Courseiva

Certified XDR Analyst (XDR-Analyst) (XDR-Analyst) — Questions 175

210 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQeasy

An analyst needs to create a BIOC (Behavioral Indicator of Compromise) rule to detect suspicious use of 'whoami' execution by an authenticated domain user. Which data source should the rule evaluate?

A.Cloud storage audit logs
B.Firewall URL filtering logs
C.Process execution telemetry from endpoint agents
D.DHCP lease tables
AnswerC

Process execution telemetry captures command-line execution such as whoami.

Why this answer

BIOC rules for process execution evaluate endpoint telemetry data, specifically process creation events.

2
MCQmedium

An analyst is configuring a BIOC rule to detect credential dumping via LSASS memory access. Which event characteristic must be monitored within the endpoint telemetry criteria?

A.Registry modifications affecting the Windows Firewall state
B.DNS query logs for newly registered domains
C.Target process name matching 'lsass.exe' with suspicious access rights from an unauthorized source process
D.Outbound HTTPS connections to unknown external IP addresses on port 443
AnswerC

Monitoring target process lsass.exe access requests is the primary method for detecting credential dumping via BIOCs.

Why this answer

LSASS credential dumping typically involves specific process open requests (e.g., OpenProcess with PROCESS_VM_READ or PROCESS_QUERY_LIMITED_INFORMATION) targeting lsass.exe.

3
MCQhard

An analyst observes that an incident's score dynamically increases over time as new related alerts are added. Which component of Cortex XDR drives this behavior?

A.The manual analyst assignment workflow
B.The dynamic incident scoring engine
C.The log collector retention policy
D.The featured fields rendering engine
AnswerB

The scoring engine continuously evaluates new alerts added to an incident and updates the aggregate score.

Why this answer

The Cortex XDR incident scoring engine recalculates the overall incident score dynamically as new telemetry and raw alerts are stitched and added to the incident context.

4
MCQeasy

What is the primary purpose of integrating Microsoft Entra ID (formerly Azure AD) logs into Cortex XDR?

A.To replace the Cortex XDR Agent on Linux servers
B.To provide visibility into cloud authentication events, sign-in anomalies, and identity risks in hybrid environments
C.To enforce local BIOS password policies
D.To automate the deployment of Windows security patches to endpoints
AnswerB

Cloud identity logs extend ITDR capabilities beyond on-premises Active Directory into cloud-managed user sign-ins.

Why this answer

Integrating cloud identity provider logs provides visibility into cloud-based authentications, conditional access failures, and SaaS app logins for comprehensive ITDR.

5
MCQmedium

An analyst notices that a service account is generating alerts for anomalous login locations. Upon review, the account is used by an automated batch script running from a newly provisioned server. How should the analyst resolve this alert while maintaining security best practices?

A.Create an exception or tune the analytics rule to account for the new authorized script execution source
B.Change the Cortex XDR agent operational mode to 'Disabled'
C.Upgrade the firewall firmware version
D.Delete the Active Directory domain entirely
AnswerA

Legitimate automated service accounts running from new hosts require analytics tuning or exclusions to prevent alert fatigue.

Why this answer

If a service account is performing expected automated operations from a new source, the analyst can tune the analytics or add the source IP/service account combination to known exclusions.

6
MCQmedium

An analyst is reviewing a cloud-based incident in Cortex XDR (such as AWS or Azure activity). Which evidence source provides the primary forensic logs for cloud resource modifications?

A.Active Directory SYSVOL share
B.Local printer driver cache
C.Local endpoint SAM registry hive
D.Cloud audit and API activity logs
AnswerD

Cloud API activity logs record who performed what action on cloud resources and when.

Why this answer

Cloud infrastructure logs (like AWS CloudTrail or Azure Activity logs) ingested into Cortex XDR provide the audit trail for cloud resource changes.

7
MCQmedium

An administrator is setting up User Risk Scoring within Cortex XDR. They notice that certain service accounts with high volumes of automated authentications are skewing the risk calculations. How should the administrator handle these service accounts in Cortex XDR to prevent false-positive risk elevations?

A.Configure Identity Analytics exclusions or entity classifications for known service accounts
B.Delete all authentication logs associated with service accounts from the Cortex XDR data lake
C.Disable Cortex XDR Agent protection on all Domain Controllers
D.Convert the service accounts into standard local administrator accounts
AnswerA

Excluding or properly tagging service accounts in Identity Analytics ensures behavioral baselines account for automated activity.

Why this answer

Administrators can configure exclusions or adjustments in Identity Analytics for specific service accounts or known non-human entity patterns to prevent skewed risk scores.

8
MCQhard

An organization notices that Cortex XDR incidents are being assigned high severity scores primarily due to a noisy network alert rule that triggers frequently on internal port scans. What is the correct administrative workflow to resolve this scoring inflation?

A.Tune or disable the noisy detector rule, or adjust scoring weight profiles
B.Star all alerts generated by the port scan rule
C.Hide the port scan column using featured fields
D.Enable data stitching overrides for internal ports
AnswerA

Tuning the detector or adjusting scoring weights directly addresses the root cause of score inflation.

Why this answer

To fix scoring inflation caused by noisy rules, administrators should tune or disable the specific detector rule or adjust scoring weights rather than ignoring incidents.

9
MCQeasy

An analyst wants to analyze the raw alert data that directly triggered a specific Cortex XDR incident to understand the exact sequence of events before automated grouping occurred. Where in the Cortex XDR console can the analyst view the individual raw alerts associated with an incident?

A.Under Analytics > BIOC > Alert Log
B.Under the Incident Details page by selecting the Alerts tab
C.Under Response > Action Center > History
D.Under Settings > Data Stitching > Raw Logs
AnswerB

The Alerts tab within the Incident Details view lists all raw alerts contributing to the selected incident.

Why this answer

By drilling down into an incident in Cortex XDR, the analyst can access the Alert tab to inspect the individual raw alerts that make up the incident lineage.

