Cybersecurity-Apprentice Endpoint Security Practice Question
An endpoint generates an alert for a suspicious script execution, but the analyst determines it is a false positive generated by a legitimate administrative tool. What is the best practice for handling this false positive in Cortex XDR?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a profile exception using the specific file hash or behavioral signature parameters identified in the alert.
Analysts should create granular exceptions based on file hashes or behavioral signatures rather than disabling security modules globally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Uninstall the Cortex XDR agent from all endpoints in that department.
Why it's wrong here
Uninstalling the agent leaves endpoints completely unprotected.
- ✗
Delete the alert from the incident queue without taking action.
Why it's wrong here
Deleting the alert without an exception means it will trigger again on the next execution.
- ✗
Set the entire Cortex XDR agent fleet to Audit mode permanently.
Why it's wrong here
Putting the fleet in audit mode disables prevention entirely.
- ✓
Create a profile exception using the specific file hash or behavioral signature parameters identified in the alert.
Why this is correct
Creating targeted exceptions resolves the false positive while keeping protections active for other threats.
About these practice questions
Courseiva writes every Cybersecurity-Apprentice question from scratch — 177 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cybersecurity-Apprentice practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Apprentice exam.