ExamDumpster

Free xdr-analyst sample questions

Real questions from the XDR Analyst practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A SOC analyst at a financial services firm is investigating a high-severity incident originating from a database server. The causality chain indicates that a legitimate, signed administrative tool, `db_admin_util.exe`, was used to spawn a PowerShell process that connected to a known malicious IP address. The firm's policy prohibits isolating this critical server. Which response action in Cortex XDR would be most effective at containing the immediate threat while adhering to the policy?

Question 2Choose 2

A security team is deploying Cortex XDR agents to a new fleet of developer workstations. To minimize false positives from custom-built applications and scripts, the team creates a specific Security Profile for this group. Which two settings within the Malware Protection profile are most appropriate for allowing legitimate, internally developed tools to run without triggering alerts, while still maintaining a strong security posture? (Select TWO)

Question 3Choose one

An analyst needs to create a scheduled XQL query that runs daily to identify any process that creates a file with a '.ps1' extension in a user's 'Downloads' directory. Which XQL query correctly accomplishes this?

Question 4Choose one

During an incident investigation, an analyst observes that Cortex XDR has automatically stitched together alerts from an endpoint, a firewall, and an identity provider into a single incident. What is the primary mechanism that enables this cross-domain data stitching?

Question 5Choose one

True or False: In Cortex XDR, using the 'Isolate Host' response action will immediately terminate all network connections, including the agent's connection back to the Cortex XDR console, preventing any further remote actions.

Question 6Choose one

An analyst is reviewing the Host Insights data for a critical server and notices that the 'OS Version' field is listed as 'Unsupported'. What is the most significant security implication of this status?

Question 7Choose one

A manufacturing company is concerned about intellectual property theft. A security analyst is tasked with creating a proactive threat hunting query to find evidence of large data exfiltration over DNS. Which XQL query would be most effective for this purpose?

Question 8Choose one

An XDR analyst is troubleshooting why a new exploit protection module is not being applied to a specific group of servers. The servers have the correct agent version installed and are connected to the console. What is the most likely reason for this issue?

Question 9Choose one

While investigating an incident, an analyst needs to retrieve a suspicious executable from a remote endpoint for sandboxing. The endpoint is currently isolated. Which is the correct sequence of steps to retrieve the file using Live Terminal?

Question 10Choose one

What is the primary function of a lookup table in Cortex XDR data analysis?

10 more free samples are waiting

Create a free account to unlock the whole xdr-analyst sample bank, or get full access to all 197 practice questions in the simulator.

Create account