Free XDR-Analyst Practice Test Questions and Answers (2026)

Last Update Check
View Mode
Q: 1
What is a primary use case of lookup tables in Cortex XDR?
Options
21 comments in the community discussion
3
A. Lookup tables are for correlating outside info with internal XDR data, not for creating datasets or auto reports.
3
Option A Not B-lookup tables aren’t for auto-dataset creation, mostly used for enrichment.
Q: 2
Which Cortex XDR feature allows hunting queries to be repeated automatically?
Options
26 comments in the community discussion
1
Its A based on what I remember from the docs and some official practice tests. Scheduled queries are the only ones that support auto-repeat for threat hunting, the others don’t schedule anything. Pretty sure but open to debate.
1
Its A, but if the question meant only saving queries instead of running them automatically, would it be B?
Q: 3
Remediation suggestions in XDR often include:
Options
21 comments in the community discussion
5
Option A
2
B tbh, Palo loves automation and false positive removal is always in their marketing.
Q: 4
What does “starring” an alert signify in the Cortex XDR console?
Options
31 comments in the community discussion
6
Option B was in my exam last year. Starring just flags it as important for the analyst, doesn't trigger any updates or actions on the alert itself. Let me know if someone got a different result.
2
Option B Saw a similar question in some exam reports, starring just makes the alert stand out as important.
Q: 5
Which of the following alert sources can provide identity-based alerts?
Options
26 comments in the community discussion
4
A. had something like this in a mock-directory services pulls in real user identities so fits identity-based alerts best.
2
C
Q: 6
What is the primary purpose of the Cortex XDR “Featured fields”?
Options
29 comments in the community discussion
2
B. not A. Featured fields are there to help triage by showing the most important attributes right away.
1
B featured fields just make triage way faster by surfacing the right stuff up top.
Q: 7
When reviewing alert evidence, which of the following provides the clearest insight into the root cause of an attack?
Options
30 comments in the community discussion
6
Option B. Official guide and lab walkthroughs usually say forensic host data is best for root cause in XDR scenarios.
2
B. ITDR logs are tempting but forensic data gives more direct evidence for root cause imo. If the question focused on credential abuse, maybe A, but here B fits better. Disagree?
Q: 8
Which two activities fall under forensic investigation in Cortex XDR? (Choose two)
Options
29 comments in the community discussion
2
A/B, seen exactly similar question in my exam and those two match the typical forensic investigation tasks every time.
2
C/D? I'm leaning toward D and C, but maybe I'm overthinking it. Configuring new firewall rules (C) feels like you'd do it as part of a containment step after you find something suspicious, so I could see someone picking it for investigation indirectly. Adjusting incident scores (D) also seems like you'd do while analyz
Q: 9
Which two benefits come from using the Query Library in Cortex XDR? (Choose two)
Options
29 comments in the community discussion
1
Actually, I'd say C. The Query Library should help with scheduling reports, right? I remember reading something about automating that process in practice questions. Not totally certain but C feels like a decent pick here.
1
Option C
Q: 10
Why is integrating dashboards, reports, and Host Insights valuable for SOCs?
Options
24 comments in the community discussion
9
Option A matches what I've seen in similar questions. Really clear distinction in the options here.
5
Makes sense to go with A here.
Q: 11
Which two outcomes can result from custom prioritization configuration? (Choose two)
Options
12 comments in the community discussion
1
I saw something similar in a recent practice, went with C and D.
1
Seen this before, it's definitely A and B. Custom prioritization is about tweaking alert severity and focusing on the most important assets, not auto-removing false positives or spinning up new playbooks. Pretty sure that's how XDR works.
Q: 12
The causality chain in Cortex XDR helps analysts:
Options
7 comments in the community discussion
1
Probably B, causality chain is that visual timeline of linked events. Not for licensing or auto playbooks, just seeing how stuff unfolded. Makes more sense than D here.
1
Seriously why is Palo Alto obsessed with visualization? Wouldn't D make more sense with alert handling?
Q: 13
Why is the timeline view useful during investigations?
Options
8 comments in the community discussion
1
Really clear question, nice. A is right since the timeline helps see each event in order, making it easier to piece together how the attack unfolded. Pretty sure that's what most exam reports say too.
A but I get why some think D, the timeline is mainly about order not grouping.
Q: 14
Which agent operational state indicates the endpoint is installed but not actively enforcing protection?
Options
5 comments in the community discussion
5
Makes sense, option C. Disabled is when the agent is there but protections are off. Disconnected still enforces, just not updating.
2
Why wouldn't it be B? If it's disconnected, doesn't that mean it's not enforcing protection?
Q: 15
Which two functions are supported in XQL queries? (Choose two)
Options
8 comments in the community discussion
1
C/D? I saw similar wording on some practice sets, so I'd check the official docs for exact XQL function support.
A/B imo, since COUNT() and SUM() are actual aggregation functions in XQL. PATCH() and REMEDIATE() sound like response actions, not things you'd use inside a query. Seen this trip up folks before.
Q: 16
Which Cortex XDR feature enables automated responses to certain threats?
Options
8 comments in the community discussion
1
It’s A, Playbooks integrated with XSOAR. XSOAR playbooks are the only option here that triggers actual automated response actions in Cortex XDR. The others are manual steps or config tweaks, not automation. D (exclusion rules) looks tempting but doesn’t handle responses to threats dynamically. Seen this on other practi
A tbh, since only playbooks with XSOAR let you automate real security responses like isolating hosts or blocking indicators. The rest (B, C, D) are more for tuning or manual actions. Not 100 percent sure if the exam ever tries to twist this, but all docs point at A.
Q: 17
Which of the following can be configured in a prevention policy but not in an extension profile?
Options
6 comments in the community discussion
1
Its A. You can only set malware blocking rules in a prevention policy, not in an extension profile. Extension (agent settings) profiles are more about agent operations and enabling modules, but malware rules specifically live inside the prevention policy. Pretty sure this lines up with how Cortex XDR splits configurati
A for sure. Had something like this in a mock, malware blocking is only configurable in the prevention policy, not within extension (agent settings) profiles. Host firewall and device control stuff can go in agent profiles but malware prevention needs its own policy. If I missed some hidden feature let me know, but
Q: 18
What type of data source is xdr_data considered?
Options
9 comments in the community discussion
Its B since xdr_data could be seen as incident-related when filtered by use case. If they're focusing on dataset roles during investigations instead of raw logs, then summary fits better. Open to correction if I'm missing something.
D imo. B looks tempting since incidents are summarized, but xdr_data is actually more about the foundational raw logs per exam reports.
Q: 19
When building an IOC hunting query, analysts should focus on:
Options
6 comments in the community discussion
2
Option A, had something like this in a mock. IOC hunts always target known bad domains or hashes.
1
Nah, not B-alert starring is a trap. It's A for IOC hunts.
Q: 20
Which two components influence the incident score in Cortex XDR? (Choose two)
Options
6 comments in the community discussion
C/B here. Official guide and labs both point out that alert severity and number of correlated alerts are what actually drive the score in XDR. D and C don't influence it afaik but double check practice tests if unsure.
A and B imo. Alert severity levels drive the score and more correlated alerts stack up risk too. C and D don't actually move the incident score in XDR, at least as far as docs explain. Anybody see different on a live environment?
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top