 'New' to 'Under Investigation' in Cortex XDR?
What is the status of an incident in Cortex XDR immediately after it is automatically created by the correlation engine?
An enterprise ingests telemetry from both Cortex XDR agents and third-party firewall logs. What mechanism allows Cortex XDR to combine these disparate data sources into a unified i…
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →What is the primary benefit of the raw-alert-to-incident lifecycle consolidation in Cortex XDR?
Which TWO attributes are typically displayed by default or through featured fields in the Cortex XDR Incident View grid? (Choose two)
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →An incident in Cortex XDR contains dozens of low-priority alerts that were grouped together. The analyst determines that one specific alert within the incident is a false positive…
An organization requires that specific custom threat intelligence tags appear as primary columns in the Incident View. How can an administrator achieve this?
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →An organization's security operations center (SOC) wants to adjust how Cortex XDR calculates incident severity scores based on specific asset criticality tags. Where should the adm…
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →What is the primary purpose of starring an alert within an incident details pane?
Where in the Cortex XDR console can an analyst review the complete lifecycle timeline of an incident, from initial raw alert generation to final resolution?
Which TWO mechanisms are used by Cortex XDR to prevent alert fatigue during the raw-alert-to-incident lifecycle? (Choose two)
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →An analyst wants to quickly identify all alerts related to a specific external IP address across multiple incidents without opening each incident individually. Which feature in the…
A security analyst wants to prioritize incidents by highlighting critical cases that require immediate executive visibility. Which feature should the analyst use to flag these spec…
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →Which TWO factors directly influence how Cortex XDR calculates the overall severity score of an incident? (Choose two)
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →Which THREE actions are appropriate when an analyst determines that a recurring raw alert is a confirmed false positive and wishes to prevent future incident pollution? (Choose thr…
During an investigation, an analyst examines the Causality Chain and Incident Graph. What THREE key insights do these visualization tools provide into the incident lifecycle? (Choo…
A security analyst wants to adjust how Cortex XDR calculates incident severity to ensure that incidents involving domain controllers receive higher priority scores. Where should th…
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →During incident triage, an analyst notices that two completely separate attacks on different endpoints were merged into a single incident by Cortex XDR. What is the underlying reas…
An analyst is investigating an incident and needs to quickly view customized columns containing threat actor attribution tags in the incident grid. Which feature must be configured…
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →An analyst wants to flag a particular high-priority incident so that other shift analysts immediately notice it when they log in. What is the most direct feature to use?
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →An analyst wants to filter the Incident View to show only incidents that have been bookmarked by members of the SOC team. Which filter criterion should be applied?
Alert Lifecycle And Incident CorrelationmediumSee the answer and why each option is right or wrong →