Courseiva

Certified XDR Engineer (XDR-Engineer) (XDR-Engineer) — Questions 151225

226 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQmedium

An enterprise plans to deploy Cortex XDR agents to servers that run resource-intensive, mission-critical database applications. During the installation planning phase, which configuration step should the administrator take to minimize potential performance impact?

A.Configure custom Agent Settings profiles with appropriate exclusions for database files and directories.
B.Disable all behavioral threat protection features on database servers.
C.Set the agent operating mode to disabled via the command line.
D.Install only the Traps module without the Cortex XDR agent core.
AnswerA

Excluding database transaction logs and data folders from real-time scans optimizes performance without sacrificing security.

Why this answer

Creating custom Agent Profiles with tailored scanning exclusions and profile settings ensures critical database directories and processes are not overly impacted by standard scanning behaviors.

152
MCQeasy

When planning the deployment of Cortex XDR preventive capabilities, which mode should an administrator initially use to evaluate security posture without risking business disruption?

A.Aggressive Prevention Mode
B.Telemetry and Monitoring (Detection-only) Mode
C.Disabled Mode
D.Quarantine Mode
AnswerB

Monitoring mode collects data and generates alerts without blocking execution, making it ideal for the initial deployment phase.

Why this answer

Deploying agents in a non-blocking or telemetry-only mode allows administrators to assess alerts and rule performance safely before enforcing blocks.

153
MCQmedium

An administrator is building a playbook in Cortex XDR incident response automation. The playbook needs to isolate an endpoint only if a specific malicious process hash is confirmed by a secondary sandbox analysis task. Which element should be used in the playbook workflow to enforce this conditional logic?

A.A Data Collection task pointing to the endpoint agent
B.A Post-Processing script executed directly on the Broker VM
C.A Condition (or Decision) block that evaluates the sandbox verdict output
D.A Manual Approval step without automated logic branching
AnswerC

A Condition block allows the workflow to branch based on the results or outputs of previous tasks like a sandbox verdict.

Why this answer

Conditional routing in playbooks is handled using Decision or Condition tasks to evaluate previous task outputs.

154
Multi-Selecthard

When configuring advanced data forwarding filters in Cortex XDR, which TWO criteria parameters can an administrator use to precisely target specific log types or endpoints? (Choose two)

Select 2 answers
A.The physical room number where the server rack is installed
B.Log dataset type (e.g., xdr_data, endpoints, network)
C.The name of the physical building security guard on duty
D.The local cafeteria menu schedule
E.Alert severity levels (Low, Medium, High, Critical)
AnswersB, E

Rules can target specific log datasets such as agent events or cloud logs.

Why this answer

Data forwarding rules allow filtering by log type (e.g., agent datasets, audit logs) and endpoint attributes or criteria.

155
MCQhard

An administrator is investigating an incident and notices that data from a specific cloud data source integrated via Cortex XDR Cloud Data Collector is delayed by several hours. Where should the administrator check first to diagnose the ingestion delay?

A.Settings > Configurations > Data Collection status monitor.
B.Dashboards > Executive Summary.
C.Incident Response > Queue Manager.
D.Endpoint Management > Collector Health.
AnswerA

The Data Collection settings page displays collector status, API connection errors, and ingestion queues.

Why this answer

The Cloud Data Collector status page under Settings > Configurations > Data Collection provides health status, error codes, and ingestion latency metrics.

156
MCQhard

During a large-scale Cortex XDR agent deployment using a Software Distribution Tool, administrators notice that multiple endpoints show identical agent IDs (UUIDs) in the Cortex XDR management console, causing telemetry to overwrite. What caused this issue?

A.The endpoints were cloned from a golden image that contained a pre-installed Cortex XDR agent without proper unregistration.
B.The installation script failed to generate a unique token parameter.
C.Active Directory GPO distributed the package with a hardcoded configuration XML.
D.The Cortex XDR Broker VM assigned the same IP address to all reporting clients.
AnswerA

Cloning a machine with an active agent copies the generated Agent ID, resulting in duplicate UUIDs in the console.

Why this answer

If a golden image or virtual machine template is captured with a pre-installed Cortex XDR agent, the resulting cloned endpoints will share the same persistent registry keys/UUID, requiring the use of the cytool unregister command or specialized imaging preparation.

157
MCQmedium

An endpoint user reports that a legitimate internal application is being blocked by Cortex XDR Exploit Protection. The administrator wants to create an exception without completely disabling the module. Which mechanism should the administrator use in the Cortex XDR console?

A.Add a profile exception under Settings > Configurations > Agent Configurations specifying the exploit module and application path.
B.Disable behavioral threat protection globally.
C.Create a correlation rule to suppress alerts from that path.
D.Modify the Broker VM ingestion filter.
AnswerA

Agent configuration profiles allow adding granular exceptions for specific exploit protection checks and file paths.

Why this answer

BIOC (Behavioral Indicator of Compromise) and Exploit Protection exceptions can be managed via Exception profiles or profile exclusions in Cortex XDR.

158
MCQmedium

An administrator has configured a new AWS CloudTrail integration via Broker VM to ingest cloud logs into Cortex XDR. However, no logs are appearing in the XDR database. Upon reviewing the Broker VM logs, the administrator notices an 'AccessDenied' error from AWS. What is the most likely root cause?

A.The IAM role or user credentials provided to the Broker VM lack permissions to read from the S3 bucket
B.The Cortex XDR agent license has expired for cloud log ingestion
C.The AWS region ID is misspelled in the local hosts configuration file
D.The Broker VM has insufficient RAM allocated to run the S3 polling daemon
AnswerA

AccessDenied errors in cloud integrations are caused by missing permissions in the IAM policy attached to the integration credentials.

Why this answer

AWS CloudTrail ingestion requires an IAM role with sufficient permissions to access the designated S3 bucket containing the logs.

159
MCQmedium

An administrator is configuring a Broker VM instance in the Cortex XDR console. After deploying the OVA template in the hypervisor, what is the mandatory next step required to link the Broker VM to the Cortex XDR cloud tenant?

A.Upload a valid SSL wildcard certificate signed by a public Certificate Authority directly to the hypervisor
B.Run the setup wizard using the default admin credentials and map an NFS datastore
C.Configure a static IP address via the CLI and enter the Broker VM registration key generated in the Cortex XDR console
D.Configure a Syslog forwarding rule in Panorama to push the registration payload
AnswerC

The Broker VM requires network configuration and registration via a unique key generated in the Cortex XDR console to establish trust and connectivity.

