Practice Cybersecurity-Practitioner Endpoint Security questions with full explanations on every answer.
Start practicing
Endpoint Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An endpoint running the Cortex XDR Agent is experiencing aggressive behavior isolation triggered by a confirmed ransomware attack. The administrator successfully remediates the threat and verifies the endpoint is clean. How should the administrator restore network connectivity to the isolated endpoint from the Cortex XDR management console?
2An administrator needs to run a live forensic artifact collection on a suspected compromised endpoint using Cortex XDR. Which capability allows the administrator to execute scripts and retrieve files directly from the endpoint in real time?
3An administrator is deploying Cortex XDR Agent to Windows workstations using an Active Directory Group Policy Object (GPO). Which installation parameter must be used to ensure the agent registers correctly with the assigned Cortex XDR tenant using a specific installation token?
4A security analyst notices that a benign internal software development tool is being incorrectly blocked by Cortex XDR Prevent as malware. What is the most granular method to whitelist this application while maintaining maximum security posture?
5An organization is configuring exploit prevention rules in Cortex XDR to protect legacy browser plugins. An application crashes repeatedly due to an overly aggressive protection profile. Which action should the administrator take to troubleshoot without completely disabling exploit protection?
6An administrator is preparing to deploy Cortex XDR agents to 500 remote endpoints using a software deployment tool. Where can the administrator download the latest installation packages and transforms?
7An administrator needs to verify that the Cortex XDR agent services are running properly on a macOS endpoint. Which command-line utility should be used to check the agent status?
8An enterprise security team discovers that a custom line-of-business application is triggering a Behavioral Threat Protection (BTP) alert in Cortex XDR. The behavior involves unusual process injection techniques that are legitimate for this application. How can the administrator suppress this specific alert without disabling BTP for other applications?
9An organization requires that Cortex XDR agents verify their connection to the Cortex XDR server through a corporate HTTP proxy. Where is the proxy configuration defined for the Cortex XDR agent?
10An administrator observes that several Cortex XDR agents are showing a 'Disconnected' status in the management console. After verifying network connectivity, the administrator suspects that communication is blocked by an intermediate firewall. Which TCP port must be open outbound from the endpoints to the Cortex XDR server?
11An organization deploys Cortex XDR disk encryption management. An endpoint fails to escrow its BitLocker recovery key to the Cortex XDR console. What is the most effective troubleshooting step to verify escrow status using the agent command-line tool?
12An administrator needs to temporarily disable the Cortex XDR agent on an endpoint for troubleshooting purposes. What mechanism is used to authorize this action locally using the command line?
13An administrator wants to configure the frequency at which the Cortex XDR agent checks in with the management server. Where is this heartbeat interval configured?
14A security analyst is investigating a threat where a legitimate administrative tool (Living off the Land) was used maliciously. Cortex XDR generated an alert via Local Analysis. Which mechanism powers the Local Analysis engine to detect this type of threat without requiring an internet connection?
15An administrator needs to upgrade Cortex XDR agents across a large enterprise environment. To minimize network congestion and control the rollout, how should the administrator manage the upgrade process?
16An endpoint has been flagged in Cortex XDR with multiple high-severity alerts. The security operations team decides to isolate the endpoint immediately to prevent lateral movement. Which network traffic remains permitted by default when an endpoint is placed in isolation mode in Cortex XDR?
17An administrator is reviewing endpoint security profiles and notices the term 'BIOC'. What does BIOC stand for in the context of Cortex XDR?
18An organization requires compliance reporting showing that all endpoints are actively protected by Cortex XDR modules (Anti-Malware, Exploit Prevention, Behavioral Threat Protection). Where can an administrator generate this comprehensive compliance report in the Cortex XDR management console?
19A security analyst notices that WildFire has successfully analyzed a suspicious file uploaded from an endpoint, but the local Cortex XDR agent did not automatically block it upon first encounter. What is the most likely explanation for this behavior?
20An administrator is troubleshooting an issue where Cortex XDR agent logs need to be gathered and submitted to Palo Alto Networks Support. Which command generates a complete support file package (often referred to as 'collector') containing all necessary logs and debug data?
21A security analyst wants to configure a custom alert rule in Cortex XDR that triggers whenever a specific command-line pattern is observed across multiple endpoints. Which feature should the analyst use to create this behavioral alert?
22An administrator wants to ensure that end users cannot tamper with or uninstall the Cortex XDR agent from their workstations. Which feature provides this protection?
23An administrator is configuring disk encryption management in Cortex XDR for macOS endpoints. Which underlying native macOS technology does Cortex XDR manage and report on for disk encryption?
24Where in the Cortex XDR management console can an administrator view the operational health, connection status, and version of all deployed agents?
25Which THREE security modules are included as core components of the Cortex XDR agent architecture? (Choose three)
26Which TWO actions can be performed directly from the Cortex XDR management console on a compromised endpoint? (Choose two)
27Which TWO methods can be utilized to distribute Cortex XDR agent installation packages across an enterprise Windows environment? (Choose two)
28Which THREE parameters or settings can be configured within a Cortex XDR Agent Settings profile? (Choose three)
29Which TWO platforms are officially supported for deploying the Cortex XDR Agent? (Choose two)
30Which TWO pieces of information are displayed in the Cortex XDR Endpoint Management inventory table for a managed agent? (Choose two)
31Which THREE mechanisms are employed by Cortex XDR to protect endpoints against unknown zero-day file-based malware? (Choose three)
32Which THREE diagnostic or troubleshooting steps can be performed using the 'cytool' command-line utility on a local endpoint? (Choose three)
33Which TWO actions should an administrator take when a legitimate software application is falsely blocked by Cortex XDR Behavioral Threat Protection (BTP)? (Choose two)
34Which TWO tasks are required when preparing to deploy Cortex XDR agents using an installation token? (Choose two)
35Which THREE conditions or indicators typically trigger an automated endpoint isolation action in Cortex XDR? (Choose three)
36Which THREE types of data are gathered and ingested by Cortex XDR to provide comprehensive endpoint visibility? (Choose three)
The Endpoint Security domain covers the key concepts tested in this area of the Cybersecurity-Practitioner exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all Cybersecurity-Practitioner domains — no account required.
The Courseiva Cybersecurity-Practitioner question bank contains 36 questions in the Endpoint Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included