Courseiva

CCNA Endpoint Security Questions

30 questions · Endpoint Security · All types, answers revealed

1
Multi-Selecteasy

Which TWO actions can an administrator perform from the Cortex XDR management console when responding to an active endpoint security incident? (Choose two)

Select 2 answers
A.Isolate the endpoint from the network to prevent lateral movement.
B.Reboot the physical datacenter HVAC cooling systems.
C.Modify core BGP routing tables on enterprise core routers.
D.Reset enterprise Wi-Fi SSID pre-shared keys.
E.Initiate file quarantine on suspicious artifacts detected during the incident.
AnswersA, E

Network isolation is a core response action available in Cortex XDR.

Why this answer

Administrators can isolate compromised hosts and initiate remote remediation actions such as file quarantine and script execution.

2
MCQeasy

Which component of the Cortex XDR architecture provides continuous endpoint data collection and threat prevention directly on the host operating system?

A.Panorama management server
B.Cortex XDR agent
C.Prisma Access cloud security service
D.WildFire cloud analysis engine
AnswerB

The agent runs on endpoints for prevention, detection, and data collection.

Why this answer

The Cortex XDR agent is installed directly on endpoints to execute prevention and gather telemetry.

3
MCQhard

An organization's security policy requires all endpoint security logs to be forwarded to a centralized SIEM in real time. How does Cortex XDR support this requirement?

A.Configure Syslog forwarding or use the Cortex XDR streaming API to export alerts and BIOC data to the SIEM.
B.Configure NetFlow export on the local endpoint network interface card.
C.Export daily CSV reports from the Cortex XDR console via email.
D.Enable SNMP trap generation inside the local Windows Event Viewer settings.
AnswerA

The streaming API and Syslog forwarding enable real-time export of security telemetry to external SIEMs.

Why this answer

Cortex XDR provides integration via Syslog forwarding or REST APIs to stream alerts and logs to third-party SIEM platforms.

4
Multi-Selecteasy

Which TWO types of files or threats are typically inspected and analyzed by the WildFire cloud service when integrated with Cortex XDR? (Choose two)

Select 2 answers
A.Default operating system desktop background wallpaper images in PNG format.
B.Uncompressed family vacation audio MP3 recordings.
C.Suspicious Microsoft Office documents containing embedded macros or scripts.
D.Unknown executable binaries and portable executables (PE files).
E.Standard plain text grocery shopping lists without executable content.
AnswersC, D

Office documents with potential malicious macros are analyzed in the sandbox.

Why this answer

WildFire analyzes suspicious executable files, documents with macros, scripts, and unknown binaries submitted by endpoints.

5
MCQmedium

An administrator wants to prevent users from tampering with or uninstalling the Cortex XDR agent on Windows workstations. Which feature must be configured in the agent settings?

A.Configure Windows BitLocker drive encryption on the system drive.
B.Enable User Account Control (UAC) at the default notification level.
C.Set the endpoint network profile to Public domain.
D.Enable Anti-Tamper protection with a designated administrator password.
AnswerD

Anti-tamper protection requires a password or token to modify or uninstall the agent.

Why this answer

Anti-tamper protection prevents unauthorized users or malware from stopping services, deleting files, or uninstalling the agent.

6
Multi-Selecthard

An administrator is troubleshooting a scenario where Cortex XDR agents are failing to report incident data to the cloud console. Which TWO network-related items should be verified? (Choose two)

Select 2 answers
A.Check that local DHCP leases are renewed every 30 seconds.
B.Ensure outbound TCP port 443 traffic is permitted to the Cortex XDR backend FQDNs.
C.Verify that local DNS servers can successfully resolve the Cortex XDR tenant service endpoints.
D.Confirm that inbound SSH port 22 is open on all endpoint host firewalls.
E.Verify that SNMP v3 trap listeners are active on port 162.
AnswersB, C

Outbound HTTPS is required for agent-to-cloud telemetry reporting.

Why this answer

Cortex XDR agents require outbound HTTPS (port 443) connectivity to Cortex XDR cloud backend URLs and proper DNS resolution.

