SecOps-Pro · domain
Cortex XDR
Practise Certified Security Operations Professional (SecOps-Pro) Cortex XDR practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cortex XDR questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cortex XDR
Cortex XDR questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Cortex XDR exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Cortex XDR questions (34)
Click any question to see the full explanation, or start a practice session above.
Which of the following describes the 'Agent Content' component?
Hard2What is the purpose of the 'XQL Query' feature in Cortex XDR?
Hard3Which TWO actions can be performed from the 'Endpoint Inventory' page?
Easy4Which component of Cortex XDR is responsible for collecting data from non-endpoint sources like network devices or firewalls?
Easy5Which THREE actions are available when responding to an incident via the Response feature?
Medium6You need to export a report of all alerts from the last 30 days for a compliance audit. Which section of the console should you use?
Medium7A legitimate administrative script is being flagged by a BIOC rule. To stop the alerts without disabling the rule, what is the best approach?
Hard8When analyzing a process execution in the Causality View, which THREE properties can be inspected?
Hard9You notice that your custom BIOC rule is not firing on a host where the malicious activity is confirmed. What is a common reason for this?
Hard10A security analyst needs to review logs from an endpoint that is reporting as 'Disconnected' in the Cortex XDR console. What is the first step to troubleshoot this communication issue?
Easy11Which THREE items can you use to build a BIOC rule in Cortex XDR?
Hard12In the Cortex XDR console, where can you see the current status of all your endpoints?
Easy13You want to automate the response to a specific type of alert. Where should you configure this?
Medium14You are investigating a ransomware incident. You want to see the parent process that spawned the malicious file. Which feature should you use?
Medium15Which THREE components are part of the Cortex XDR architecture?
Medium16When performing a 'Live Terminal' session on an endpoint, what must be true for the connection to succeed?
Medium17You are creating a custom BIOC rule to detect suspicious PowerShell execution. The rule must trigger when PowerShell is executed with an encoded command. Which field should you focus on in the rule builder?
Medium18Which configuration setting in the Malware profile determines if the agent should move a file to a secure location upon detection?
Hard19Which TWO of the following are valid ways to deploy the Cortex XDR agent?
Easy20Which TWO types of logs can be ingested by a Cortex XDR Collector?
Easy21What is the function of the 'Cortex XDR Broker Service'?
Medium22When configuring a Behavioral Threat Protection (BTP) profile, what is the impact of setting the protection mode to 'Block'?
Hard23During an investigation, you observe multiple alerts originating from a single endpoint. You want to group these alerts into a single incident to simplify the analysis. Which feature allows this?
Hard24You need to prevent the execution of a specific malicious script across the entire enterprise. What is the most efficient way to achieve this using Cortex XDR?
Medium25Which THREE pieces of information are displayed in the Incident View?
Hard26What is the primary function of the 'Cortex XDR Data Lake'?
Easy27Which TWO features in Cortex XDR help reduce alert fatigue for security analysts?
Medium28Which view in the Cortex XDR console provides the most comprehensive timeline of all activities related to a specific endpoint?
Easy29If an endpoint is marked as 'Out of Date', what does this mean?
Easy30What does the 'Cortex XDR Agent' do if it cannot communicate with the cloud for an extended period?
Easy31Where do you configure the settings to ensure that the Cortex XDR agent receives regular updates from the Cortex XDR console?
Easy32An analyst is reviewing the 'Causality View' of an alert. What does a dotted line between two processes signify?
Medium33Which TWO methods can be used to investigate an endpoint in Cortex XDR?
Easy34When investigating a file, you see a 'WildFire' verdict. What does this indicate?
HardOther domains
All SecOps-Pro exam domains
Frequently asked questions
- What does the Cortex XDR domain cover on the SecOps-Pro exam?
- Cortex XDR questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 34 Cortex XDR questions in the SecOps-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cortex XDR questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.