Courseiva

SecOps-Pro · domain

Cortex XDR

Practise Certified Security Operations Professional (SecOps-Pro) Cortex XDR practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

34 questions12 easy11 medium11 hard

Focused practice

Practice Cortex XDR questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cortex XDR

Cortex XDR questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Cortex XDR exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Cortex XDR questions (34)

Click any question to see the full explanation, or start a practice session above.

1

Which of the following describes the 'Agent Content' component?

Hard
2

What is the purpose of the 'XQL Query' feature in Cortex XDR?

Hard
3

Which TWO actions can be performed from the 'Endpoint Inventory' page?

Easy
4

Which component of Cortex XDR is responsible for collecting data from non-endpoint sources like network devices or firewalls?

Easy
5

Which THREE actions are available when responding to an incident via the Response feature?

Medium
6

You need to export a report of all alerts from the last 30 days for a compliance audit. Which section of the console should you use?

Medium
7

A legitimate administrative script is being flagged by a BIOC rule. To stop the alerts without disabling the rule, what is the best approach?

Hard
8

When analyzing a process execution in the Causality View, which THREE properties can be inspected?

Hard
9

You notice that your custom BIOC rule is not firing on a host where the malicious activity is confirmed. What is a common reason for this?

Hard
10

A security analyst needs to review logs from an endpoint that is reporting as 'Disconnected' in the Cortex XDR console. What is the first step to troubleshoot this communication issue?

Easy
11

Which THREE items can you use to build a BIOC rule in Cortex XDR?

Hard
12

In the Cortex XDR console, where can you see the current status of all your endpoints?

Easy
13

You want to automate the response to a specific type of alert. Where should you configure this?

Medium
14

You are investigating a ransomware incident. You want to see the parent process that spawned the malicious file. Which feature should you use?

Medium
15

Which THREE components are part of the Cortex XDR architecture?

Medium
16

When performing a 'Live Terminal' session on an endpoint, what must be true for the connection to succeed?

Medium
17

You are creating a custom BIOC rule to detect suspicious PowerShell execution. The rule must trigger when PowerShell is executed with an encoded command. Which field should you focus on in the rule builder?

Medium
18

Which configuration setting in the Malware profile determines if the agent should move a file to a secure location upon detection?

Hard
19

Which TWO of the following are valid ways to deploy the Cortex XDR agent?

Easy
20

Which TWO types of logs can be ingested by a Cortex XDR Collector?

Easy
21

What is the function of the 'Cortex XDR Broker Service'?

Medium
22

When configuring a Behavioral Threat Protection (BTP) profile, what is the impact of setting the protection mode to 'Block'?

Hard
23

During an investigation, you observe multiple alerts originating from a single endpoint. You want to group these alerts into a single incident to simplify the analysis. Which feature allows this?

Hard
24

You need to prevent the execution of a specific malicious script across the entire enterprise. What is the most efficient way to achieve this using Cortex XDR?

Medium
25

Which THREE pieces of information are displayed in the Incident View?

Hard
26

What is the primary function of the 'Cortex XDR Data Lake'?

Easy
27

Which TWO features in Cortex XDR help reduce alert fatigue for security analysts?

Medium
28

Which view in the Cortex XDR console provides the most comprehensive timeline of all activities related to a specific endpoint?

Easy
29

If an endpoint is marked as 'Out of Date', what does this mean?

Easy
30

What does the 'Cortex XDR Agent' do if it cannot communicate with the cloud for an extended period?

Easy
31

Where do you configure the settings to ensure that the Cortex XDR agent receives regular updates from the Cortex XDR console?

Easy
32

An analyst is reviewing the 'Causality View' of an alert. What does a dotted line between two processes signify?

Medium
33

Which TWO methods can be used to investigate an endpoint in Cortex XDR?

Easy
34

When investigating a file, you see a 'WildFire' verdict. What does this indicate?

Hard

Frequently asked questions

What does the Cortex XDR domain cover on the SecOps-Pro exam?
Cortex XDR questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 34 Cortex XDR questions in the SecOps-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cortex XDR questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Certified Security Operations Professional (SecOps-Pro) Cortex XDR Practice Questions