Why this answer

To link a newly deployed Broker VM to the cloud tenant, the administrator must register it using a registration key generated in the Cortex XDR console.

160
MCQeasy

When testing a newly configured API integration instance in Cortex XSOAR, what is the standard action used to verify connectivity and authentication credentials?

A.Reboot the Cortex XDR management server tenant
B.Restart the Broker VM container service
C.Execute a full endpoint isolation workflow
D.Run the 'test-module' command
AnswerD

The 'test-module' command verifies that API keys, URLs, and credentials are valid and working.

Why this answer

The 'test-module' command is the standard mechanism in Cortex XSOAR to test API connectivity and credentials.

161
Multi-Selectmedium

An administrator needs to troubleshoot an AWS S3 bucket integration via Broker VM where logs are failing to ingest. Which TWO diagnostic steps should be taken? (Choose two)

Select 2 answers
A.Change the local monitor resolution on the administrator workstation
B.Disconnect all enterprise physical firewalls
C.Verify that the AWS IAM policy has s3:GetObject and s3:ListBucket permissions
D.Reinstall the Windows operating system on the AWS S3 server
E.Inspect the Broker VM container logs for S3 polling errors
AnswersC, E

Missing IAM permissions are the primary cause of AWS S3 ingestion failures.

Why this answer

Troubleshooting cloud integrations involves verifying IAM permissions and checking Broker VM container logs.

162
Multi-Selecthard

An administrator is managing custom IOC (Indicator of Compromise) feeds in Cortex XDR. Which THREE file formats or ingestion methods are supported when importing custom IOC indicators? (Choose three)

Select 3 answers
A.Compiled C++ source code (.cpp)
B.CSV file upload
C.TAXII threat feed integration
D.Cortex XDR REST API ingestion
E.Windows Registry Hive backup (.hiv)
AnswersB, C, D

Administrators can upload custom IOC lists formatted as CSV files.

Why this answer

Cortex XDR supports importing custom IOCs via flat file uploads (CSV), STIX/TAXII threat feeds, and direct API ingestion.

163
MCQeasy

An administrator needs to schedule a weekly PDF report of all critical endpoint incidents to email to the security operations team. Which Cortex XDR feature should be used to accomplish this?

A.Incident Export via Syslog
B.Data Export Service
C.BIOC Alert Notifications
D.Scheduled Reports in the Reporting menu
AnswerD

Scheduled Reports let you generate PDF or CSV reports and deliver them via email automatically.

Why this answer

Cortex XDR allows administrators to schedule reports through the Reporting section by defining parameters and delivery frequency.

164
MCQmedium

An administrator has deployed a Broker VM and enabled the Active Directory (AD) collector to ingest user and group mapping data. The connection test fails with a 'Kerberos Authentication Failed' error. What is the most likely cause of this failure?

A.The Broker VM firewall is blocking ICMP ping requests
B.The Cortex XDR agent on the domain controller has been uninstalled
C.The Broker VM has exceeded its maximum disk storage allocation
D.The Broker VM system clock is out of sync with the Domain Controller by more than five minutes
AnswerD

Kerberos authentication strictly relies on time synchronization between the client (Broker VM) and the KDC (Domain Controller).

Why this answer

Active Directory collectors communicating via Kerberos require accurate time synchronization and correct domain/SPN configurations.

165
MCQhard

When configuring a custom Malware Protection profile, an administrator wants to enable prevention for greyware (Potentially Unwanted Applications - PUA). What action does the Cortex XDR agent take when a PUA is detected and the profile action is set to 'Block'?

A.Sends an alert to the console but allows the application to continue running.
B.Quarantines the file and terminates the running process.
C.Isolates the entire endpoint from the corporate network.
D.Deletes the file permanently from the disk without creating a quarantine backup.
AnswerB

Blocking greyware results in process termination and file quarantine.

Why this answer

When PUA prevention is set to block, the agent terminates the execution of the application and prevents it from running.

166
MCQhard

An enterprise security team wants to ingest NetFlow records from core routers into Cortex XDR. Which component and collector combination supports NetFlow/IPFIX ingestion?

A.Direct API streaming from router CLI to the XDR cloud storage bucket
B.Broker VM with the NetFlow / IPFIX Collector enabled
C.Cortex XDR Agent installed directly on the core routers via SSH
D.Cortex XSOAR integration instance using SNMP polling
AnswerB

The Broker VM includes a NetFlow/IPFIX collector module to ingest flow records from network devices.

Why this answer

NetFlow and IPFIX logs are ingested using the NetFlow Collector app on the Broker VM.

167
MCQmedium

An analyst wants to create a customized dashboard widget in Cortex XDR that displays the top 10 endpoints generating the highest volume of alerts over the last 7 days. Where should the analyst configure this widget?

A.Agent Settings -> Profiles -> Analytics
B.Threat Intelligence -> Feed Management
C.Incident Response -> Playbooks
D.Dashboards menu using a widget based on an XQL query
AnswerD

Dashboards allow the creation of custom widgets powered by XQL to visualize specific organizational metrics.

Why this answer

Custom dashboards and widgets in Cortex XDR are built and managed within the Dashboard module using either pre-built templates or custom XQL queries.

168
Multi-Selectmedium

An administrator notices that Cortex XDR content updates are failing to apply to endpoints in a secured network segment. Which TWO potential causes should the administrator investigate? (Choose two)

Select 2 answers
A.Broker VM database corruption.
B.Firewall rules blocking outbound HTTPS traffic to Content CDN distribution domains.
C.Lack of available disk space in the /boot partition of the endpoint.
D.Proxy authentication failures preventing the agent from downloading content packages.
E.Failure of the local endpoint DNS server to resolve Active Directory domain controllers.
AnswersB, D

Agents download content updates from cloud CDNs over HTTPS, which must be permitted by firewalls.

Why this answer

Content update failures on isolated endpoints usually stem from firewall blocking content distribution URLs or proxy issues.

169
MCQhard

An administrator wants to configure local log retention settings and verify the ingestion rate of raw endpoint telemetry within Cortex XDR. Where can the administrator monitor platform license consumption and data ingestion metrics?

A.Settings -> Configurations -> License Management / Hub
B.Host Insights -> Disk Utilization report
C.Incident Response -> Queue Statistics
D.Analytics -> BIOC Rule Health monitor
AnswerA

License Management displays ingestion rates, storage utilization, and licensed endpoints.

Why this answer

License utilization, data ingestion volumes, and storage statistics in Cortex XDR are managed and viewed via the License Management / Settings menus.

170
MCQhard

An administrator is deploying the Cortex XDR agent on a virtual desktop infrastructure (VDI) non-persistent pool. Which configuration consideration is critical to ensure proper management and prevent duplicate endpoint entries in the Cortex XDR console?

A.Disable all behavioral threat prevention modules on gold master images
B.Configure the hypervisor to inject a new license key on every reboot
C.Enable the VDI optimization setting in the agent installation parameters or profile so the agent cleans up stale records upon shutdown
D.Install a unique static IP address allocation script for every virtual machine instance spawned
AnswerC

VDI optimization ensures non-persistent endpoints unregister correctly and avoid creating ghost records in the console.

Why this answer

Non-persistent VDI clones frequently power down and reset, requiring proper master image preparation with VDI flags enabled to prevent cluttering the console with stale offline endpoints.

171
MCQeasy

What is the primary function of an Agent Settings profile in Cortex XDR?

A.To establish network firewall rules for endpoint isolation.
B.To configure administrative options such as anti-tampering passwords and operational parameters.
C.To specify which file hashes are malicious and should be blocked.
D.To define exploit prevention techniques for browser-based attacks.
AnswerB

Agent Settings govern operational parameters like passwords, UI visibility, and update behaviors.

Why this answer

Agent Settings profiles control operational aspects of the agent, such as password protection, uninstallation permissions, and update schedules.

172
MCQhard

An administrator deployed a new Cortex XDR agent profile, but a specific subset of endpoints in the finance department is failing to receive the policy updates. What is the most likely troubleshooting step on the endpoint?

A.Verify the status and logs of the Cyvera.Service.exe service on the endpoint.
B.Reboot the Panorama management server to push the updated profile.
C.Run the migration tool to upgrade the agent installer package.
D.Restart the Palo Alto Networks Cortex Data Lake collector service.
AnswerA

The Cyvera.Service process is responsible for agent communication and policy enforcement on Windows.

Why this answer

Checking the Cyvera.Service.exe logs (or collector log files) on the endpoint helps determine if communication with the Cortex XDR server is failing or if registration is corrupted.

173
MCQhard

An administrator is deploying the Cortex XDR agent in a Linux environment and encounters dependency issues during the RPM installation. Specifically, the system reports missing kernel headers. What is the impact on Cortex XDR functionality if kernel headers or required kernel development packages are missing?

A.The endpoint will experience an immediate kernel panic and enter a reboot loop
B.The agent will automatically download the correct kernel source code from the public Linux kernel archives
C.The agent installation will fail or certain kernel-dependent prevention and monitoring modules will not load properly
D.The agent will operate normally without any functional limitations because Linux does not use kernel modules for security
AnswerC

Linux kernel-level monitoring requires compiling or loading kernel modules, which fail if required headers/dependencies are absent.

Why this answer

Certain Linux preventive and behavioral monitoring features rely on kernel modules that require matching kernel headers/devel packages to compile successfully during installation.

174
MCQmedium

An administrator is configuring data forwarding filters in Cortex XDR to send specific severity alerts to a SIEM. The requirement is to forward all 'High' and 'Critical' severity alerts while excluding 'Low' and 'Medium' alerts. Where is this filter configured?

A.In the Cortex XDR Agent installation package configuration properties
B.Inside the Cortex XSOAR incident layout editor
C.Under Settings > Configurations > Data Forwarding rules
D.On the Broker VM local routing table configuration
AnswerC

Data forwarding rules in Cortex XDR allow filtering logs and alerts by severity, type, and source.

Why this answer

Data forwarding rules with specific filters are configured under Settings > Configurations > Data Forwarding.

175
MCQeasy

Where should an administrator navigate in the Cortex XDR management console to create and manage security profiles such as Malware Protection and Exploit Protection?

A.Settings > Endpoint Configuration
B.Dashboards > Profiles
C.Endpoints > Policy Rules
D.Response > Profiles
AnswerC

Policy Rules is where malware, exploit, and behavioral protection profiles are created and assigned.

Why this answer

Security profiles in Cortex XDR are managed under the Endpoints > Policy Rules section.

176
Multi-Selecteasy

An administrator is reviewing the Cortex XDR console to plan endpoint groupings. Which TWO criteria can be used to organize endpoints into groups for policy assignment? (Choose two)

Select 2 answers
A.Installed printer driver versions
B.Local user desktop wallpaper resolution settings
C.Operating system type (Windows, macOS, Linux)
D.Physical serial number of the endpoint monitor
E.IP address subnets or network ranges
AnswersC, E

Endpoints can be grouped by their operating system to apply relevant security profiles.

Why this answer

Endpoints can be grouped based on operating system, naming conventions, IP subnets, or domain membership.

177
MCQeasy

Where in the Cortex XDR web interface can an administrator generate API keys (API Key and Incident ID / Key) required for external integrations and scripts to authenticate with the Cortex XDR API?

A.Marketplace > Settings > Credentials
B.Settings > Configurations > Integrations > API Keys
C.Endpoints > Policy > Authentication
D.Incidents > Actions > Generate Key
AnswerB

API Keys can be generated and managed under Settings > Configurations > Integrations > API Keys.

Why this answer

API keys are generated under Settings > Configurations > Integrations > API Keys.

178
Multi-Selecthard

An administrator is troubleshooting a scenario where Cortex XDR incident severities appear misaligned with organizational priority. Which THREE components or features can the administrator adjust to tune incident scoring and severity? (Choose three)

Select 3 answers
A.Reinstall the Cortex XDR Agent on all high-priority servers.
B.Modify the Broker VM packet buffer size.
C.Create exceptions for known benign alerts to prevent them from inflating incident priority scores.
D.Modify individual BIOC or Analytics alert severities to reflect their true operational impact.
E.Configure Incident Scoring rules to adjust how individual alert weights contribute to overall incident severity.
AnswersC, D, E

Suppressing false positives through exceptions prevents score inflation from noisy alerts.

Why this answer

Incident severity and scoring can be tuned via scoring rules, alert severity mappings, and exception configurations.

179
Multi-Selecthard

When troubleshooting a failing Cortex XDR API query or automation script, which TWO logs or diagnostic tools should an administrator examine to diagnose the root cause? (Choose two)

Select 2 answers
A.Windows Event Viewer Security log on unmanaged workstations
B.Local BIOS firmware event logs
C.Cortex XDR Agent installation MSI error logs
D.Cortex XSOAR Server Audit and Server logs (/var/log/demisto/server.log)
E.Integration debug logs (Docker container logs for the specific integration instance)
AnswersD, E

Server logs capture application-level errors, script execution failures, and system warnings.

Why this answer

Troubleshooting API and automation issues involves reviewing the Cortex XSOAR integration debug logs and the Audit Trail / Server logs.

180
MCQeasy

Where in the Cortex XDR management console can an administrator review the connection status, agent version, and operating system of all registered endpoints?

A.Dashboards > Health > Agents
B.Endpoints > Endpoint Management
C.Response > Endpoint Status
D.Settings > Agent Management > Status
AnswerB

Endpoint Management is the central inventory view for all registered agents.

Why this answer

The Endpoint Management view provides a comprehensive inventory table of all deployed agents, their status, versions, and details.

181
MCQhard

An automation engineer is building a Cortex XSOAR playbook that is triggered by a Cortex XDR incident. The playbook needs to fetch all associated endpoint artifacts using the Cortex XDR integration. Which parameter is required in the command execution to ensure all relevant forensics files are retrieved?

A.Specify the cloud storage bucket ARN where the endpoint stores its local cache.
B.Enter the firewall security policy rule ID that triggered the alert.
C.Supply the global tenant ID and the Active Directory Distinguished Name of the host.
D.Provide the unique Agent ID and the absolute file path of the artifact.
AnswerD

Correct. Cortex XDR API and XSOAR integration commands require the specific Agent ID and file path to target file retrieval.

Why this answer

When fetching endpoint files or running get-file commands in XSOAR using the Cortex XDR integration, providing the specific agent ID and file path or artifact identifier is required to target the correct machine.

182
MCQeasy

Where within the Cortex XDR console should an administrator configure scheduled reporting to automatically email executive summaries to stakeholders on a weekly basis?

A.Incident Response > Incident Management
B.XQL Search > Scheduled Queries
C.Reporting > Report Builder
D.Settings > Configurations > Email Notifications
AnswerC

Correct. The Report Builder allows administrators to configure, schedule, and email custom and built-in reports.

Why this answer

Scheduled reporting and report generation templates are managed within the Dashboards and Reports section of Cortex XDR.

183
Multi-Selecteasy

Which TWO actions can an administrator perform from the Endpoint Management view in the Cortex XDR management console? (Choose two)

Select 2 answers
A.Configure firewall security policies for perimeter gateways.
B.Isolate an endpoint from the network during an incident.
C.Create and deploy Palo Alto Networks firewall traffic filters.
D.Initiate a manual malware scan on selected endpoints.
E.Manage DNS server IP address assignments.
AnswersB, D

Endpoint isolation is a core action available within Endpoint Management.

Why this answer

Endpoint Management allows administrators to view endpoint details and execute management actions such as isolating endpoints or initiating scans.

184
MCQeasy

Which type of profile in Cortex XDR controls the collection of endpoint telemetry used for threat hunting and forensic analysis?

A.Agent Settings profile
B.Malware Protection profile
C.Network Control profile
D.Data Collection profile
AnswerD

Data Collection profiles govern the scope of telemetry gathered for hunting and investigation.

Why this answer

Data Collection profiles determine what security telemetry and artifacts are gathered from endpoints and sent to the Cortex XDR backend.

185
Multi-Selecthard

An administrator is configuring XQL scheduled alerts in Cortex XDR. Which THREE parameters must be defined when setting up a scheduled XQL rule to generate alerts? (Choose three)

Select 3 answers
A.The physical memory allocation limit on the Broker VM handling syslog collection.
B.The kernel bypass configuration parameters for Windows endpoints.
C.The underlying XQL query string that defines the detection logic.
D.The mapping for generated alert attributes such as severity, name, and description.
E.The schedule frequency (how often the query runs) and the time range of the data evaluated.
AnswersC, D, E

Correct. The query string defines what events or data to search for.

Why this answer

When configuring scheduled XQL rules, administrators must specify the query string, execution frequency/time window, and alert severity mapping.

186
MCQmedium

An analyst is investigating an alert generated by Analytics where a user account executed an unusual command. The analyst wants to view all other actions performed by that same user across any endpoint during a 24-hour window. Which query technique in XQL best fulfills this requirement?

A.dataset = endpoints_inventory | filter owner == 'TargetUser'
B.dataset = xdr_data | filter username == 'TargetUser' and _time >= now() - 24h
C.dataset = panw_analytics_alerts | filter alert_id == 'TargetUser'
D.dataset = network_story | filter user_context == null
AnswerB

This query isolates all telemetry associated with the specific username over the past 24 hours.

Why this answer

Filtering the `xdr_data` dataset by the specific username and a time range (`emp_time` or timestamp filters) allows full behavioral reconstruction of user activity.

187
MCQeasy

An analyst is investigating an open incident in Cortex XDR and determines that the activity is benign and authorized. What is the appropriate action to close the incident and document the resolution?

A.Delete the agent from Endpoint Management.
B.Change the incident status to Resolved and select the appropriate resolution reason (e.g., False Positive).
C.Put the agent into Bypass mode.
D.Purge all logs using the XQL delete command.
AnswerB

Resolving incidents with a status and reason properly closes them in the triage queue.

Why this answer

Incidents in Cortex XDR are resolved by changing their status to 'Resolved' and assigning an appropriate resolution status such as False Positive or Benign True Positive.

188
MCQhard

An organization requires that Cortex XDR agent installation packages be deployed silently without displaying any user interface or rebooting the workstation. Which command-line arguments should be used with a Windows MSI installer package?

A.setup.exe /silent /noreboot
B.install.bat --silent --no-restart
C.cytool install --quiet --suppress-reboot
D.msiexec /i <installer>.msi /qn REBOOT=ReallySuppress
AnswerD

Standard MSI silent installation parameters include /qn and REBOOT=ReallySuppress.

Why this answer

Silent installations of MSI packages are standard using the '/qn' or '/quiet' flags, often combined with REBOOT=ReallySuppress to prevent forced reboots.

189
MCQhard

An administrator configured a new Agent Settings profile in Cortex XDR, but endpoints in the 'Finance' folder are not applying the new tamper protection password. What is the most likely reason for this behavior?

A.Tamper protection passwords can only be configured globally and cannot be overridden by profile.
B.The Agent Settings profile priority for the Finance folder is set lower than a conflicting child assignment or inheritance is broken.
C.Tamper protection configuration changes require a manual service restart on every agent.
D.Agents require a full endpoint reboot before downloading any configuration changes.
AnswerB

Folder precedence and profile assignments determine which configuration wins when multiple profiles could apply.

Why this answer

Cortex XDR evaluates folders and profiles based on priority and inheritance. If a sub-folder or specific endpoint group has an explicit profile assigned with higher precedence, or if profile inheritance is broken, the settings will not propagate down as expected.

190
MCQmedium

An administrator has deployed a Broker VM to act as a syslog collector and agent installer. During the configuration of the Broker VM in the Cortex XDR console, the status remains 'Disconnected'. What is the most likely cause of this issue?

A.The Cortex XDR agent license count has been exceeded on the tenant.
B.Outbound connectivity on TCP port 443 from the Broker VM to the Cortex XDR tenant is blocked.
C.The Broker VM requires an active inbound SSH session from the administrator's workstation.
D.Syslog UDP port 514 is closed on the internal firewall.
AnswerB

Correct. The Broker VM initiates an outbound connection to the Cortex XDR backend over port 443.

Why this answer

The Broker VM requires outbound HTTPS access (port 443) to the Cortex XDR tenant URL for registration and management heartbeat. Network connectivity or firewall blocks are the most frequent cause of disconnection.

191
MCQmedium

An administrator is planning an automated mass deployment of Cortex XDR agents using Microsoft Endpoint Configuration Manager (SCCM). Which command-line switch should be included with the MSI installer to perform a silent installation without user interaction?

A./verysilent /suppressmsgs
B.--install --silent
C./silent /norestart
D./qn /norestart
AnswerD

The '/qn' switch specifies a completely quiet/silent installation for MSI packages, and '/norestart' prevents unexpected reboots.

Why this answer

Standard Windows Installer (msiexec) uses '/qn' or '/quiet' to perform a completely silent installation.

192
MCQmedium

An administrator is troubleshooting a Cortex XDR script execution failure via Remote Actions. Which condition must be met on a Windows endpoint for a PowerShell remediation script to run successfully?

A.The Broker VM must be configured as a script relay server.
B.The endpoint must have WinRM enabled on TCP port 5985.
C.The endpoint must allow PowerShell script execution and the Cortex XDR agent service must be running with administrative privileges.
D.The user must be logged into an active GUI session.
AnswerC

Remote actions require administrative rights on the host and permitted script execution settings.

Why this answer

Remote action scripts executed via Cortex XDR require appropriate PowerShell execution policies and agent permissions on the endpoint.

193
MCQhard

An administrator is designing a custom Alert-based BIOC rule in Cortex XDR. The requirement is to trigger an alert only when three distinct failed login events occur within a 5-minute window from the same source IP address. How should the aggregation and time window be configured?

A.Set the threshold count to 3, group by source IP address, and set the time window to 5 minutes.
B.Set the threshold count to 5, group by event ID, and set the time window to 3 minutes.
C.Configure a BIOC rule using a single event trigger with a recurrence limit set to 3.
D.Use XQL correlation rules instead, because BIOC rules cannot evaluate time-based thresholds.
AnswerA

Correct. Grouping by source IP with a count threshold of 3 over a 5-minute window precisely fulfills the detection requirement.

Why this answer

Alert-based BIOC rules support aggregation and grouping by specific fields with a sliding time window to detect threshold breaches.

194
MCQeasy

When creating an installation package in the Cortex XDR management console, what is the purpose of assigning an agent profile to the package?

A.To encrypt the installation binary against unauthorized tampering during transit.
B.To automatically apply specific configuration and security settings upon agent registration.
C.To determine which operating system architecture (32-bit or 64-bit) the package will target.
D.To set the license expiration date for the endpoint.
AnswerB

Agent profiles define security policies and are bound to installation packages for initial setup.

Why this answer

Assigning a profile to an installation package ensures that the endpoint immediately adopts the correct configuration, security rules, and data collection settings upon registration.

195
MCQhard

An administrator needs to write a custom automation script in Cortex XSOAR to query the Cortex XDR API for all endpoints that have not checked in within the last 7 days. Which API endpoint and filtering mechanism should the script use?

A.POST /public_api/v1/incidents/get_all_incidents/ with a severity filter
B.PUT /public_api/v1/audits/get_actions/ with an agent version parameter
C.GET /public_api/v1/endpoints/get_endpoint/ with an explicit JSON filter for last_seen timestamp
D.GET /public_api/v1/file/file_metadata/ with a SHA256 parameter
AnswerC

Querying endpoints requires the endpoint API route with filters matching the last seen time criteria.

Why this answer

The Cortex XDR public API uses the `/public_api/v1/endpoints/get_endpoint/` endpoint with custom filters based on operational status and last seen timestamp.

196
Multi-Selectmedium

An administrator needs to troubleshoot an endpoint where the Cortex XDR agent has been tampered with or corrupted. Which TWO actions can the administrator take to repair or reinstall the agent safely? (Choose two)

Select 2 answers
A.Format the endpoint hard drive and restore from a factory image.
B.Delete the agent folder manually in Program Files without using the uninstaller.
C.Force an overwrite installation without uninstalling by modifying Windows Group Policy.
D.Uninstall the agent using the console-generated uninstallation password, then perform a clean reinstallation using the latest installer package.
E.Use 'cytool' with the appropriate maintenance password to reset corrupted agent database files and restore default settings.
AnswersD, E

A clean uninstall with the correct password followed by a fresh install resolves corruption and tampering issues.

Why this answer

Repairing or reinstalling a tampered agent requires using the uninstallation password and official installation packages.

197
Multi-Selectmedium

An administrator is configuring network settings for Cortex XDR Broker VMs. Which TWO protocols and associated ports are commonly used when configuring the Broker VM for syslog ingestion and agent communication? (Choose two)

Select 2 answers
A.TCP port 443 for cloud tenant and agent communication
B.UDP/TCP port 514 (or configured custom ports) for Syslog log collection
C.TCP port 23 for Telnet remote management
D.UDP port 69 for Trivial File Transfer Protocol (TFTP) agent staging
E.TCP port 3389 for Remote Desktop Protocol (RDP) log streaming
AnswersA, B

TCP port 443 is used for secure TLS communication between agents, Broker VMs, and the Cortex XDR cloud.

Why this answer

Broker VMs ingest syslog over standard ports (such as UDP/TCP 514 or custom ports) and communicate with agents/cloud over TCP 443.

198
MCQmedium

An endpoint has been isolated via the Cortex XDR management console to contain a suspected active breach. Once the threat is remediated, how does the administrator restore network connectivity to the endpoint?

A.Delete and recreate the endpoint agent installation token.
B.Select the endpoint in Endpoints > All Endpoints and click Unisolate.
C.Reboot the endpoint twice in safe mode.
D.Run 'cytool set isolation disable' locally via command line.
AnswerB

The Unisolate action reverses network isolation rules applied by the agent and restores full network connectivity.

Why this answer

Administrators can reverse containment by selecting the isolated endpoint in the Endpoints view and clicking 'Unisolate'.

199
Multi-Selectmedium

An analyst is reviewing the Endpoint Management module in Cortex XDR. Which TWO pieces of status information are visible for each enrolled agent? (Choose two)

Select 2 answers
A.Agent software version
B.Hard drive manufacturing serial number
C.Last seen timestamp
D.BIOS cryptographic signature key
E.Local administrator password hash
AnswersA, C

The management console displays the exact running version of every agent.

Why this answer

Endpoint Management displays operational agent details including the agent version and the last seen timestamp.

200
Multi-Selecthard

An analyst is troubleshooting a complex multi-stage attack in Cortex XDR. Which THREE analytical tools or views in the console help reconstruct the sequence of events across endpoints? (Choose three)

Select 3 answers
A.Agent deployment package downloader
B.Global agent proxy configuration menu
C.Causality View graph
D.Incident Timeline view
E.XQL Search query interface
AnswersC, D, E

The Causality View maps out process ancestry and event relationships.

Why this answer

Incident causality views, XQL hunting queries, and attack story timelines are core tools used to reconstruct attacks in Cortex XDR.

201
MCQmedium

An administrator needs to upgrade a large fleet of Linux endpoints running the Cortex XDR agent. What is the recommended best practice for performing this upgrade via the Cortex XDR management console?

A.Delete the endpoint from the console and re-enroll it with the latest agent version.
B.Modify the local yum/apt repository configuration to pull updates from Palo Alto Networks public cloud.
C.Uninstall the existing agent completely, reboot the server, and manually install the new version via CLI.
D.Create a new installation package with the upgraded version and push it using software distribution tools or the console upgrade feature.
AnswerD

Using distribution tools or console upgrade mechanisms allows seamless updates without manual intervention.

Why this answer

Deploying an upgraded installation package or using the console's upgrade mechanism ensures consistency, but for Linux, deploying the updated package via software deployment tools or the console upgrade task is standard.

202
MCQeasy

What is the function of an Exploit Protection profile in Cortex XDR?

A.To encrypt endpoint hard drives using BitLocker or FileVault.
B.To prevent memory-based attacks and protect applications from exploitation techniques.
C.To control USB mass storage device access.
D.To detect and block known malware hashes during file scans.
AnswerB

Exploit Protection focuses on shielding applications from memory exploits and vulnerabilities.

Why this answer

Exploit Protection profiles safeguard applications against memory-based attacks, buffer overflows, and software vulnerabilities.

203
MCQmedium

An administrator wants to ensure that Cortex XDR agent logs are automatically uploaded to the Cortex XDR server for troubleshooting without manual intervention. Which profile governs log collection and forwarding behaviors?

A.Exploit Protection profile
B.Data Collection profile
C.Agent Settings profile
D.Biometric Threat Prevention profile
AnswerB

Data Collection profiles define the scope of data gathering and telemetry sent to the server.

Why this answer

The Data Collection profile dictates what telemetry, logs, and files are gathered and sent from the endpoint to the Cortex XDR backend.

204
MCQhard

An advanced threat actor executes a living-off-the-land technique using certutil.exe to decode a malicious payload. The built-in Analytics engine generates an alert. The security team wants to understand how the Analytics engine derived this finding by reviewing the underlying behavioral logic or heuristics associated with the alert ID. Where can an engineer review the definition and rule logic of built-in Analytics detectors?

A.Analytics rule descriptions and details within the Cortex XDR console / documentation reference
B.Agent binary configuration file (agent.conf)
C.Host Insights Vulnerability assessment database
D.Cortex XSOAR Playbook Designer source code
AnswerA

Cortex XDR provides descriptions and mapping for built-in analytics rules to explain the triggers.

Why this answer

While custom BIOCs are fully user-editable, built-in Analytics rule details, descriptions, and attack descriptions are documented within the Cortex XDR Analytics documentation and rule description references in the console.

205
MCQmedium

An administrator is planning network connectivity for a Broker VM that needs to forward logs to an external SIEM while also communicating with Cortex XDR. Which network configuration requirement must be met?

A.The Broker VM must operate as an explicit proxy server with Kerberos authentication enabled
B.The Broker VM must have ICMP echo requests enabled across all enterprise routers
C.The Broker VM must have a direct public IP address assigned to its management interface
D.The Broker VM must be able to resolve DNS and communicate outbound to the Cortex XDR cloud over TCP port 443
AnswerD

DNS resolution and outbound TCP port 443 connectivity to the Cortex XDR tenant are mandatory for Broker VM operation.

Why this answer

The Broker VM requires outbound HTTPS access to the Cortex XDR cloud and inbound/outbound connectivity depending on syslog collection and SIEM forwarding roles.

206
Multi-Selectmedium

When setting up automated alert response actions using Cortex XDR built-in response actions or XSOAR integrations, which THREE actions can be automatically initiated directly against an endpoint agent? (Choose three)

Select 3 answers
A.Initiate a file quarantine and retrieval request for forensic analysis.
B.Force a full operating system reinstallation from a clean recovery partition.
C.Reflash the target endpoint device BIOS firmware remotely.
D.Terminate a running process identified as malicious.
E.Isolate the endpoint from the network to prevent lateral movement.
AnswersA, D, E

Correct. File retrieval and quarantine are supported agent actions.

Why this answer

Cortex XDR agent supports automated response actions including isolating an endpoint from the network, retrieving files for forensics, and terminating suspicious processes.

207
MCQmedium

An administrator notices that several macOS endpoints have incomplete Cortex XDR agent functionality because required operating system permissions were not granted during installation. Which component or setting must be configured to resolve this?

A.Deploy an Apple MDM configuration profile containing System Extension and Full Disk Access payloads.
B.Run the agent installer with sudo privileges twice consecutively.
C.Disable Apple SIP (System Integrity Protection) globally on all endpoints.
D.Modify the macOS sudoers file to include the Cortex XDR process path.
AnswerA

MDM profiles are required on modern macOS versions to silently approve system extensions and privacy permissions for security agents.

Why this answer

macOS endpoints require specific System Extensions and Full Disk Access permissions to be granted, which are typically pre-configured and deployed via Mobile Device Management (MDM) configuration profiles.

208
MCQhard

An administrator is troubleshooting an API rate-limiting error (HTTP 429 Too Many Requests) occurring in a custom Cortex XSOAR automation playbook that queries an external threat intel API. How should the integration or playbook be modified to handle this gracefully?

A.Disable SSL certificate validation on the API integration instance
B.Switch the integration protocol from HTTPS to raw TCP sockets
C.Implement exponential backoff and retry logic within the integration command or playbook task
D.Increase the Broker VM CPU allocation to bypass API server limits
AnswerC

Handling HTTP 429 errors requires pausing and retrying after a backoff period.

Why this answer

Handling rate limits requires implementing backoff and retry logic or adjusting polling intervals within the integration/playbook.

209
MCQhard

An administrator is troubleshooting a Broker VM that is failing to pull updates from the Cortex XDR cloud. Upon inspecting the Broker VM system logs, the administrator notices SSL handshake errors. What is the most likely root cause?

A.The Broker VM registration key contains invalid characters due to copy-paste formatting
B.The Cortex XDR management tenant license has expired due to billing cycle misalignment
C.An intervening firewall or explicit proxy is performing SSL decryption and presenting an untrusted certificate to the Broker VM
D.The Broker VM kernel version is incompatible with the Linux swap space partition size
AnswerC

If an inspection device intercepts TLS traffic without the Broker VM trusting its root CA, the handshake fails.

Why this answer

SSL inspection or interception by an explicit proxy or next-generation firewall without proper TLS decryption certificate installation causes SSL handshake failures on the Broker VM.

210
MCQeasy

An administrator is configuring a Syslog Collector agent on Cortex XDR to ingest logs from a third-party firewall. Which log collection protocol and transport layer combination is natively supported by the Cortex XDR Collector for receiving unencrypted syslog messages?

A.Syslog over UDP and TCP
B.Syslog over HTTP/HTTPS
C.Syslog over SSH tunneling
D.Syslog over FTP/SFTP
AnswerA

The Cortex XDR Syslog Collector accepts unencrypted syslog data over both UDP and TCP protocols.

Why this answer

Cortex XDR Syslog Collector natively supports receiving syslog messages over UDP and TCP.

211
MCQeasy

An administrator is troubleshooting a Broker VM that cannot ingest CEF logs from a third-party SIEM. Which service status command should the administrator run inside the Broker VM shell to verify that the syslog collector service is running?

A.pan_status --all
B.broker-vm status-collector
C.systemctl status pan-syslog-collector
D.service broker status
AnswerC

systemctl status pan-syslog-collector (or the respective broker service name) checks if the log collector service is active and running.

Why this answer

Systemctl is the standard Linux service management tool used on the Broker VM appliance.

212
MCQhard

During a troubleshooting session, an administrator needs to collect all Cortex XDR agent troubleshooting logs into a single compressed archive directly from the Windows endpoint command line. Which cytool command should be executed?

A.cytool debug generate
B.cytool dump-logs
C.cytool log collect
D.cytool export support-bundle
AnswerC

'cytool log collect' gathers agent diagnostic data into a compressed package.

Why this answer

The 'cytool log collect' command generates a diagnostic archive containing all relevant agent logs for support or advanced troubleshooting.

213
MCQmedium

An organization utilizes custom correlation rules in Cortex XDR. An engineer needs to export these custom BIOC rules to backup configurations or migrate them to another Cortex XDR tenant. Which administrative feature supports this?

A.Export and Import options within the BIOC management interface
B.Agent deployment script parameter flags
C.Cortex XDR API key generation settings
D.Data Export Service configuration bucket
AnswerA

BIOC rules can be exported to JSON/XML or shared formats for backup and migration.

Why this answer

Cortex XDR provides administrative export and import capabilities under Analytics / BIOC rules to manage rule portability.

214
Multi-Selectmedium

Which TWO criteria can be used to dynamically group endpoints and assign agent profiles in Cortex XDR? (Choose two)

Select 2 answers
A.Physical office desk location number
B.Operating system type (e.g., Windows, macOS, Linux)
C.Endpoint hostname or naming convention patterns
D.BIOS manufacturer serial number color
E.Local user account password expiration date
AnswersB, C

Operating system is a primary criterion for grouping and assigning profiles.

Why this answer

Dynamic endpoint grouping in Cortex XDR can be based on criteria such as operating system type and Active Directory organizational units or naming patterns.

215
Multi-Selectmedium

An administrator is planning the deployment of Cortex XDR agents across endpoints and needs to configure Agent Settings profiles. Which TWO configurations can be managed directly within an Agent Settings profile? (Choose two)

Select 2 answers
A.Agent operational mode (e.g., Normal, Extended, or Disabled)
B.PAN-OS firewall security rule policies
C.Scheduled malware scan configurations and exclusions
D.Global WildFire threat signature updates
E.Cortex XSOAR playbook automation triggers
AnswersA, C

Operational modes are defined and assigned via Agent Settings profiles.

Why this answer

Agent Settings profiles allow administrators to configure agent behavior such as endpoint protection modules, scan schedules, proxy settings, and operational parameters.

216
MCQeasy

Where can an administrator view the status and health of all deployed Broker VMs directly within the Cortex XDR management console?

A.Settings > Configurations > Infrastructure > Broker VMs
B.Settings > Configurations > Broker VMs
C.Endpoints > Broker VMs
D.XDR Devices > Infrastructure > Broker VMs
AnswerA

Administrators navigate to Settings > Configurations > Infrastructure > Broker VMs to check Broker VM connectivity, status, and version.

Why this answer

Broker VM health and status are monitored under the Broker VMs page in the Cortex XDR console.

217
Multi-Selectmedium

Which TWO of the following capabilities are provided by Cortex XDR Behavioral Threat Analytics (Analytics BIOCs)? (Choose two)

Select 2 answers
A.Detecting rare or anomalous process execution across the enterprise environment.
B.Identifying lateral movement and credential dumping techniques using machine learning models.
C.Automatically updating agent software binaries on offline endpoints.
D.Manually enforcing firewall blocking rules on third-party perimeter gateways.
E.Performing local signature scans on static files at rest.
AnswersA, B

Correct. Analytics BIOCs identify anomalous behavior such as rare process executions.

Why this answer

Behavioral Threat Analytics detect anomalous behavior, potential credential theft, lateral movement, and rare execution patterns by establishing baseline activity.

218
MCQmedium

An administrator needs to upgrade the Cortex XDR agents across all enterprise endpoints. Where should the administrator upload and manage the new agent software versions before rolling them out?

A.Dashboards > System Status > Updates
B.Administration > Global Protect > Client Versions
C.Endpoints > Agent Upgrades
D.Settings > Tenant Management > Software Repository
AnswerC

The Agent Upgrades page allows administrators to upload, manage, and schedule agent software version upgrades.

Why this answer

Administrators manage and stage agent software versions under the Agent Upgrades section in the Cortex XDR console.

219
Multi-Selecteasy

An administrator is planning an automated deployment of Cortex XDR agents using an enterprise software distribution tool. Which TWO advantages does using an MSI package offer over an EXE package in this scenario? (Choose two)

Select 2 answers
A.Standardized installation parameters and property passing (e.g., /qn, /norestart)
B.Built-in capability to execute shell scripts on Linux servers
C.Automatic conversion of EXE payloads into macOS PKG files
D.Native support for application transforms (.MST files) for customization
E.Exemption from all Windows User Account Control (UAC) prompts without admin rights
AnswersA, D

MSI packages adhere to Windows Installer standards, providing consistent switches and property arguments.

Why this answer

MSI packages offer standard command-line properties, easy integration with GPO/SCCM, and built-in support for transforms (MST).

220
Multi-Selectmedium

An administrator is configuring a new integration in Cortex XSOAR and needs to ensure secure credential handling. Which TWO practices are recommended when managing API keys and secrets? (Choose two)

Select 2 answers
A.Store API keys using the integration parameter type 'Encrypted' / 'Password'
B.Hardcode the API keys directly into the playbook Python script source code
C.Rotate API keys periodically according to organizational security policy
D.Publish the API keys in plain text within the incident description field for team visibility
E.Share integration credentials across all tenants via public GitHub repositories
AnswersA, C

Password and encrypted parameter types mask and secure sensitive secrets in the UI and database.

Why this answer

API keys and secrets should be stored securely using integration parameters configured as password/credential types and managed securely.

221
MCQmedium

An administrator is configuring automated incident enrichment in Cortex XDR. Whenever a new malware incident is generated, the system should automatically query VirusTotal using an integration. Where should this automated workflow be built and attached?

A.Inside the Cortex XDR Agent installation policy settings
B.Inside the Broker VM local crontab configuration file
C.As an automated Playbook attached to Incident Trigger rules in the Automation module
D.As a local cron job running on each individual endpoint
AnswerC

Playbooks are triggered automatically based on incident filters and rules configured in the platform.

Why this answer

Automated workflows triggered by incident creation are built as Playbooks in Cortex XSOAR / XDR Automation and attached to Incident Classification or Trigger rules.

222
MCQhard

A Cortex XDR Agent on a macOS endpoint is failing to start its kernel extension (Endpoint Security extension). Which diagnostic command should be run locally in the macOS Terminal to verify system extension approval status?

A.macos-agent-check --status
B.systemextensionsctl list
C.kextstat | grep paloalto
D.cytool mac status
AnswerB

systemextensionsctl list displays the activation and approval state of Endpoint Security and Network Extension system extensions on macOS.

Why this answer

macOS uses system extension management commands such as 'systemextensionsctl' to inspect loaded and approved extensions.

223
MCQmedium

An administrator needs to temporarily disable the Cortex XDR agent on a Windows endpoint to troubleshoot a conflicting third-party application. Which method should be used?

A.Execute 'cytool protection disable' locally using the authorized disable password.
B.Delete the Cortex XDR driver files from System32/drivers.
C.Disable the Windows Firewall network adapter binding.
D.Stop the Cortex XDR service from the Windows Services management console (services.msc).
AnswerA

The cytool utility allows authorized administrators to temporarily disable protection features locally when armed with the correct password.

Why this answer

To disable agent protection features without uninstalling, the administrator must use the 'Disable Agent' action from the Cortex XDR console or use the cytool command-line utility locally with the correct authorization password.

224
Multi-Selecteasy

Which TWO actions can an administrator take if a Cortex XDR agent fails to register with the cloud management console after installation? (Choose two)

Select 2 answers
A.Reconfigure the endpoint's printer sharing permissions.
B.Reboot the local office router to refresh the ISP dynamic IP lease.
C.Change the Windows desktop wallpaper theme.
D.Check that the installation package was created with the correct tenant parameters and valid token.
E.Verify outbound TCP port 443 connectivity to the Cortex XDR backend.
AnswersD, E

Incorrect tenant parameters or invalid installation tokens prevent successful registration.

Why this answer

Registration failures are typically investigated by checking network/firewall connectivity and validating the installation token or package configuration.

225
MCQeasy

An organization is preparing to deploy the Cortex XDR agent using Microsoft Active Directory Group Policy Objects (GPO). Which installation package format is natively supported for GPO deployment of the agent on Windows endpoints?

A.Windows Installer Package (.msi)
B.Compressed Archive (.zip)
C.Executable (.exe)
D.PowerShell Script (.ps1)
AnswerA

Active Directory GPO software installation requires an .msi package format.

Why this answer

Group Policy deployment natively supports Microsoft Installer (.msi) packages for software distribution.

Page 2

Page 3 of 4

Page 4

All pages