Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Paloalto Networks Security Operations XSIAM-Analyst Questions and answers with ValidTests

Exam XSIAM-Analyst All Questions
Exam XSIAM-Analyst Premium Access

View all detail and faqs for the XSIAM-Analyst exam

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

How would Incident Context be referenced in an alert War Room task or alert playbook task?

Options:

A.

${parentIncidentContext}

B.

${getparentIncidentFields}

C.

${parentIncidentFields}

D.

${getParentIncidentContext}

Expert Solution
Questions # 12:

Which attributes can be used as featured fields?

Options:

A.

Device-ID, URL, port, and indicator

B.

Endpoint-ID, alert source, critical asset, and threat name

C.

CIDR range, file hash, tags, and log source

D.

Hostnames, user names, IP addresses, and Active Directory

Expert Solution
Questions # 13:

SCENARIO:

A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors state that the file format cannot be opened. IT has verified that the file server is online and functioning, but that all files have unusual extensions attached to them.

The security analyst reviews alerts within Cortex XSIAM and identifies malicious activity related to a possible ransomware attack on the file server. This incident is then escalated to the incident response team for further investigation.

Upon reviewing the incident, the responders confirm that ransomware was successfully executed on the file server. Other details of the attack are noted below:

• An unpatched vulnerability on an externally facing web server was exploited for initial access

• The attackers successfully used Mimikatz to dump sensitive credentials that were used for privilege escalation

• PowerShell was used on a Windows server for additional discovery, as well as lateral movement to other systems

• The attackers executed SystemBC RAT on multiple systems to maintain remote access

• Ransomware payload was downloaded on the file server via an external site "file io"

QUESTION STATEMENT:

Which forensics artifact collected by Cortex XSIAM will help the responders identify what the attackers were looking for during the discovery phase of the attack?

Options:

A.

PSReadline

B.

WordWheelQuery

C.

User access logging

D.

Shell history

Expert Solution
Questions # 14:

An on-demand malware scan of a Windows workstation using the Cortex XDR agent is successful and detects three malicious files. An analyst attempts further investigation of the files by right-clicking on the scan result, selecting "Additional data," then "View related alerts," but no alerts are reported.

What is the reason for this outcome?

Options:

A.

The malicious files were true positives and were automatically quarantined from the scan results

B.

The malware scan action detects malicious files but does not generate alerts for them

C.

The malicious files are currently in an excluded directory in the Malware Profile

D.

The malicious files were false positives and were automatically removed from the scan results

Expert Solution
Questions # 15:

What is the expected behavior when querying a data model with no specific fields specified in the query?

Options:

A.

The query will error out and not run.

B.

The default dataset=xdr_data fields will be returned.

C.

No fields will be returned by default.

D.

The xdm_core fieldset will be returned by default.

Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions