Courseiva
Endpoint SecuritymediumMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner Endpoint Security Practice Question

A security analyst notices that a benign internal software development tool is being incorrectly blocked by Cortex XDR Prevent as malware. What is the most granular method to whitelist this application while maintaining maximum security posture?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Profile Exception in the Malware Profile using the SHA-256 hash of the executable.

Hashing the specific file or using a signed certificate exception provides targeted remediation without compromising endpoint security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add the file path as an exclusion in the OS-level Windows Defender settings.

    Why it's wrong here

    Windows Defender settings do not affect Cortex XDR agent behavior.

  • Disable the local analysis module entirely for the affected endpoint group.

    Why it's wrong here

    Disabling a core prevention module weakens the security posture across the entire group.

  • Create a Profile Exception in the Malware Profile using the SHA-256 hash of the executable.

    Why this is correct

    Using the SHA-256 hash ensures only the exact approved file is exempted from blocking.

  • Change the agent profile operating mode from Prevention to Audit mode globally.

    Why it's wrong here

    Audit mode disables blocking for all threats, which is not granular.

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.