7
Multi-Selectmedium

Which THREE actions occur when an endpoint is placed into 'Isolation' mode using Cortex XDR? (Choose three)

Select 3 answers
A.Configured isolation exceptions can allow specific forensic servers to communicate with the host.
B.The endpoint hard drive is securely wiped and zeroed out.
C.Communication with the Cortex XDR management backend remains permitted via defined exceptions.
D.All non-exempt network traffic to and from the endpoint is dropped.
E.The endpoint physical hardware power supply is automatically cut off.
AnswersA, C, D

Exceptions can be created for forensics or remediation access.

Why this answer

Isolation severs standard network communication while allowing designated management traffic and preventing lateral movement.

8
Multi-Selectmedium

Which THREE features are provided by the Cortex XDR agent to protect endpoints against modern malware and advanced threats? (Choose three)

Select 3 answers
A.Local Analysis utilizing machine learning models to detect unknown malware.
B.Behavioral Threat Protection to detect post-exploitation techniques in real time.
C.Exploit Protection to prevent memory corruption and injection attacks.
D.Deep Packet Inspection for BGP routing protocol convergence.
E.Automatic generation of RAID disk arrays for local fault tolerance.
AnswersA, B, C

Local Analysis uses ML models to evaluate files directly on the endpoint.

Why this answer

Cortex XDR agents provide local analysis, behavioral threat protection, and exploit protection among other security modules.

9
MCQhard

An endpoint has been compromised by an advanced persistent threat (APT). The incident response team needs to reconstruct the entire attack lifecycle, showing how the initial access led to lateral movement and persistence. Which Cortex XDR feature provides this visualization?

A.Causation Analysis view showing the graphical chain of events originating from the root cause process.
B.Windows Event Viewer custom filtered operational logs.
C.Network packet capture waveform analyzer.
D.Global Threat Intelligence map showing country-of-origin IP addresses.
AnswerA

Causation Analysis traces the complete lineage of an attack from root cause through all child processes and actions.

Why this answer

Cortex XDR Causation Analysis provides a graphical causality chain showing the relationship between processes, files, registry modifications, and network connections.

10
MCQeasy

An administrator needs to upgrade Cortex XDR agents across all enterprise endpoints. What is the recommended method in the Cortex XDR management console?

A.Reinstall the operating system on all endpoints using a clean golden image.
B.Use the Cortex XDR upgrade feature in Endpoint Management to push the new agent version to selected endpoint groups.
C.Manually log into every individual endpoint and run the uninstall wizard.
D.Modify the DNS records to point agents to a secondary upgrade server.
AnswerB

Centralized upgrades via Endpoint Management ensure consistent deployment across groups.

Why this answer

Cortex XDR provides centralized agent version management where administrators can schedule or push upgrades to endpoint groups.

11
MCQeasy

What is the primary function of WildFire integration within the Cortex XDR ecosystem?

A.To provide local disk defragmentation services.
B.To enforce multi-factor authentication for endpoint login sessions.
C.To automatically analyze unknown files and samples submitted by endpoints to determine if they are malicious.
D.To manage firewall security policies across multiple tenants.
AnswerC

WildFire uses sandboxing and static analysis to evaluate unknown files.

Why this answer

WildFire acts as the cloud-based threat analysis engine that analyzes unknown files and provides accurate verdicts.

12
Multi-Selecthard

An administrator needs to configure granular endpoint settings for different departments within the organization. Which THREE components of Cortex XDR should be utilized? (Choose three)

Select 3 answers
A.Endpoint Groups to categorize workstations based on criteria such as department or OS.
B.Global Wi-Fi WPA3 enterprise RADIUS shared secrets.
C.Installation Settings to define initial agent configuration parameters during setup.
D.BGP Autonomous System Number (ASN) path configuration tables.
E.Agent Settings profiles to define operational parameters and prevention module states.
AnswersA, C, E

Endpoint groups organize targets for policy application.

Why this answer

Cortex XDR uses endpoint groups, agent settings profiles, and installation settings to manage different department configurations.

13
MCQeasy

An administrator wants to verify which prevention modules (e.g., Malware, Exploit, Behavioral Threat Protection) are enabled for a specific set of workstations. Where should the administrator check?