10
MCQmedium

An analyst wants to flag a particular high-priority incident so that other shift analysts immediately notice it when they log in. What is the most direct feature to use?

A.Alert exclusion rule
B.Syslog forwarding profile
C.Data stitching configuration
D.Incident starring
AnswerD

Starring flags the incident for team visibility and filterability.

Why this answer

Starring an incident marks it for visibility and easy filtering across the SOC team.

11
Multi-Selectmedium

Which TWO features assist an analyst in prioritizing which incidents to investigate first within the Cortex XDR console? (Choose two)

Select 2 answers
A.Incident Starring indicators
B.Data stitching status logs
C.Agent version compliance meters
D.Incident Score / Severity ranking
E.Featured fields display order
AnswersA, D

Starring flags critical cases for team visibility and priority review.

Why this answer

Analysts prioritize incidents using the Incident Score (severity) and Incident Starring for bookmarked high-priority items.

12
MCQmedium

An administrator wants to ensure that Cortex XDR agents automatically update their software version whenever a new version is released by Palo Alto Networks. Where is this automated agent upgrade setting configured?

A.Settings > Configurations > Agent Settings > Upgrades
B.Help > About > Check for Updates
C.Response > Actions > Push Update
D.Data Collector > Broker VM > Software Distribution
AnswerA

Automated agent upgrade policies are defined within the Agent Settings configuration profiles.

Why this answer

Agent upgrade settings are managed within the Agent Settings profiles in the Cortex XDR console.

13
MCQeasy

When reviewing the Incident View, an analyst notices an incident with an orange severity badge. What does this severity level typically indicate in Cortex XDR?

A.Critical severity incident requiring immediate containment
B.High severity incident
C.Low priority false positive
D.Informational event requiring no action
AnswerB

Orange corresponds to High severity incidents requiring prompt review.

Why this answer

Cortex XDR uses standard severity levels (Low, Medium, High, Critical) represented by color-coded badges, where orange typically denotes High severity.

14
MCQmedium

An analyst identifies a malicious persistence mechanism utilizing a Run registry key. After removing the threat, the analyst wants to verify whether any other machines have this exact registry key populated. Which tool should the analyst use?

A.Syslog server forwarding destination list
B.XQL Search querying registry event tables
C.Cortex XDR Agent installation log
D.GlobalProtect client configuration wizard
AnswerB

XQL search supports querying registry telemetry tables to scope persistence mechanisms across endpoints.

Why this answer

XQL Search allows analysts to query registry modification events across the entire fleet of endpoints to hunt for persistence mechanisms.

15
MCQeasy

When reviewing an incident, an analyst wants to assign ownership to themselves. Which action should the analyst take?

A.Star the incident and export it to syslog
B.Assign the incident to their user account in the Incident View
C.Change the data stitching profile name
D.Add a featured field with their username
AnswerB

Assigning ownership ensures accountability and tracks who is investigating the incident.

Why this answer

Assigning an incident to an analyst updates the incident ownership field in the Cortex XDR console.

16
MCQmedium

An organization has strict egress filtering rules. Which destination URLs or IP ranges must be whitelisted in the corporate firewall to allow the Cortex XDR agent to communicate with the Cortex XDR cloud service?

A.A static list of Palo Alto Networks global headquarters IP addresses
B.Only local internal DNS servers
C.Public NTP servers only
D.The specific regional Cortex XDR tenant FQDNs and update distribution domains
AnswerD

Agents must reach their assigned regional tenant FQDNs and content update servers over HTTPS.

Why this answer

Cortex XDR agents require outbound HTTPS access to the specific regional Cortex XDR cloud tenant URLs provided by Palo Alto Networks.

17
MCQeasy

An analyst is reviewing identity analytics data in Cortex XDR and notices an impossible travel alert for a user account. Which evidence artifact should the analyst primarily inspect to validate the login locations?

A.Network packet capture (PCAP)
B.Master Boot Record (MBR) analysis
C.Identity and authentication logs
D.Endpoint memory dump
AnswerC

Authentication logs supply the timestamps, source IP addresses, and user identifiers needed to evaluate impossible travel scenarios.

Why this answer

Log data containing IP addresses, user agent strings, and geo-location metadata provides the source of truth for identity analytics and impossible travel alerts.

18
MCQhard

An attacker compromises a domain user account and attempts to enumerate domain admins using native Windows utilities (e.g., 'net group "Domain Admins" /domain'). Which Cortex XDR detection mechanism is specifically designed to catch such reconnaissance behaviors without relying solely on static signatures?

A.WildFire file quarantine settings
B.DNS sinkholing profiles
C.Cloud Identity Provider Conditional Access policies
D.Behavioral Indicator of Compromise (BIOC) rules tuned for suspicious command-line execution and reconnaissance patterns
AnswerD

BIOCs evaluate command-line execution telemetry to detect native utility abuse for domain reconnaissance.

Why this answer

BIOCs (Behavioral Indicators of Compromise) and Analytics rules detect malicious command-line patterns and behavioral anomalies associated with domain enumeration tools.

19
MCQeasy

An administrator is reviewing compromised credentials in Cortex XDR. Where should they navigate to inspect identity analytics alerts specifically generated by user behavior analytics (UBA)?

A.Cloud > Posture > Identity
B.Incident Response > Alerts, filtering by Analytics category related to Identity
C.XQL Search > Identity_Raw schema
D.Endpoints > Agent Configurations > Identity
AnswerB

The Alerts view allows filtering by Analytics categories to identify UBA-driven identity threats.

Why this answer

Cortex XDR consolidates identity-based threats and user behavior analytics within the Incident Response and Alerts views, specifically filtered by analytics categories such as compromised credentials.

