xdr-analyst XDR Analyst Practice Questions
Prepare for xdr-analyst with more than an answer.
- Exam fee
- $250 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 4
- Alerting and Detection Processes23%
- Incident Handling and Response34%
- Data Analysis28%
- Endpoint Security Management15%
- 1
An alert is generated with a severity of 'High' and an incident score of 85. According to the alert prioritization handling process, what does this indicate to the analyst?
Show answer details
Correct answer: B
Incident scoring in Cortex XDR combines the severity of individual alerts with other factors, such as the number of alerts, the types of tactics and techniques observed (MITRE ATT&CK), and the criticality of the involved assets. A high score (typically 70-100) indicates a high-confidence, high-impact event that should be prioritized for immediate analysis and response.
- 2
What are the primary purposes of the Causality View in an incident? (Select TWO)
Show answer details
Correct answer: A, C
The Causality View provides a graphical representation of the attack chain, showing how one process launched another, which in turn created a file or network connection, helping the analyst understand the sequence of events.
By tracing the chain of events backward from the alert, the Causality View helps an analyst quickly identify the initial point of entry or execution—the root cause—of the incident.
- 3
An organization has a strict 90-day data retention policy for all security event data due to storage cost constraints. However, for compliance reasons, all authentication-related events must be kept for 365 days. How can an analyst configure Cortex XDR to meet these conflicting requirements?
Show answer details
Correct answer: C
Cortex Data Lake provides granular control over data retention. An administrator can set a default retention period (e.g., 90 days) and then create additional, filtered retention rules. In this case, they would create a rule with an XQL filter for authentication events (e.g.,
dataset = xdr_data and action_evtlog_event_id = 4624) and set the retention period for data matching that filter to 365 days. - 4
Case Study:
A retail company, 'StyleStream', is investigating a data breach. The initial indicator was an alert for a suspicious PowerShell command on a marketing department workstation. The analyst, upon viewing the causality chain, sees that the PowerShell process was launched by an Excel macro. This macro was enabled by a user who opened a phishing email with a malicious attachment named
Q3-Sales-Forecast.xlsm.The PowerShell script downloaded a second-stage payload from
http://malicious-domain.com/loader.exeand executed it. Theloader.exeprocess then established persistence via a new scheduled task and began scanning the internal network. The analyst needs to take immediate, comprehensive action to contain the threat and gather evidence.Which sequence of actions represents the most effective incident response strategy in this scenario?
Show answer details
Correct answer: B
This is the most comprehensive and methodologically sound approach. 1. Isolation immediately contains the threat. 2. Blocking the hashes of both the initial dropper and the payload prevents them from running elsewhere. 3. Blocking the C2 domain stops further communication. 4. Proactively hunting for other compromised machines using the observed IOC is a critical step to determine the scope of the breach.
- 5
An analyst uses the
alterstage in an XQL query. What is the purpose of this stage?flowchart TD A[Start: xdr_data] --> B{Filter Events}; B --> C[Alter: Create new_field]; C --> D{Further Processing}; D --> E[End: Final Results];Show answer details
Correct answer: B
The
alterstage is used for data manipulation within the query pipeline. It allows an analyst to create new fields based on calculations or functions (e.g.,alter new_field = field_a + field_b), modify existing fields, or remove fields from the results. It is essential for transforming raw data into a more useful format for analysis. - 6
A SOC analyst at a financial services firm is investigating a high-severity incident originating from a database server. The causality chain indicates that a legitimate, signed administrative tool,
db_admin_util.exe, was used to spawn a PowerShell process that connected to a known malicious IP address. The firm's policy prohibits isolating this critical server. Which response action in Cortex XDR would be most effective at containing the immediate threat while adhering to the policy?Show answer details
Correct answer: B
Terminating the specific malicious process is the most precise action. It stops the active threat (the C2 connection) without disrupting the legitimate administrative tool or the server's primary function, thus adhering to the policy against isolation. Blocking the legitimate tool's hash would cause operational disruption. Isolating the host is explicitly forbidden. Adding the IP to a block list is a good secondary step but doesn't stop the already running process.
- 7
A security team is deploying Cortex XDR agents to a new fleet of developer workstations. To minimize false positives from custom-built applications and scripts, the team creates a specific Security Profile for this group. Which two settings within the Malware Protection profile are most appropriate for allowing legitimate, internally developed tools to run without triggering alerts, while still maintaining a strong security posture? (Select TWO)
Show answer details
Correct answer: B, D
Adding the signer certificate is a secure and scalable way to trust all applications signed by the internal development team. This avoids having to allow-list every single file hash.
Creating process exceptions for specific directories is a common and effective method to prevent alerts on known-good applications running from a controlled location. This is more targeted than disabling entire modules.
- 8
An analyst needs to create a scheduled XQL query that runs daily to identify any process that creates a file with a '.ps1' extension in a user's 'Downloads' directory. Which XQL query correctly accomplishes this?
Show answer details
Correct answer: C
This query correctly uses the
xdr_datadataset, filters for the specificEnum.FileCreatedevent type, checks that theaction_file_pathcontains 'Downloads', and uses theends_withfunction to accurately find files with the '.ps1' extension. This is the most precise and correct syntax among the options. - 9
During an incident investigation, an analyst observes that Cortex XDR has automatically stitched together alerts from an endpoint, a firewall, and an identity provider into a single incident. What is the primary mechanism that enables this cross-domain data stitching?
Show answer details
Correct answer: C
The Causality Analysis Engine is the core component that processes data from all sources (endpoint, network, cloud, identity) and builds a comprehensive picture of an attack. It identifies relationships between events, such as a process on an endpoint making a network connection that is logged by a firewall, and stitches them together into a unified incident view.
- 10
True or False: In Cortex XDR, using the 'Isolate Host' response action will immediately terminate all network connections, including the agent's connection back to the Cortex XDR console, preventing any further remote actions.
Show answer details
Correct answer: B
The 'Isolate Host' action is designed to block all network traffic except for the essential communication between the Cortex XDR agent and the XDR console. This ensures that the analyst maintains control over the isolated endpoint and can perform further actions like running Live Terminal commands, collecting forensic data, or removing the isolation.
