XDR-Analyst · domain
Evidence Review And Response Actions
Practise Certified XDR Analyst (XDR-Analyst) Evidence Review And Response Actions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Evidence Review And Response Actions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Evidence Review And Response Actions
Evidence Review And Response Actions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Evidence Review And Response Actions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Evidence Review And Response Actions questions (63)
Click any question to see the full explanation, or start a practice session above.
An analyst is reviewing a cloud-based incident in Cortex XDR (such as AWS or Azure activity). Which evidence source provides the primary forensic logs for cloud resource modifications?
Medium2An analyst identifies a malicious persistence mechanism utilizing a Run registry key. After removing the threat, the analyst wants to verify whether any other machines have this exact registry key populated. Which tool should the analyst use?
Medium3An analyst is reviewing identity analytics data in Cortex XDR and notices an impossible travel alert for a user account. Which evidence artifact should the analyst primarily inspect to validate the login locations?
Easy4An analyst wants to ensure that a newly discovered legitimate application is excluded from Cortex XDR behavioral analysis without compromising overall security. Which THREE steps or considerations are essential? (Choose three)
Hard5During incident response, an analyst isolates a host using Cortex XDR. The user on the machine reports that they can no longer reach internal file shares, but the analyst still has visibility and control over the agent. How is this achieved?
Medium6An analyst notices suspicious network connections originating from an unknown process on an endpoint. To block outbound communication for this process without isolating the entire host, what action can be taken?
Medium7Which TWO details are typically reviewed when inspecting an alert in the Cortex XDR Incident Viewer? (Choose two)
Easy8Which TWO evidence sources help an analyst investigate whether an unauthorized user accessed a compromised workstation locally? (Choose two)
Medium9Which TWO actions are available to an analyst when managing an incident's assignment in Cortex XDR? (Choose two)
Easy10An analyst notices that a malicious binary dropped multiple secondary payloads and modified registry keys. The analyst decides to initiate a remediation action to undo these changes. Which Cortex XDR capability supports automatic remediation of file drops and registry modifications?
Medium11An analyst is investigating an advanced persistent threat (APT) that established persistence using multiple techniques. Which THREE persistence mechanisms should the analyst specifically check via Cortex XDR telemetry? (Choose three)
Hard12An analyst wants to view all security events associated with a specific user account across multiple devices over the last 7 days. Which Cortex XDR module provides user-centric investigation capabilities?
Easy13An analyst is investigating an alert and wants to check if the file was analyzed by WildFire. Where in the Cortex XDR console can the analyst view the WildFire sandbox verdict and analysis report?
Easy14An organization wants to configure Cortex XDR to automatically respond to high-severity ransomware alerts. Which THREE elements must be correctly configured to ensure successful automated mitigation? (Choose three)
Hard15When configuring a Response Playbook in Cortex XDR to automatically remediate an incident, what condition must be met for the playbook to execute successfully on an endpoint?
Hard16When conducting a comprehensive post-incident review and remediation verification in Cortex XDR, which THREE actions should an analyst perform? (Choose three)
Hard17An analyst receives an incident containing multiple related alerts across different machines. What is the primary benefit of the Cortex XDR Incident Viewer grouping these alerts together?
Easy18Which TWO pieces of information are displayed in the Incident summary dashboard of Cortex XDR? (Choose two)
Easy19When managing exclusions and exceptions in Cortex XDR, which THREE best practices should an analyst follow to maintain security posture? (Choose three)
Hard20Which TWO features in Cortex XDR assist an analyst in scoping an incident across the entire enterprise? (Choose two)
Easy21When reviewing an incident in Cortex XDR, which TWO types of artifacts are commonly available for inspection within the alert details? (Choose two)
Easy22An analyst needs to gather a memory dump and running process list from a remote endpoint for deep forensic analysis. Which Cortex XDR feature enables this collection?
Medium23An analyst is investigating an incident where a malicious file was dropped via email. Which TWO evidence artifacts should the analyst inspect to correlate the email vector with the endpoint execution? (Choose two)
Medium24Which TWO actions can an analyst take when closing an incident in Cortex XDR? (Choose two)
Easy25An analyst wants to create a robust incident response workflow in Cortex XDR that incorporates both manual analyst review and automated remediation. Which THREE capabilities support this integrated approach? (Choose three)
Hard26An analyst is performing advanced threat hunting in Cortex XDR using XQL. Which THREE clauses or functions are commonly used when constructing analytical queries for evidence review? (Choose three)
Hard27An analyst wants to prevent Cortex XDR from generating alerts on a specific signature-based detection (such as a known vulnerability scanner tool) across a specific endpoint group. Where should this exclusion be created?
Hard28An administrator needs to automate a remediation workflow so that whenever a specific critical alert severity is triggered, Cortex XDR automatically runs a script to collect forensic artifacts. Where must this automation be configured?
Hard29An analyst writes an XQL query to investigate lateral movement. Which dataset table in Cortex XDR contains comprehensive network connection telemetry across endpoints?
Hard30An analyst discovers that a malicious payload communicated with an external Command and Control (C2) server. Which TWO evidence sources should the analyst review to identify the C2 communication details? (Choose two)
Medium31Which TWO details does the Cortex XDR Incident Graph display during evidence review? (Choose two)
Easy32An analyst needs to change the status of an incident from 'Under Investigation' to 'Resolved' after completing remediation. Which section of the Incident View allows updating the incident status?
Easy33Which TWO forensic logs or artifacts are most valuable when investigating a suspected ransomware attack on an endpoint? (Choose two)
Medium34An organization experiences a false positive alert caused by a legitimate administrative script executed via PowerShell. The analyst wants to create an exception that applies specifically to this script's command-line arguments without whitelisting PowerShell entirely. What type of exception should be configured?
Hard35An analyst determines that a malicious file was executed on multiple endpoints within the environment. Using the Cortex XDR Query Builder (XQL Search), how can the analyst quickly locate all other instances of this specific file across the organization?
Medium36An administrator needs to configure automated incident response actions in Cortex XDR. Which THREE components are critical for building a successful automated response workflow? (Choose three)
Hard37An analyst is configuring a Response Playbook in Cortex XDR to handle automated containment. Which THREE actions can be automated within the playbook workflow? (Choose three)
Hard38An analyst is investigating an incident and wants to export the full incident report and associated artifact list for compliance reporting. Which option should the analyst select in Cortex XDR?
Easy39While reviewing a compromised host in the Cortex XDR Incident Viewer, an analyst wants to isolate the endpoint from the network to prevent lateral movement while maintaining administrative access. Which response action should the analyst initiate?
Medium40When an endpoint is isolated during an incident response action in Cortex XDR, which TWO types of network traffic are generally permitted to ensure continued management and minimal disruption? (Choose two)
Medium41During incident investigation, an analyst identifies an unauthorized script executed via WMI (Windows Management Instrumentation). Which TWO telemetry artifacts should the analyst examine to trace the activity? (Choose two)
Medium42When investigating an endpoint compromise, an analyst suspects DLL sideloading was used to execute malicious code. Which TWO telemetry indicators should the analyst examine? (Choose two)
Medium43An analyst reviewing an incident sees an indicator labeled as an 'IP Connection'. What information does this artifact provide?
Easy44Which TWO actions can be performed directly from the Cortex XDR Incident Details page when reviewing evidence? (Choose two)
Easy45Which TWO views in Cortex XDR are primarily used to monitor overall alert and incident status across the SOC? (Choose two)
Easy46Which TWO automated or manual response actions can be executed directly on an endpoint from the Cortex XDR Incident Response toolbox? (Choose two)
Medium47When configuring exceptions in Cortex XDR to suppress false positives, which THREE parameters can typically be leveraged to define the exception scope? (Choose three)
Hard48An analyst wants to ensure that any file evaluated with a specific SHA-256 hash is immediately blocked from execution across all endpoints managed by Cortex XDR, regardless of its WildFire verdict. Where should this hash be added?
Hard49An analyst reviewing an incident in Cortex XDR notices a suspicious scheduled task created by an attacker. What is the primary purpose of examining the scheduled task evidence?
Easy50An analyst is investigating an alert involving suspicious PowerShell execution. To thoroughly review the evidence, which THREE investigative steps should the analyst take within Cortex XDR? (Choose three)
Hard51When responding to a malware alert, an analyst decides to quarantine the offending file. Which TWO outcomes occur when Cortex XDR performs a file quarantine? (Choose two)
Medium52Which TWO views or tabs in Cortex XDR provide insight into forensic artifacts collected from endpoints? (Choose two)
Easy53An analyst is investigating a suspected phishing attack and needs to review the command line arguments passed to a suspicious email attachment execution. Where can the analyst find this evidence in Cortex XDR?
Medium54Which TWO actions should an analyst take when conducting evidence review for a suspected credential dumping incident? (Choose two)
Medium55When reviewing incident details in Cortex XDR, an analyst sees the 'MITRE ATT&CK' tab. What value does this tab provide during evidence review?
Easy56An analyst is investigating an endpoint alert in Cortex XDR and needs to review the process hierarchy that led to the execution of a suspicious PowerShell command. Which Cortex XDR view should the analyst examine?
Easy57An analyst wants to terminate a malicious process and all of its spawned child processes across a targeted endpoint directly from the Cortex XDR incident view. Which response action accomplishes this?
Medium58An organization uses Cortex XDR and wants to ensure that a known internal penetration testing tool is never blocked or alerted upon by Cortex XDR protection modules. Where should the exclusion be defined to affect all agents globally?
Hard59An analyst is investigating an alert where an attacker attempted credential dumping via LSASS. To understand the exact API calls and techniques used by the process, which evidence source within Cortex XDR provides low-level OS event telemetry?
Hard60When reviewing identity alerts in Cortex XDR, which TWO anomalous behaviors might indicate compromised credentials? (Choose two)
Medium61An analyst is reviewing the Causality Chain for an alert. Which TWO key insights does this view provide? (Choose two)
Easy62An analyst identifies that a legitimate software updater is triggering behavioral alerts due to spawning child processes typical of Living-off-the-Land binaries. To prevent alerts for this specific signed binary when executed from its legitimate path, what exception configuration is recommended?
Hard63An analyst identifies a custom, benign internal tool that is continuously flagged by a BIOC rule in Cortex XDR. To prevent future alerts without disabling the entire rule globally, what is the best practice method to create an exception?
HardOther domains
All XDR-Analyst exam domains
Frequently asked questions
- What does the Evidence Review And Response Actions domain cover on the XDR-Analyst exam?
- Evidence Review And Response Actions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 63 Evidence Review And Response Actions questions in the XDR-Analyst question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Evidence Review And Response Actions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.