A.In the Active Directory Domain Controller Group Policy Management Editor.
B.In the Cortex XDR management console under Endpoint Management > Agent Settings.
C.In the firewall Security Policy rulebase.
D.In the global DNS Server configuration utility.
AnswerB

Agent Settings profiles define the active state of each prevention module.

Why this answer

Agent settings and profiles dictate which protection modules are active for specific endpoint groups.

14
MCQeasy

An organization wants to verify that the Cortex XDR agent is actively communicating with the Cortex XDR cloud tenant. Which status indicator should the administrator look for in the Endpoint Management view?

A.Ensure the endpoint operating system is running the latest patch level.
B.Confirm that the kernel module version matches the BIOS version.
C.Check that the connection status shows Connected with a recent heartbeat timestamp.
D.Verify that the local disk usage is below 10 percent.
AnswerC

A Connected status and recent heartbeat verify active communication.

Why this answer

The connection status in Endpoint Management indicates whether the agent has an active, healthy TLS session with the backend server.

15
MCQmedium

A security analyst notices that a specific PowerShell script is being blocked on an endpoint by Cortex XDR behavioral threat protection. However, the development team confirms the script is legitimate. Where should the analyst create an exception to allow this specific script execution while maintaining behavioral monitoring?

A.In the Cortex XDR management console under Profiles, create a behavioral threat protection exception using the script file hash.
B.Change the Agent settings to bypass all SSL decryption rules.
C.Disable the Local Analysis module entirely for the target endpoint group.
D.Modify the Windows Firewall inbound rules on the local endpoint.
AnswerA

A behavioral threat protection exception using the file hash permits the specific script without disabling the entire module.

Why this answer

Cortex XDR allows administrators to create profile exceptions based on hash or behavioral exception rules for specific trusted scripts.

16
MCQeasy

An administrator is deploying Cortex XDR agent to corporate Windows endpoints and needs to ensure that the agent runs in full prevention mode without user intervention. Which configuration setting in the installation profile must be verified?

A.Disable the self-defense mechanism during MSI deployment.
B.Configure the proxy bypass list for local loopback communication.
C.Set the heartbeat interval to 60 seconds.
D.Ensure the operation mode parameter is set to prevent rather than detect or disable.
AnswerD

Setting the mode to prevent ensures that blocking actions are taken against malicious payloads.

Why this answer

The prevention module must be explicitly enabled in the agent installation settings to ensure full enforcement immediately upon installation.

17
MCQmedium

An endpoint running macOS encounters a kernel extension loading blockage when installing the Cortex XDR agent. What action must the administrator take to resolve this?

A.Disable SIP (System Integrity Protection) permanently on all Mac endpoints.
B.Approve the system extension and network filter configurations via Mobile Device Management (MDM) policy or local system settings.
C.Reformat the drive using the APFS file system format.
D.Configure the Endpoint Security client to run as a root daemon via launchd.
AnswerB

macOS security controls require explicit authorization for system extensions and network filters.

Why this answer

Modern macOS versions require explicit user or MDM approval for system extensions and kernel extensions used by security software.

18
MCQhard

An administrator needs to deploy Cortex XDR agents across a large enterprise using an Active Directory Group Policy Object (GPO). The installation fails on Windows endpoints with an error indicating missing prerequisites. What must be verified first?

A.Verify that the endpoint BIOS has Secure Boot enabled and TPM 2.0 active.
B.Check that the local Administrator account password matches the domain admin password.
C.Ensure the required Windows OS servicing stack updates and Universal C Runtime dependencies are installed on target endpoints.
D.Configure the endpoint to use DHCP reservation instead of static IP addresses.
AnswerC

Missing OS dependencies will cause the MSI package installation to fail during deployment.

Why this answer

Cortex XDR agents require specific Windows OS patches (such as Universal C Runtime updates) and proper MSI execution privileges.

19
MCQeasy

An endpoint generates an alert indicating that a known malicious file was detected and quarantined by the Cortex XDR agent. Where can the administrator review details about this quarantine action?

