Palo Alto Networks XSIAM-Analyst - Palo Alto Networks Certified XSIAM Analyst Exam
Page: 3 / 12
Total 60 questions
Question #11 (Topic: Exam A)
Which Cytool command will re-enable protection on an endpoint that has Cortex XDR agent protection paused?
A. cytool security enable
B. cytool service start
C. cytool runtime start
D. cytool protect enable
Answer: C
Question #12 (Topic: Exam A)
A Cortex XSIAM analyst is reading a blog that references an unfamiliar critical zero-day vulnerability. This vulnerability has been weaponized, and there is evidence that it is being exploited by threat actors targeting a customer's industry.
Where can the analyst go within Cortex XSIAM to learn more about this vulnerability and any potential impacts on the customer environment?
Where can the analyst go within Cortex XSIAM to learn more about this vulnerability and any potential impacts on the customer environment?
A. Threat Intel Management --> Sample Analysis
B. Attack Surface --> Threat Response Center
C. Attack Surface --> Attack Surface Rules
D. Threat Intel Management --> Indicator
Answer: B
Question #13 (Topic: Exam A)
While investigating an alert, an analyst notices that a URL indicator has a related alert from a previous incident. The related alert has the same URL, but it resolved to a different IP address.
Which combination of two actions should the analyst take to resolve this issue? (Choose two.)
Which combination of two actions should the analyst take to resolve this issue? (Choose two.)
A. Enrich the IP address indicator associated with the previous alert.
B. Expire the URL indicator.
C. Remove the relationship between the URL and the older IP address.
D. Enrich the URL indicator.
Answer: CD
Question #14 (Topic: Exam A)
Which two actions will allow a security analyst to review updated commands from the core pack and interpret the results without altering the incident audit? (Choose two.)
A. Create a playbook with the commands and run it from within the War Room.
B. Run the core commands directly by typing them into the playground CLI.
C. Run the core commands directly from the Command and Scripts menu inside playground.
D. Run the core commands directly from the playground and invite other collaborators.
Answer: BC
Question #15 (Topic: Exam A)
Based on the image below, which two determinations can be made from the causality chain? (Choose two.)
A. Three alerts in total were generated by the agent on the endpoint.
B. Cortex XDR agent malware profile module applied is set to "Report" mode.
C. Malware.pdf.exe is responsible for the entire chain of execution resulting in the alerts.
D. The process cmd.exe is responsible for the entire chain of execution resulting in the alerts.
Answer: AC