Palo Alto Networks XDR Engineer - XDR-Engineer Exam Practice Test

An organization experiences recurring malware alerts from the same endpoint despite repeated remediation efforts. What should investigators examine first?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
What is the earliest time frame an alert could be automatically generated once the conditions of a new correlation rule are met?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Windows endpoints by non-technical business units. Which rule type should be implemented?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)
[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
Correct Answer: C,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A Cortex XDR engineer discovers multiple alerts generated across several endpoints. The alerts appear unrelated individually but collectively indicate coordinated malicious activity. What explains this grouping?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A mobile device management (MDM) system is configured per documentation, and after Cortex XDR agent deployment, many users show their operational status as "Partially Protected." What is a potential cause for this behavior?
Correct Answer: D
How can a customer ingest additional events from a Windows DHCP server into Cortex XDR with minimal configuration?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0