A.In the DNS Security query logs.
B.In the Cortex XDR management console under Incident Response, view the Action Center or Endpoint Management quarantine tab.
C.In the WildFire analysis report repository exclusively.
D.In the global firewall traffic log.
AnswerB

The Action Center records all remediation actions including quarantine history.

Why this answer

Quarantined items can be managed and reviewed directly from the Cortex XDR management console under Incident Response or Endpoint views.

20
MCQhard

An enterprise environment contains legacy Windows servers that cannot support the latest Cortex XDR agent version due to OS limitations. How does Cortex XDR handle protection for these older operating systems?

A.By forcing an automatic in-place upgrade of the legacy Windows server to Windows 11.
B.By routing all legacy server traffic through a next-generation firewall proxy instead of installing an agent.
C.By deploying a compatible legacy agent version that supports older OS APIs while providing core malware and exploit prevention.
D.By disabling all security checks for servers older than five years.
AnswerC

Palo Alto Networks provides dedicated legacy agent builds for older supported operating systems.

Why this answer

Cortex XDR supports legacy operating systems with specific legacy agent versions that provide core prevention capabilities supported by those OS architectures.

21
Multi-Selecteasy

Which TWO operating systems are officially supported for deployment of the standard Cortex XDR agent? (Choose two)

Select 2 answers
A.Embedded automotive CAN bus microcontrollers
B.Commercial airliner avionics flight control firmware
C.Apple macOS
D.Microsoft Windows 10 and Windows 11
E.Consumer smart refrigerator operating systems
AnswersC, D

macOS is fully supported with dedicated agent builds.

Why this answer

Cortex XDR supports major desktop and server operating systems including Windows and macOS.

22
MCQmedium

A security analyst is reviewing a BIOC (Behavioral Indicator of Compromise) alert in the Cortex XDR incident view. What distinguishes a BIOC alert from a standard malware alert?

A.BIOC alerts are generated exclusively by network firewall threat logs.
B.BIOC alerts only trigger when a user manually initiates a full system scan.
C.BIOC alerts require an active WildFire cloud subscription to function locally.
D.BIOC alerts detect suspicious sequences of system events and behaviors rather than matching known file signatures.
AnswerD

BIOCs focus on techniques and behaviors, making them effective against unknown or fileless threats.

Why this answer

BIOC alerts identify malicious sequences of events or techniques rather than relying solely on file signatures.

23
Multi-Selectmedium

Which THREE methods can be used to deploy the Cortex XDR agent package across an enterprise Windows environment? (Choose three)

Select 3 answers
A.Broadcasting the installation package over commercial FM radio frequencies.
B.Injecting the MSI payload via unauthenticated network printer port scans.
C.Endpoint management platforms such as Microsoft Intune or SCCM.
D.Manual interactive installation using the installation package with administrator privileges.
E.Active Directory Group Policy Object (GPO) software installation.
AnswersC, D, E

Enterprise management tools can push MSI installations to enrolled workstations.

Why this answer

Administrators can deploy the Cortex XDR agent via Active Directory GPO, third-party software deployment tools (SCCM/Intune), or manual installation scripts.

24
MCQmedium

A security analyst is investigating a polymorphic malware sample that attempts to inject code into legitimate Windows processes (Process Injection). Which Cortex XDR protection module is primarily responsible for detecting and blocking this technique?

A.Behavioral Threat Protection
B.URL Filtering profile
C.Data Loss Prevention (DLP) engine
D.DNS Security subscription
AnswerA

Behavioral Threat Protection analyzes runtime activity to detect malicious techniques like process injection.

Why this answer

Local Analysis and Exploit/Behavioral Threat Protection guard against process injection and memory-based attacks.

25
MCQmedium

An endpoint generates an alert for a suspicious script execution, but the analyst determines it is a false positive generated by a legitimate administrative tool. What is the best practice for handling this false positive in Cortex XDR?

A.Uninstall the Cortex XDR agent from all endpoints in that department.
B.Delete the alert from the incident queue without taking action.
C.Set the entire Cortex XDR agent fleet to Audit mode permanently.
D.Create a profile exception using the specific file hash or behavioral signature parameters identified in the alert.
AnswerD

Creating targeted exceptions resolves the false positive while keeping protections active for other threats.

