Courseiva

XDR-Analyst · domain

Evidence Review And Response Actions

Practise Certified XDR Analyst (XDR-Analyst) Evidence Review And Response Actions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

63 questions21 easy21 medium21 hard

Focused practice

Practice Evidence Review And Response Actions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Evidence Review And Response Actions

Evidence Review And Response Actions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Evidence Review And Response Actions exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Evidence Review And Response Actions questions (63)

Click any question to see the full explanation, or start a practice session above.

1

An analyst is reviewing a cloud-based incident in Cortex XDR (such as AWS or Azure activity). Which evidence source provides the primary forensic logs for cloud resource modifications?

Medium
2

An analyst identifies a malicious persistence mechanism utilizing a Run registry key. After removing the threat, the analyst wants to verify whether any other machines have this exact registry key populated. Which tool should the analyst use?

Medium
3

An analyst is reviewing identity analytics data in Cortex XDR and notices an impossible travel alert for a user account. Which evidence artifact should the analyst primarily inspect to validate the login locations?

Easy
4

An analyst wants to ensure that a newly discovered legitimate application is excluded from Cortex XDR behavioral analysis without compromising overall security. Which THREE steps or considerations are essential? (Choose three)

Hard
5

During incident response, an analyst isolates a host using Cortex XDR. The user on the machine reports that they can no longer reach internal file shares, but the analyst still has visibility and control over the agent. How is this achieved?

Medium
6

An analyst notices suspicious network connections originating from an unknown process on an endpoint. To block outbound communication for this process without isolating the entire host, what action can be taken?

Medium
7

Which TWO details are typically reviewed when inspecting an alert in the Cortex XDR Incident Viewer? (Choose two)

Easy
8

Which TWO evidence sources help an analyst investigate whether an unauthorized user accessed a compromised workstation locally? (Choose two)

Medium
9

Which TWO actions are available to an analyst when managing an incident's assignment in Cortex XDR? (Choose two)

Easy
10

An analyst notices that a malicious binary dropped multiple secondary payloads and modified registry keys. The analyst decides to initiate a remediation action to undo these changes. Which Cortex XDR capability supports automatic remediation of file drops and registry modifications?

Medium
11

An analyst is investigating an advanced persistent threat (APT) that established persistence using multiple techniques. Which THREE persistence mechanisms should the analyst specifically check via Cortex XDR telemetry? (Choose three)

Hard
12

An analyst wants to view all security events associated with a specific user account across multiple devices over the last 7 days. Which Cortex XDR module provides user-centric investigation capabilities?

Easy
13

An analyst is investigating an alert and wants to check if the file was analyzed by WildFire. Where in the Cortex XDR console can the analyst view the WildFire sandbox verdict and analysis report?

Easy
14

An organization wants to configure Cortex XDR to automatically respond to high-severity ransomware alerts. Which THREE elements must be correctly configured to ensure successful automated mitigation? (Choose three)

Hard
15

When configuring a Response Playbook in Cortex XDR to automatically remediate an incident, what condition must be met for the playbook to execute successfully on an endpoint?

Hard
16

When conducting a comprehensive post-incident review and remediation verification in Cortex XDR, which THREE actions should an analyst perform? (Choose three)

Hard
17

An analyst receives an incident containing multiple related alerts across different machines. What is the primary benefit of the Cortex XDR Incident Viewer grouping these alerts together?

Easy
18

Which TWO pieces of information are displayed in the Incident summary dashboard of Cortex XDR? (Choose two)

Easy
19

When managing exclusions and exceptions in Cortex XDR, which THREE best practices should an analyst follow to maintain security posture? (Choose three)

Hard
20

Which TWO features in Cortex XDR assist an analyst in scoping an incident across the entire enterprise? (Choose two)

Easy
21

When reviewing an incident in Cortex XDR, which TWO types of artifacts are commonly available for inspection within the alert details? (Choose two)

Easy
22

An analyst needs to gather a memory dump and running process list from a remote endpoint for deep forensic analysis. Which Cortex XDR feature enables this collection?

Medium
23

An analyst is investigating an incident where a malicious file was dropped via email. Which TWO evidence artifacts should the analyst inspect to correlate the email vector with the endpoint execution? (Choose two)

Medium
24

Which TWO actions can an analyst take when closing an incident in Cortex XDR? (Choose two)

Easy
25

An analyst wants to create a robust incident response workflow in Cortex XDR that incorporates both manual analyst review and automated remediation. Which THREE capabilities support this integrated approach? (Choose three)

Hard
26

An analyst is performing advanced threat hunting in Cortex XDR using XQL. Which THREE clauses or functions are commonly used when constructing analytical queries for evidence review? (Choose three)

Hard
27

An analyst wants to prevent Cortex XDR from generating alerts on a specific signature-based detection (such as a known vulnerability scanner tool) across a specific endpoint group. Where should this exclusion be created?

Hard
28

An administrator needs to automate a remediation workflow so that whenever a specific critical alert severity is triggered, Cortex XDR automatically runs a script to collect forensic artifacts. Where must this automation be configured?

Hard
29

An analyst writes an XQL query to investigate lateral movement. Which dataset table in Cortex XDR contains comprehensive network connection telemetry across endpoints?

Hard
30

An analyst discovers that a malicious payload communicated with an external Command and Control (C2) server. Which TWO evidence sources should the analyst review to identify the C2 communication details? (Choose two)

Medium
31

Which TWO details does the Cortex XDR Incident Graph display during evidence review? (Choose two)

Easy
32

An analyst needs to change the status of an incident from 'Under Investigation' to 'Resolved' after completing remediation. Which section of the Incident View allows updating the incident status?

Easy
33

Which TWO forensic logs or artifacts are most valuable when investigating a suspected ransomware attack on an endpoint? (Choose two)

Medium
34

An organization experiences a false positive alert caused by a legitimate administrative script executed via PowerShell. The analyst wants to create an exception that applies specifically to this script's command-line arguments without whitelisting PowerShell entirely. What type of exception should be configured?

Hard
35

An analyst determines that a malicious file was executed on multiple endpoints within the environment. Using the Cortex XDR Query Builder (XQL Search), how can the analyst quickly locate all other instances of this specific file across the organization?

Medium
36

An administrator needs to configure automated incident response actions in Cortex XDR. Which THREE components are critical for building a successful automated response workflow? (Choose three)

Hard
37

An analyst is configuring a Response Playbook in Cortex XDR to handle automated containment. Which THREE actions can be automated within the playbook workflow? (Choose three)

Hard
38

An analyst is investigating an incident and wants to export the full incident report and associated artifact list for compliance reporting. Which option should the analyst select in Cortex XDR?

Easy
39

While reviewing a compromised host in the Cortex XDR Incident Viewer, an analyst wants to isolate the endpoint from the network to prevent lateral movement while maintaining administrative access. Which response action should the analyst initiate?

Medium
40

When an endpoint is isolated during an incident response action in Cortex XDR, which TWO types of network traffic are generally permitted to ensure continued management and minimal disruption? (Choose two)

Medium
41

During incident investigation, an analyst identifies an unauthorized script executed via WMI (Windows Management Instrumentation). Which TWO telemetry artifacts should the analyst examine to trace the activity? (Choose two)

Medium
42

When investigating an endpoint compromise, an analyst suspects DLL sideloading was used to execute malicious code. Which TWO telemetry indicators should the analyst examine? (Choose two)

Medium
43

An analyst reviewing an incident sees an indicator labeled as an 'IP Connection'. What information does this artifact provide?

Easy
44

Which TWO actions can be performed directly from the Cortex XDR Incident Details page when reviewing evidence? (Choose two)

Easy
45

Which TWO views in Cortex XDR are primarily used to monitor overall alert and incident status across the SOC? (Choose two)

Easy
46

Which TWO automated or manual response actions can be executed directly on an endpoint from the Cortex XDR Incident Response toolbox? (Choose two)

Medium
47

When configuring exceptions in Cortex XDR to suppress false positives, which THREE parameters can typically be leveraged to define the exception scope? (Choose three)

Hard
48

An analyst wants to ensure that any file evaluated with a specific SHA-256 hash is immediately blocked from execution across all endpoints managed by Cortex XDR, regardless of its WildFire verdict. Where should this hash be added?

Hard
49

An analyst reviewing an incident in Cortex XDR notices a suspicious scheduled task created by an attacker. What is the primary purpose of examining the scheduled task evidence?

Easy
50

An analyst is investigating an alert involving suspicious PowerShell execution. To thoroughly review the evidence, which THREE investigative steps should the analyst take within Cortex XDR? (Choose three)

Hard
51

When responding to a malware alert, an analyst decides to quarantine the offending file. Which TWO outcomes occur when Cortex XDR performs a file quarantine? (Choose two)

Medium
52

Which TWO views or tabs in Cortex XDR provide insight into forensic artifacts collected from endpoints? (Choose two)

Easy
53

An analyst is investigating a suspected phishing attack and needs to review the command line arguments passed to a suspicious email attachment execution. Where can the analyst find this evidence in Cortex XDR?

Medium
54

Which TWO actions should an analyst take when conducting evidence review for a suspected credential dumping incident? (Choose two)

Medium
55

When reviewing incident details in Cortex XDR, an analyst sees the 'MITRE ATT&CK' tab. What value does this tab provide during evidence review?

Easy
56

An analyst is investigating an endpoint alert in Cortex XDR and needs to review the process hierarchy that led to the execution of a suspicious PowerShell command. Which Cortex XDR view should the analyst examine?

Easy
57

An analyst wants to terminate a malicious process and all of its spawned child processes across a targeted endpoint directly from the Cortex XDR incident view. Which response action accomplishes this?

Medium
58

An organization uses Cortex XDR and wants to ensure that a known internal penetration testing tool is never blocked or alerted upon by Cortex XDR protection modules. Where should the exclusion be defined to affect all agents globally?

Hard
59

An analyst is investigating an alert where an attacker attempted credential dumping via LSASS. To understand the exact API calls and techniques used by the process, which evidence source within Cortex XDR provides low-level OS event telemetry?

Hard
60

When reviewing identity alerts in Cortex XDR, which TWO anomalous behaviors might indicate compromised credentials? (Choose two)

Medium
61

An analyst is reviewing the Causality Chain for an alert. Which TWO key insights does this view provide? (Choose two)

Easy
62

An analyst identifies that a legitimate software updater is triggering behavioral alerts due to spawning child processes typical of Living-off-the-Land binaries. To prevent alerts for this specific signed binary when executed from its legitimate path, what exception configuration is recommended?

Hard
63

An analyst identifies a custom, benign internal tool that is continuously flagged by a BIOC rule in Cortex XDR. To prevent future alerts without disabling the entire rule globally, what is the best practice method to create an exception?

Hard

Frequently asked questions

What does the Evidence Review And Response Actions domain cover on the XDR-Analyst exam?
Evidence Review And Response Actions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 63 Evidence Review And Response Actions questions in the XDR-Analyst question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Evidence Review And Response Actions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-xdr-analyst PANW-XDR-ANALYST evidence review and response actions Practice Questions