20
Multi-Selecthard

An analyst wants to ensure that a newly discovered legitimate application is excluded from Cortex XDR behavioral analysis without compromising overall security. Which THREE steps or considerations are essential? (Choose three)

Select 3 answers
A.Verify the digital signature and publisher of the application
B.Disable all Cortex XDR agent security modules across the entire enterprise
C.Remove all file access permissions from the operating system kernel
D.Restrict the exception path to the specific application installation directory
E.Test the exception in a staging agent group before applying it organization-wide
AnswersA, D, E

Ensuring the binary is digitally signed by a trusted publisher validates authenticity.

Why this answer

Safe exception implementation involves validating binary integrity, verifying legitimate paths, and testing prior to global deployment.

21
MCQmedium

During incident response, an analyst isolates a host using Cortex XDR. The user on the machine reports that they can no longer reach internal file shares, but the analyst still has visibility and control over the agent. How is this achieved?

A.The agent maintains a dedicated management communication channel to the Cortex XDR server while blocking other network traffic.
B.The host switches to a backup dial-up modem connection.
C.All network traffic is routed through an open public proxy server.
D.The host disables its TCP/IP stack entirely.
AnswerA

Isolation restricts standard network access while preserving the control plane channel for administrative management.

Why this answer

Endpoint isolation blocks all general network traffic while maintaining a secure, dedicated management channel between the Cortex XDR agent and the backend server.

22
Multi-Selecthard

What THREE outcomes typically occur when data stitching successfully links a network alert and an endpoint alert? (Choose three)

Select 3 answers
A.Featured fields are wiped out and reset to default
B.The timeline reflects a complete attack path across network and endpoint
C.Both alerts are consolidated into a single unified incident
D.All constituent raw alerts are automatically starred
E.The overall incident score is recalculated based on the combined evidence
AnswersB, C, E

The incident timeline integrates network and endpoint events chronologically.

Why this answer

Successful data stitching results in a unified incident containing both alerts, an updated aggregate incident score, and enriched asset visibility in the timeline.

23
MCQmedium

An analyst notices suspicious network connections originating from an unknown process on an endpoint. To block outbound communication for this process without isolating the entire host, what action can be taken?

A.Unplug the physical power cable from the workstation
B.Change the local monitor refresh rate
C.Terminate the process and block its file hash or path
D.Reset the enterprise DNS root servers
AnswerC

Terminating the process and blocking its execution prevents the malicious process from running and establishing network sessions.

Why this answer

Network rules or process blocking actions in Cortex XDR can restrict malicious processes from communicating over the network while allowing normal OS operations.

24
Multi-Selecteasy

Which TWO details are typically reviewed when inspecting an alert in the Cortex XDR Incident Viewer? (Choose two)

Select 2 answers
A.Timestamp of when the event occurred
B.Local cafeteria lunch receipt totals
C.Alert description and detection rule name
D.Corporate travel booking itineraries
E.Office building parking garage gate codes
AnswersA, C

Timestamps establish the exact timing of the suspicious activity.

Why this answer

Alert inspection involves reviewing detection descriptions, timestamps, affected hosts, and associated MITRE mappings.

25
Multi-Selecthard

An enterprise is facing credential stuffing attacks targeting its cloud and on-premises applications. Which TWO detection or mitigation strategies within Cortex XDR and integrated tools help address this threat?

Select 2 answers
A.Analytics rules detecting high-frequency failed login attempts across multiple accounts from distributed source IPs
B.Modifying screen saver timeout intervals via Group Policy
C.Configuring printer sharing permissions on all Windows 10 endpoints
D.Enabling USB mass storage device blocking
E.Integrating cloud identity provider logs to monitor sign-in risk policies and automated lockout thresholds
AnswersA, E

Credential stuffing generates mass failed logons from varied IP sources, which analytics rules detect.

Why this answer

Credential stuffing can be detected via analytics identifying high volumes of failed logins from distinct external IPs, and mitigated via identity provider conditional access or automated account locking.

26
Multi-Selecteasy

Which TWO log sources are commonly ingested into Cortex XDR to support Identity Threat Detection and Response (ITDR)?

Select 2 answers
A.BIOS Firmware Update Logs
B.Cloud Identity Provider Sign-in Logs (e.g., Microsoft Entra ID)
C.Display Resolution Configuration Logs
D.Windows Security Event Logs
E.Printer Spooler Error Logs
AnswersB, D

Cloud sign-in logs extend identity visibility to SaaS and hybrid cloud environments.

Why this answer

Windows Security Event Logs and Cloud Identity Provider logs (such as Entra ID or Okta) are primary sources for ITDR in Cortex XDR.

27
Multi-Selectmedium

Which TWO evidence sources help an analyst investigate whether an unauthorized user accessed a compromised workstation locally? (Choose two)

Select 2 answers
A.Corporate vehicle fleet GPS tracking logs
B.Windows Security Event logs (Event IDs for logon successes and failures)
C.Office cafeteria refrigerator temperature charts
D.Office janitorial cleaning supply invoices
E.User session and authentication telemetry in Cortex XDR
AnswersB, E

Security logs record interactive, RDP, and network logon events.

Why this answer

Local workstation access investigations rely on Windows Security Event logs (Logon/Logoff events) and user session telemetry.

28
Multi-Selecteasy

Which TWO actions are available to an analyst when managing an incident's assignment in Cortex XDR? (Choose two)

Select 2 answers
A.Assign the incident to a specific analyst user account
B.Update corporate stock market ticker symbols
C.Re-route office mail delivery to a new address
D.Change corporate office building security guard shifts
E.Assign the incident to a specific SOC analyst group or tier
AnswersA, E

Assignment ensures ownership and accountability for investigating the incident.

Why this answer

Incidents can be assigned to specific analysts or SOC user groups for investigation and accountability.

29
Multi-Selectmedium

An administrator is configuring Active Directory integration with Cortex XDR using the Broker VM. Which TWO prerequisites or components are required to successfully establish User-ID mapping and synchronization?

Select 2 answers
A.A dedicated service account in Active Directory with read permissions to query user and group objects
B.A physical hardware token connected to the Broker VM USB port
C.Direct SSH root access to every Active Directory Domain Controller
D.Installation of the Cortex XDR Agent on all Domain Controllers as a mandatory prerequisite
E.Network connectivity from the Broker VM to Domain Controllers over TCP port 389 (LDAP) or 636 (LDAPS)
AnswersA, E

A service account is required for the Broker VM to query Active Directory.

Why this answer

AD integration via Broker VM requires LDAP/LDAPS connectivity to domain controllers and valid service account credentials.

30
MCQhard

During incident triage, an analyst notices that two completely separate attacks on different endpoints were merged into a single incident by Cortex XDR. What is the underlying reason for this over-correlation?

A.All alerts were manually starred by an analyst
B.The incident scoring threshold was set too low
C.Featured fields were configured to group by IP subnet
D.Shared common identifiers such as a NAT gateway IP address within the correlation window
AnswerD

Shared infrastructure like NAT gateways can cause the engine to falsely stitch unrelated activity.

Why this answer

Over-correlation typically occurs when disparate alerts share a common indicator (such as a shared NAT gateway IP address or a generic proxy server) within the same time window, tricking the stitching engine.

31
Multi-Selecthard

An administrator is planning an agent rollout and needs to configure agent profiles in the Cortex XDR management console. Which THREE configuration elements can be defined within an Agent Settings profile?

Select 3 answers
A.Proxy server configuration for agent communication traversal
B.GlobalProtect VPN gateway tunnel encryption algorithms
C.Exclusions for specific paths, processes, or file hashes
D.Physical firewall interface IP addresses and routing tables
E.Operational mode (e.g., Normal, Detect-only, or Disabled)
AnswersA, C, E

Proxy configurations are specified within the agent settings profile.

Why this answer

Agent Settings profiles control operational settings such as operational mode, scan schedules, proxy settings, and exclusion rules.

32
MCQhard

An administrator is troubleshooting a Broker VM that has lost connectivity to the Cortex XDR cloud tenant. After logging into the Broker VM CLI, which command should the administrator use to test connectivity and troubleshoot DNS/HTTPS communication to the cloud backend?

A.traceroute -m 64 gateway
B.show broker status and test connection
C.ping -t customer.paloaltonetworks.com
D.tail -f /var/log/pan_broker_vm.log
AnswerB

The Broker VM CLI provides specific operational commands like 'show' and connectivity test utilities.

Why this answer

The Broker VM CLI provides specific troubleshooting commands, including network diagnostics and connectivity tests to verify cloud reachability.

33
MCQeasy

An analyst wants to quickly identify all alerts related to a specific external IP address across multiple incidents without opening each incident individually. Which feature in the Cortex XDR console should the analyst use?

A.Incident scoring threshold filter
B.Featured fields sorting
C.Data stitching status toggle
D.Alerts View filter and search capabilities
AnswerD

The Alerts View supports granular filtering by IP, hash, user, and other parameters across the environment.

Why this answer

Global search or filtering within the Alerts View allows analysts to query specific IOCs, IPs, or hashes across all incidents and alerts.

34
Multi-Selecteasy

Which TWO metrics or components are typically included in a user's risk score calculation within Cortex XDR's identity analytics?

Select 2 answers
A.Severity and count of triggered behavioral analytics alerts
B.Manufacturer of the user's computer monitor
C.Total number of desktop wallpaper images stored by the user
D.Frequency and volume of failed authentication attempts
E.Average length of time the user spends on lunch breaks
AnswersA, D

Analytics alerts (such as impossible travel or abnormal access) directly impact user risk scores.

Why this answer

User risk scores incorporate failed authentication attempts and alerts triggered by anomalous behavioral patterns.

35
MCQmedium

An analyst notices that a malicious binary dropped multiple secondary payloads and modified registry keys. The analyst decides to initiate a remediation action to undo these changes. Which Cortex XDR capability supports automatic remediation of file drops and registry modifications?

A.DNS Flushing
B.DHCP Lease Renewal
C.Static Route Addition
D.Remediate Action (Cleanup)
AnswerD

The Remediate action automatically rolls back changes made by malicious processes, including file drops and registry edits.

Why this answer

Remediation in Cortex XDR can automatically clean up artifacts such as created files, registry modifications, and processes associated with a malicious execution.

36
Multi-Selecthard

An analyst is investigating an advanced persistent threat (APT) that established persistence using multiple techniques. Which THREE persistence mechanisms should the analyst specifically check via Cortex XDR telemetry? (Choose three)

Select 3 answers
A.Office desk relocation requests
B.Breakroom coffee machine maintenance schedules
C.Windows Scheduled Tasks
D.Windows Services creation and modification
E.Registry Run and RunOnce keys
AnswersC, D, E

Scheduled tasks execute malicious payloads at specified times or system triggers.

Why this answer

Common endpoint persistence mechanisms include Run keys, scheduled tasks, and Windows services.

37
MCQeasy

Which architectural component acts as the central repository for all Cortex XDR telemetry, logs, and behavioral data?

A.Local Agent SQLite Cache
B.Panorama Log Collector Appliance
C.Cortex Data Lake
D.Broker VM Internal Hard Disk
AnswerC

The Cortex Data Lake stores all ingested logs, telemetry, and forensics data.

Why this answer

The Cortex Data Lake is the cloud-based repository that stores all enterprise telemetry and logs for Cortex XDR.

38
MCQeasy

When configuring Cortex XDR agent permissions on macOS, what step is necessary due to macOS security restrictions (Transparency, Consent, and Control - TCC)?

A.Configuring an Apple Developer ID certificate in Keychain Access
B.Installing a custom kernel extension compiled locally using Xcode
C.Approving System Extensions, Full Disk Access, and Network Filter permissions via MDM or user prompt
D.Disabling System Integrity Protection (SIP) entirely on every Mac
AnswerC

macOS security frameworks require explicit authorization for system extensions and full disk access.

