Courseiva
Evidence Review And Response ActionsmediumMultiple SelectObjective-mapped

XDR-Analyst Evidence Review And Response Actions Practice Question

An analyst discovers that a malicious payload communicated with an external Command and Control (C2) server. Which TWO evidence sources should the analyst review to identify the C2 communication details? (Choose two)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Network connection event logs (Destination IP, port, and connection duration)

C2 communications are investigated using network connection telemetry and DNS request history logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Local office printer toner cartridge status

    Why it's wrong here

    Toner status is printer hardware telemetry.

  • Employee parking permit registration forms

    Why it's wrong here

    Parking permits are administrative HR records.

  • Network connection event logs (Destination IP, port, and connection duration)

    Why this is correct

    Network event logs record outbound connection destinations and ports used for C2.

  • Corporate conference room booking calendars

    Why it's wrong here

    Conference room calendars track meeting schedules.

  • DNS query logs showing domain names resolved by the endpoint

    Why this is correct

    DNS logs reveal domain names queried prior to establishing C2 connections.

About these practice questions

Courseiva writes every XDR-Analyst question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This XDR-Analyst practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XDR-Analyst exam.