Why this answer

Analysts should create granular exceptions based on file hashes or behavioral signatures rather than disabling security modules globally.

26
MCQhard

An administrator is troubleshooting a Cortex XDR agent that has stopped reporting to the management console. The local agent service is running, but network traces show TLS handshake failures with the Cortex XDR server. What is the most likely cause?

A.The endpoint's local time is synchronized with an NTP server outside the local subnet.
B.The agent license key has reached its maximum daily log ingestion limit.
C.An intervening proxy or firewall is decrypting TLS traffic without the Cortex XDR root certificate installed in the agent trust store.
D.The Cortex XDR agent version is newer than the cloud backend tenant version.
AnswerC

SSL interception without proper certificate trust causes TLS handshake termination.

Why this answer

TLS handshake failures usually stem from expired certificates, SSL inspection proxies intercepting traffic without proper root CA trust, or incorrect proxy settings.

27
MCQhard

An endpoint has been isolated via the Cortex XDR console due to a suspected ransomware outbreak. The incident responder needs to allow one specific management server to communicate with this isolated endpoint for forensics collection. What is the correct procedure?

A.Configure IP-based isolation exceptions in the Cortex XDR profile to allow traffic from the designated forensic server IP.
B.Delete the endpoint from the Cortex XDR asset list and re-add it.
C.Modify the endpoint routing table locally via a startup script.
D.Temporarily disable the Host Firewall module on the endpoint via the CLI.
AnswerA

Isolation exceptions allow targeted connectivity to specific IPs while keeping the rest of the network cut off.

Why this answer

Cortex XDR allows administrators to configure isolation exceptions that specify permitted IP addresses or ports for isolated endpoints.

28
Multi-Selecthard

An administrator is reviewing security events in Cortex XDR and notices multiple alerts tagged with MITRE ATT&CK techniques. Which THREE benefits does integrating MITRE ATT&CK taxonomy into Cortex XDR provide for analysts? (Choose three)

Select 3 answers
A.Automatically recompiles malicious binary code into safe executable patches.
B.Provides a standardized industry terminology for describing adversary tactics and techniques.
C.Assists in identifying security control gaps by revealing which ATT&CK techniques lack detection coverage.
D.Directly replaces the need for endpoint firewalls and network segmentation.
E.Helps analysts map alerts to specific stages of the cyber kill chain and attack lifecycle.
AnswersB, C, E

MITRE ATT&CK establishes a common language for threat analysis.

Why this answer

MITRE ATT&CK mapping provides a common framework for understanding adversary tactics, standardizing incident reports, and identifying security coverage gaps.

29
MCQhard

An endpoint experiences a zero-day fileless attack where shellcode is executed directly in memory via a vulnerable service. Which Cortex XDR protection feature is specifically designed to detect and block this type of attack prior to file drop?

A.Scheduled weekly full disk scans using YARA rules.
B.Antivirus signature database matching against known file hashes.
C.Browser extension security hardening policies.
D.Exploit Protection module monitoring common application memory spaces and blocking anomalous execution flows.
AnswerD

Exploit protection guards against memory-based techniques used in fileless attacks.

Why this answer

Local Analysis and Exploit Protection prevent memory-based and fileless attack techniques like heap spraying or DLL injection.

30
MCQmedium

An endpoint user reports that a legitimate internal application is failing to run because the Cortex XDR agent flags its behavior as suspicious. The administrator wants to collect forensic data specifically for this application to analyze its behavior. Which Cortex XDR feature should be enabled?

A.Enable Causation Analysis and expanded forensic data collection in the Agent Settings profile for that endpoint group.
B.Increase the firewall packet capture buffer size to 1 GB.
C.Configure a URL filtering block page bypass.
D.Enable administrative debug logging on the local syslog server.
AnswerA

Expanded forensic collection ensures detailed process telemetry is sent to the backend for analysis.

Why this answer

Granular agent settings allow administrators to adjust data collection profiles and enable enhanced forensics or BIOC rules.

Ready to test yourself?

Try a timed practice session using only Endpoint Security questions.