Why this answer

macOS requires users or MDM profiles to grant Full Disk Access and network filter permissions to the Cortex XDR agent.

39
MCQeasy

An analyst wants to view all security events associated with a specific user account across multiple devices over the last 7 days. Which Cortex XDR module provides user-centric investigation capabilities?

A.Disk Encryption status panel
B.Agent Health dashboard
C.BIOC Policy editor
D.User Investigation view
AnswerD

User Investigation is specifically designed to correlate activities and alerts tied to a specific user identity.

Why this answer

The User Investigation view in Cortex XDR aggregates user activity, authentication events, and associated alerts across endpoints and cloud environments.

40
MCQeasy

What role does the Cortex XDR Broker VM play regarding Active Directory and ITDR log collection?

A.It acts as a collector appliance to ingest and forward syslog, WMI, and Active Directory logs to Cortex XDR
B.It stores long-term forensic disk images of all enterprise workstations
C.It replaces the domain controller operating system
D.It functions as an external Next-Generation Firewall
AnswerA

Broker VM is deployed on-premises to ingest and securely transmit AD and log data to the Cortex XDR tenant.

Why this answer

Broker VM serves as an internal collector appliance that polls or receives syslog/WMI/LDAP data from on-premises infrastructure like Active Directory and forwards it to Cortex XDR.

41
MCQeasy

An analyst is investigating an alert and wants to check if the file was analyzed by WildFire. Where in the Cortex XDR console can the analyst view the WildFire sandbox verdict and analysis report?

A.DHCP Server status log
B.File Details / WildFire Analysis tab
C.DNS query statistics panel
D.Printer queue management interface
AnswerB

File inspection views display comprehensive WildFire sandbox analysis results, behaviors, and verdicts.

Why this answer

The WildFire analysis report and verdict are accessible directly from the file details or alert inspection panel within Cortex XDR.

42
Multi-Selecthard

An organization wants to configure Cortex XDR to automatically respond to high-severity ransomware alerts. Which THREE elements must be correctly configured to ensure successful automated mitigation? (Choose three)

Select 3 answers
A.Response Playbook configured with ransomware detection triggers
B.Manual adjustment of office lighting dimmer switches
C.Manual postal mail notification to external regulatory bodies
D.Appropriate response actions defined in the playbook (e.g., Isolate Endpoint, Kill Process)
E.Active management connectivity between endpoints and the Cortex XDR backend
AnswersA, D, E

Playbooks must be configured to listen for and trigger on ransomware detection alerts.

Why this answer

Automated ransomware mitigation requires active agent connectivity, properly configured response playbooks, and appropriate containment actions such as isolation or process termination.

43
MCQmedium

An analyst is investigating an incident and needs to quickly view customized columns containing threat actor attribution tags in the incident grid. Which feature must be configured to show these columns?

A.Data stitching parameters
B.Featured fields configuration
C.Raw alert priority rules
D.Incident scoring weights
AnswerB

Featured fields let analysts select which attributes appear as dedicated columns in the UI.

Why this answer

Featured fields allow security teams to customize grid views with specific metadata fields relevant to their operational needs.

44
MCQeasy

What is the primary function of Cortex XDR Agent prevention modules (such as Anti-Malware and Exploit Protection)?

A.To generate weekly compliance PDF reports for external auditors
B.To actively block and remediate threats such as malware, exploits, and ransomware execution on the endpoint
C.To monitor bandwidth usage across enterprise switch ports
D.To automatically patch third-party software vulnerabilities like Adobe Reader
AnswerB

Prevention modules stop malicious activities before or during execution.

Why this answer

Prevention modules block known and unknown malware, exploits, and ransomware execution in real-time on the endpoint.

45
MCQhard

When configuring a Response Playbook in Cortex XDR to automatically remediate an incident, what condition must be met for the playbook to execute successfully on an endpoint?

A.The endpoint agent must be online and connected to receive the command.
B.The user must manually approve every automated step in the playbook.
C.The endpoint must have local administrative privileges disabled.
D.The endpoint must be running a legacy operating system without secure boot.
AnswerA

Real-time remediation actions require an active management connection between the backend and the endpoint agent.

Why this answer

Automated response playbooks require the Cortex XDR agent to be actively connected and online to receive and execute commands such as isolation or file quarantine.

46
MCQeasy

Which role-based permission is typically required for an analyst to change the status of an incident from 'New' to 'Under Investigation' in Cortex XDR?

A.Data stitching configuration role
B.Cortex XDR Analyst role
C.Syslog forwarding administrator
D.Collector installation role
AnswerB

The XDR Analyst role includes permissions to triage, investigate, and update incident statuses.

Why this answer

Incident management actions such as status changes and assignment require appropriate analyst or administrator roles with incident handling permissions.

47
Multi-Selecthard

An administrator is configuring Broker VM network settings and firewall rules in a secure data center zone. Which THREE traffic flows must be permitted through internal firewalls for the Broker VM to function correctly?

Select 3 answers
A.Outbound BitTorrent peer-to-peer traffic for software distribution
B.Inbound Remote Desktop Protocol (RDP) from all internet IP addresses directly to the Broker VM
C.Inbound Syslog (TCP/UDP 514 or custom ports) from network devices to the Broker VM Syslog collector
D.Inbound and outbound LDAP/LDAPS (TCP 389/636) between the Broker VM and Active Directory Domain Controllers
E.Outbound HTTPS (TCP 443) from the Broker VM to the Cortex XDR cloud tenant and content delivery networks
AnswersC, D, E

Network devices send syslog messages to the Broker VM collector.

Why this answer

Broker VM requires outbound HTTPS to the cloud, inbound Syslog/AD traffic from local sources, and DNS resolution.

48
Multi-Selecthard

When conducting a comprehensive post-incident review and remediation verification in Cortex XDR, which THREE actions should an analyst perform? (Choose three)

Select 3 answers
A.Review and document lessons learned, updating detection rules or playbooks as needed
B.Verify that all compromised endpoints report healthy agent status and no active malicious processes
C.Permanently uninstall Cortex XDR agents from all enterprise endpoints
D.Ensure that temporary containment measures (like endpoint isolation) are lifted once remediation is complete
E.Delete all historical telemetry databases to save disk space permanently
AnswersA, B, D

Post-incident analysis improves future defenses and detection engineering.

Why this answer

Post-incident review includes verifying threat eradication, ensuring agent health, and updating detection rules or exceptions.

49
Multi-Selectmedium

An administrator is planning the deployment of Broker VM instances across a multi-site enterprise network. Which TWO best practices should be followed when planning Broker VM deployments?

Select 2 answers
A.Install the Broker VM directly on user workstations running Windows 10 Pro
B.Deploy Broker VM instances locally at remote sites or data centers to aggregate logs and reduce WAN bandwidth consumption
C.Configure the Broker VM to store all enterprise log data locally on its virtual disk permanently for 7 years
D.Ensure proper sizing and resource allocation (vCPU and RAM) based on the expected event-per-second (EPS) load
E.Share a single Broker VM instance across 50,000 global endpoints separated by high-latency WAN links
AnswersB, D

Deploying Broker VMs locally at remote locations minimizes WAN traffic for log collection and agent proxying.

Why this answer

Broker VMs should be deployed locally at major remote sites to reduce WAN traffic, and high availability or multiple instances should be considered for redundancy.

50
MCQeasy

What is the status of an incident in Cortex XDR immediately after it is automatically created by the correlation engine?

A.New
B.Closed
C.Under Investigation
D.Resolved
AnswerA

New incidents start in the 'New' state awaiting triage.

Why this answer

Newly created incidents default to the 'New' status until an analyst takes ownership and updates the status.

51
MCQeasy

An analyst receives an incident containing multiple related alerts across different machines. What is the primary benefit of the Cortex XDR Incident Viewer grouping these alerts together?

A.It automatically upgrades endpoint operating system licenses.
B.It deletes duplicate log files to save storage space.
C.It reduces alert fatigue by grouping related alerts into a single attack storyline.
D.It provisions new virtual machines for containment.
AnswerC

Incident correlation aggregates disparate telemetry into unified incidents to reflect the broader campaign.

Why this answer

Incident grouping correlates related alerts into a single incident based on causality and shared artifacts, reducing alert fatigue and providing a cohesive attack narrative.

52
MCQmedium

An administrator notices that legitimate administrative scripts are repeatedly generating low-level behavioral alerts, cluttering the incident queue. How should the administrator handle these raw alerts within the lifecycle framework?

A.Create an alert exclusion or exception rule
B.Manually star all related alerts
C.Increase the data stitching window
D.Modify featured fields to hide script alerts
AnswerA

Exclusion rules prevent benign scripts from triggering raw alerts and subsequent incidents.

Why this answer

Administrators can create alert tuning or exclusion rules to filter out known benign activities so they do not generate unnecessary raw alerts or incidents.

53
MCQeasy

An XDR Analyst is investigating a newly generated incident in Palo Alto Networks Cortex XDR and notices that multiple disparate alerts from different endpoints and network sensors have been automatically grouped together. Which core mechanism of Cortex XDR is primarily responsible for intelligently grouping these related alerts into a single incident?

A.Alert starring
B.Local Analysis agent configuration
C.Incident scoring and analytics correlation engine
D.BIOC rule generation wizard
AnswerC

The incident scoring and analytics correlation engine automatically stitches and groups related alerts into a single incident based on indicators and causality.

Why this answer

Cortex XDR uses a specialized analytics engine and data stitching algorithms to correlate and group related alerts across endpoints, network, and cloud sources into a single incident based on shared indicators of compromise or causality chains.

54
Multi-Selectmedium

Which TWO factors directly influence how Cortex XDR calculates the overall severity score of an incident? (Choose two)

Select 2 answers
A.The severity levels of the constituent raw alerts
B.The number of featured fields enabled in the UI
C.The criticality weighting of the affected assets
D.The frequency of manual alert starring by analysts
E.The syslog forwarding port configuration
AnswersA, C

Raw alert severities feed directly into the aggregate incident scoring formula.

Why this answer

Incident scores are calculated based on the severity of the constituent raw alerts and the criticality of the affected assets.

55
Multi-Selecthard

What THREE conditions can cause data stitching failures between network logs and endpoint telemetry in Cortex XDR? (Choose three)

Select 3 answers
A.Significant time skew or clock desynchronization between data sources
B.Starring the endpoint alerts during triage
C.Unmapped or inconsistent user identity formats across systems
D.Events occurring outside the predefined data stitching time window
E.Enabling featured fields for the network log source
AnswersA, C, D

Time skew breaks temporal correlation windows required for stitching.

Why this answer

Data stitching can fail due to clock desynchronization, missing or unmapped user/IP identifiers, or events falling outside the correlation time window.

56
Multi-Selecteasy

Which TWO pieces of information are displayed in the Incident summary dashboard of Cortex XDR? (Choose two)

Select 2 answers
A.Overall incident severity distribution
B.Cellular phone network tower signal strengths
C.Local employee salary payroll database records
D.Total number of affected hosts and endpoints
E.Commercial airline flight booking schedules
AnswersA, D

Severity breakdown helps triage high-priority incidents.

Why this answer

The Incident summary provides high-level metrics such as total incident count, severity distribution, and affected host counts.

57
Multi-Selecthard

When managing exclusions and exceptions in Cortex XDR, which THREE best practices should an analyst follow to maintain security posture? (Choose three)

Select 3 answers
A.Share internal exception hashes publicly on open social media channels
B.Scope exceptions as narrowly as possible (e.g., specific hash and path)
C.Document the business justification and ticket reference for every exception created
D.Periodically review and audit existing exceptions to ensure they are still necessary
E.Disable all default Cortex XDR BIOC rules globally upon deployment
AnswersB, C, D

Narrow scoping prevents overly broad exceptions from creating security blind spots.

Why this answer

Effective exception management requires scoping rules tightly, documenting justifications, and reviewing exceptions periodically.

58
MCQhard

An incident in Cortex XDR contains dozens of low-priority alerts that were grouped together. The analyst determines that one specific alert within the incident is a false positive while the rest are legitimate threats. What is the best practice for handling this specific raw alert?

A.Change the incident score to zero to hide all alerts
B.Delete the entire incident and recreate it manually
C.Apply an alert starring filter to exclude the false positive
D.Mark the specific raw alert as a false positive or dismiss it within the incident view
AnswerD

Cortex XDR allows granular management of individual raw alerts inside an incident.

Why this answer

Analysts can manage individual alerts within an incident, suppressing or tuning specific detectors or marking individual alerts as false positives without discarding the entire incident.

59
Multi-Selecteasy

Which TWO features in Cortex XDR assist an analyst in scoping an incident across the entire enterprise? (Choose two)

Select 2 answers
A.Mouse pointer speed settings
B.Audio speaker volume mixer
C.Global Indicator Search / Threat Hunting
D.Physical keyboard backlight color adjuster
E.XQL Search (Query Builder)
AnswersC, E

Threat hunting features allow checking if a hash or IP appears anywhere in the environment.

Why this answer

Enterprise scoping is accomplished using XQL search and global threat hunting tools.

60
Multi-Selecteasy

When reviewing an incident in Cortex XDR, which TWO types of artifacts are commonly available for inspection within the alert details? (Choose two)

Select 2 answers
A.IP Connection (Source/Destination IP and Port)
B.Physical RAM stick serial number
C.Office printer cartridge ink level
D.File hash (SHA-256)
E.BIOS manufacturer date
AnswersA, D

Network connection artifacts are routinely recorded and displayed for alerts involving network activity.

Why this answer

Cortex XDR incident and alert views capture various telemetry artifacts, notably file hashes and network connection details.

61
MCQmedium

An analyst is reviewing an identity incident where an attacker performed a Kerberoasting attack. Which log source ingested by Cortex XDR is most critical for detecting requests for service tickets against high-privilege service principal names (SPNs)?

A.Antivirus scan reports
B.DNS query logs showing external root hints
C.Windows Security Event logs (specifically Event ID 4769) collected via Broker VM
D.DHCP lease allocation tables
AnswerC

Event ID 4769 captures Kerberos TGS requests, which are analyzed to identify potential Kerberoasting activity.

Why this answer

Kerberoasting is detected by analyzing Windows Security Event log ID 4769 (A Kerberos service ticket was requested), specifically looking for high encryption downgrade requests (e.g., RC4).

62
MCQmedium

An administrator is preparing to deploy Cortex XDR agents using an enterprise software deployment tool (such as SCCM or Intune). Where can the administrator download the appropriate installation packages (.msi or .pkg) from the Cortex XDR management console?

A.Data Collector > Broker VM > Agent Packages
B.Incidents > Actions > Export Agent
C.Settings > Configurations > Endpoint Settings > Install Packages
D.Monitoring > System Health > Agent Distribution
AnswerC

The Install Packages menu allows administrators to build and download tailored agent installers.

Why this answer

Installation packages and transform files are accessed via Settings > Configurations > Endpoint Settings > Install Packages in the Cortex XDR console.

63
MCQmedium

An analyst needs to gather a memory dump and running process list from a remote endpoint for deep forensic analysis. Which Cortex XDR feature enables this collection?

A.Retrieve File and Forensic File Collection
B.Global Protect Tunnel Inspection
C.Agent Upgrade Schedule
D.WildFire Submission Policy
AnswerA

Forensic and file retrieval features allow pulling artifacts from the endpoint for offline or deep inspection.

Why this answer

Cortex XDR allows analysts to trigger forensic data collection, including file retrieval and process information, directly from the incident response tools.

64
MCQhard

An administrator needs to deploy Cortex XDR agents to a fleet of Linux servers running Ubuntu 20.04. Before executing the installation script, which prerequisite package must be verified as installed on the Linux endpoints to ensure kernel module or Extended Berkeley Packet Filter (eBPF) support functions correctly?

A.Microsoft .NET Framework 4.8 Runtime
B.IIS Web Server Role and ASP.NET
C.Active Directory Domain Services Client tools
D.Kernel headers and dependent build tools matching the running kernel version
AnswerD

Linux kernel modules require matching kernel headers for successful compilation/load.

Why this answer

Linux agents rely on standard kernel headers, build essentials, or specific utilities depending on whether kernel modules or eBPF are utilized.

65
MCQmedium

An organization wants to ensure that all administrative logon sessions are closely monitored for anomalous behaviors in Cortex XDR. Where should the administrator configure custom behavioral alert thresholds for privileged users?

A.Response > Playbooks > Designer
B.Settings > Analytics > Analytics Rules / Thresholds
C.Cloud > Settings > CSPM
D.Endpoints > Agent Configurations > Profile
AnswerB

Analytics configuration menus allow administrators to tune behavioral thresholds and detection rules.

Why this answer

Custom behavioral analytics settings and threshold configurations for user risk and analytics are managed within the Analytics configuration section of Cortex XDR.

66
MCQhard

An organization experiences a Golden Ticket attack. How does Cortex XDR's identity analytics engine typically detect this type of Kerberos ticket manipulation?

A.By monitoring USB mass storage insertion events
B.By blocking outbound TCP port 80 traffic at the perimeter firewall
C.By scanning the master boot record (MBR) of the endpoint for rootkit signatures
D.By detecting anomalies in Kerberos authentication attributes such as unusual ticket lifetimes or mismatched SID history from domain controller telemetry
AnswerD

Golden tickets exhibit abnormal attributes like forged lifetimes and SID structures that security event logs and analytics can identify.

