Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Palo Alto Networks Certified XDR Engineer XDR-Engineer Exam Questions

Page: 1 / 9 Total 50 questions

Want more questions? Get Premium Access.

Question 1

[Cortex XDR Agent Configuration]

How are dynamic endpoint groups created and managed in Cortex XDR?

Correct Answer: D. Endpoint groups are defined based on fields such as OS type, OS version, and network segment

Question 2

[Detection Engineering]

A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)

[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]

Correct Answer: A. Apply an alert exception; B. Apply an alert exclusion to the XDR behavioral indicator of compromise (BIOC) alert

Question 3

[Detection Engineering]

During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Windows endpoints by non-technical business units. Which rule type should be implemented?

Correct Answer: B. Behavioral Indicator of Compromise (BIOC)

Question 4

[Post-Deployment Management and Configuration]

Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?

Correct Answer: C. Add entries in Exceptions Configuration section of Isolation Exceptions

Question 5

[Detection Engineering]

Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?

Correct Answer: D. dataset = xdr_data| filter event_type = ENUM.PROCESS and action_process_image_name = '**'and action_process_image_command_line = '-e cmd*'and action_process_image_command_line != '*cmd.exe -a /c*'

Question 6

[Detection Engineering]

A correlation rule is created to detect potential insider threats by correlating user login events from one dataset with file access events from another dataset. The rule must retain all user login events, even if there are no matching file access events, to ensure no login activity is missed.

text

Copy

dataset = x

| join (dataset = y)

Which type of join is required to maintain all records from dataset x, even if there are no matching events from dataset y?

Correct Answer: B. Left