Skip to content

Incident Handling and Response Questions

Practice questions for Incident Handling and Response topic in Palo Alto Networks Certified XDR Analyst. 68 questions covering this domain.

68 questions16 easy34 medium18 hard
Q1
medium

A team is mapping a workflow to alert evidence. Which choice best supports the need to review evidence tied to an alert before choosing a response whi...

Q2
easy

Which term should an analyst select when the task is to examine forensic evidence during an incident investigation during initial triage?

Q3
easy

Which XDR Analyst blueprint concept best matches the need to follow the chain of related activity in an incident during initial triage?

Q4
easy

Which XDR Analyst blueprint concept best matches the need to review evidence tied to an alert before choosing a response during initial triage?

Q5
hard

A SOC lead wants to plan remediation based on Cortex XDR guidance before escalating a case without shifting to an unrelated Cortex XDR function. Which...

Q6
medium

A team is mapping a workflow to security incidents. Which choice best supports the need to identify and analyze security incidents while validating an...

Q7
medium

A SOC analyst needs to review the chronological sequence of incident events while validating an investigation path. Which option is the best fit?

Q8
medium

During Cortex XDR operations, an analyst must include identity threat context in the investigation while validating an investigation path. Which conce...

Q9
medium

During Cortex XDR operations, an analyst must plan remediation based on Cortex XDR guidance during initial triage. Which concept or feature should the...

Q10
medium

A SOC analyst needs to examine forensic evidence during an incident investigation while validating an investigation path. Which option is the best fit...

Q11
medium

During Cortex XDR operations, an analyst must identify and analyze security events while validating an investigation path. Which concept or feature sh...

Q12
hard

A SOC lead wants to include identity threat context in the investigation when tuning daily SOC operations without shifting to an unrelated Cortex XDR ...

Q13
hard

A practitioner is validating a PANW-XDRA-aligned process and must examine forensic evidence during an incident investigation when tuning daily SOC ope...

Q14
medium

A team is mapping a workflow to causality chain. Which choice best supports the need to follow the chain of related activity in an incident while vali...

Q15
easy

In the PANW-XDRA blueprint, which choice aligns with the need to include identity threat context in the investigation during initial triage?

Q16
hard

An analyst is troubleshooting a Cortex XDR workflow and still needs to follow the chain of related activity in an incident when tuning daily SOC opera...

Q17
hard

An analyst is troubleshooting a Cortex XDR workflow and still needs to review evidence tied to an alert before choosing a response when tuning daily S...

Q18
medium

A SOC analyst needs to progress an investigation from evidence review to response while validating an investigation path. Which option is the best fit...

Q19
hard

A practitioner is validating a PANW-XDRA-aligned process and must review the chronological sequence of incident events when tuning daily SOC operation...

Q20
hard

A practitioner is validating a PANW-XDRA-aligned process and must select an available response action for an incident when tuning daily SOC operations...

Sign in to see all 68 questions

Create a free account to browse all questions — completely free during our launch phase.