Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

XDR-Engineer Paloalto Networks Palo Alto Networks XDR Engineer Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Paloalto Networks XDR-Engineer Palo Alto Networks XDR Engineer certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 50 questions

An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by automatically isolating the affected endpoint and notifying the security team via email. The playbook should only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)

A.

Alert severity is High

B.

Alert source is Cortex XDR Analytics

C.

Alert category is Malware

D.

Alert status is New

After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a partially protected status. In which two places can insights into what is contributing to this status be located? (Choose two.)

A.

Management Audit Logs

B.

XQL query of the endpoints dataset

C.

All Endpoints page

D.

Asset Inventory

Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?

A.

It will immediately execute

B.

It will not execute

C.

It will execute after one hour

D.

It will execute after the second attempt

An analyst considers an alert with the category of lateral movement to be allowed and not needing to be checked in the future. Based on the image below, which action can an engineer take to address the requirement?

A.

Create a behavioral indicator of compromise (BIOC) suppression rule for the parent process and the specific BIOC: Lateral movement

B.

Create an alert exclusion rule by using the alert source and alert name

C.

Create a disable injection and prevention rule for the parent process indicated in the alert

D.

Create an exception rule for the parent process and the exact command indicated in the alert

During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Windows endpoints by non-technical business units. Which rule type should be implemented?

A.

Analytics Behavioral Indicator of Compromise (ABIOC)

B.

Behavioral Indicator of Compromise (BIOC)

C.

Correlation

D.

Indicator of Compromise (IOC)

A query is created that will run weekly via API. After it is tested and ready, it is reviewed in the Query Center. Which available column should be checked to determine how many compute units will be used when the query is run?

A.

Query Status

B.

Compute Unit Usage

C.

Simulated Compute Units

D.

Compute Unit Quota

What happens when the XDR Collector is uninstalled from an endpoint by using the Cortex XDR console?

A.

The files are removed immediately, and the machine is deleted from the system without any retention period

B.

The machine status remains active until manually removed, and the configuration data is retained for up to seven days

C.

It is uninstalled during the next heartbeat communication, machine status changes to Uninstalled, and the configuration data is retained for 90 days

D.

The associated configuration data is removed from the Action Center immediately after uninstallation

When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is used to turn off a component on a Windows machine?

A.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" stop

B.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop

C.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" -s stop

D.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" occp

When using Kerberos as the authentication method for Pathfinder, which two settings must be validated on the DNS server? (Choose two.)

A.

DNS forwarders

B.

Reverse DNS zone

C.

Reverse DNS records

D.

AD DS-integrated zones

A cloud administrator reports high network bandwidth costs attributed to Cortex XDR operations and asks for bandwidth usage to be optimized without compromising agent functionality. Which two techniques should the engineer implement? (Choose two.)

A.

Configure P2P download sources for agent upgrades and content updates

B.

Enable minor content version updates

C.

Enable agent content management bandwidth control

D.

Deploy a Broker VM and activate the local agent settings applet

What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?

A.

Sending endpoint logs to the NGFW for analysis

B.

Blocking network traffic based on Cortex XDR detections

C.

Enabling additional analysis through enhanced application logging

D.

Automated downloading of malware signatures from the NGFW

Which two steps should be considered when configuring the Cortex XDR agent for a sensitive and highly regulated environment? (Choose two.)

A.

Enable critical environment versions

B.

Create an agent settings profile where the agent upgrade scope is maintenance releases only

C.

Create an agent settings profile, enable content auto-update, and include a delay of four days

D.

Enable minor content version updates

What will enable a custom prevention rule to block specific behavior?

A.

A correlation rule added to an Agent Blocking profile

B.

A custom behavioral indicator of compromise (BIOC) added to an Exploit profile

C.

A custom behavioral indicator of compromise (BIOC) added to a Restriction profile

D.

A correlation rule added to a Malware profile

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

A.

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Page: 1 / 1
Total 50 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved