Courseiva
Endpoint SecurityhardMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner Endpoint Security Practice Question

An organization is configuring exploit prevention rules in Cortex XDR to protect legacy browser plugins. An application crashes repeatedly due to an overly aggressive protection profile. Which action should the administrator take to troubleshoot without completely disabling exploit protection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Change the exploit protection behavior for the specific technique to 'Report' instead of 'Terminate'.

Putting the exploit protection module into Report (Audit) mode allows verification of potential blocks without disrupting user productivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add the browser executable path to the OS exclusions list in Cortex XDR.

    Why it's wrong here

    Exploit protection operates on technique-based memory monitoring rather than simple path exclusions.

  • Change the exploit protection behavior for the specific technique to 'Report' instead of 'Terminate'.

    Why this is correct

    Switching the action to Report logs the violation without terminating the application, enabling effective troubleshooting.

  • Disable memory protection features globally in the agent settings profile.

    Why it's wrong here

    Disabling memory protection globally compromises overall endpoint security.

  • Enable Agent Self-Protection to prevent local interference.

    Why it's wrong here

    Self-protection defends the agent itself from tampering, unrelated to application crashing.

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.