Why this answer

Golden Ticket attacks forge Kerberos TGTs with arbitrary lifespans and SIDs. Cortex XDR detects this by correlating anomalous ticket attributes, such as invalid SID history or ticket lifetimes exceeding domain policy, captured from domain controller logs.

67
Multi-Selectmedium

Which TWO tasks can be performed directly from the Incident View in Cortex XDR? (Choose two)

Select 2 answers
A.Update the incident status (e.g., New to Under Investigation)
B.Build global dashboard metric widgets
C.Assign incident ownership to specific analysts
D.Install Cortex XDR agents on remote endpoints
E.Configure custom data stitching parser scripts
AnswersA, C

Status updates are core triage actions performed in the Incident View.

Why this answer

Analysts can change incident statuses and assign ownership directly from the Incident View.

68
MCQeasy

When investigating an identity-based alert in Cortex XDR, what information does the User View provide to the analyst?

A.Comprehensive profile information including recent alerts, associated devices, and identity attributes
B.Real-time packet captures of the user's active browsing session
C.The hardware warranty status of endpoints assigned to the user
D.Group Policy Object (GPO) editing capabilities
AnswerA

The User View is specifically designed to provide a holistic risk and context profile for a given identity.

Why this answer

The User View in Cortex XDR aggregates user-centric data, including associated endpoints, active directory attributes, risk scores, and correlated alerts.

69
MCQeasy

What is the primary function of the Cortex XDR Agent Support File collection tool?

A.To collect diagnostic logs, configuration details, and troubleshooting data for Palo Alto Networks Support
B.To generate a forensic disk image of the entire hard drive
C.To back up the user's personal documents to the cloud data lake
D.To export endpoint cryptographic keys to an external vault
AnswerA

Support files aggregate diagnostic logs for troubleshooting agent issues.

Why this answer

The Support File collection tool gathers diagnostic logs and system states from the endpoint agent to assist Palo Alto Networks support in troubleshooting.

70
MCQeasy

Which dashboard widget type in Cortex XDR is best suited for tracking the volume of open incidents over time across different severity levels?

A.Syslog export status meter
B.Data stitching performance monitor
C.Agent health and connectivity graph
D.Incident trend and severity breakdown widgets
AnswerD

These widgets provide visual metrics on open incidents categorized by severity.

Why this answer

Incident trend and severity widgets in Cortex XDR dashboards display historical and real-time metrics categorized by severity levels.

71
Multi-Selectmedium

An administrator is reviewing the Cortex XDR system requirements and architecture. Which TWO statements accurately describe the Broker VM architecture?

Select 2 answers
A.The Broker VM is installed directly on individual macOS endpoints as a kernel extension
B.The Broker VM runs as a virtual appliance on supported hypervisors such as VMware ESXi, KVM, AWS, or Azure
C.The Broker VM hosts modular Cortex XDR apps such as Syslog Collector, Active Directory, and agent proxying
D.The Broker VM replaces the Cortex Data Lake as the primary long-term log storage repository for the entire enterprise
E.The Broker VM requires a physical server with at least 128 cores and 1TB of RAM
AnswersB, C

Broker VM is distributed as virtual appliance images for major hypervisors and clouds.

Why this answer

Broker VM is a virtual appliance running on supported hypervisors that acts as an aggregator, proxy, and collector app host.

72
Multi-Selectmedium

An analyst is investigating an incident where a malicious file was dropped via email. Which TWO evidence artifacts should the analyst inspect to correlate the email vector with the endpoint execution? (Choose two)

Select 2 answers
A.Employee dental insurance benefit claim forms
B.Office building elevator maintenance inspection reports
C.Email gateway logs (sender, recipient, subject, and attachment name/hash)
D.Corporate cafeteria recipe preparation guidelines
E.Endpoint file drop and process execution events matching the attachment hash
AnswersC, E

Email logs identify how the malicious attachment entered the organization.

Why this answer

Correlating email vectors with endpoint execution involves analyzing email gateway logs and endpoint file drop events.

73
MCQmedium

An administrator is planning network bandwidth utilization for Cortex XDR agents deployed across 10,000 endpoints. Which mechanism does Cortex XDR use to minimize WAN bandwidth consumption during content updates and software upgrades?

A.Incremental, lightweight signature updates delivered dynamically over HTTPS
B.Mandatory FTP file transfer during off-peak midnight hours only
C.Peer-to-peer multicast streaming across all local subnets
D.Local caching and distribution exclusively through Domain Controllers via GPO
AnswerA

Content updates are incremental and small, minimizing bandwidth impact.

Why this answer

Content updates and signatures are lightweight, and proxy/Broker VM caching can further assist, though agents primarily download directly or via designated distribution mechanisms.

74
Multi-Selecthard

An administrator is preparing to install the Cortex XDR Agent on enterprise endpoints using a pre-installation script. Which THREE checks should be performed on the target endpoints before executing the installation?

Select 3 answers
A.Verify that the operating system version meets the minimum requirements supported by the current Cortex XDR agent release
B.Confirm outbound network connectivity over TCP port 443 to the regional Cortex XDR tenant FQDNs
C.Disable all local network interface cards permanently
D.Ensure that competing third-party endpoint security agents that may conflict with kernel hooks are uninstalled or properly configured
E.Reformat the local hard drive to use the FAT32 file system for compatibility
AnswersA, B, D

Checking OS compatibility prevents installation failures on unsupported platforms.

Why this answer

Before agent installation, administrators should verify OS compatibility, ensure no conflicting security software is present, and check network connectivity.

75
Multi-Selecthard

An administrator is troubleshooting a failed Cortex XDR agent installation on a Windows endpoint. Which THREE log locations or troubleshooting methods should the administrator examine to determine the root cause of the installation failure?

Select 3 answers
A.The Windows System and Application Event Logs for MSIInstaller or service creation errors
B.The agent installation log files located in the Windows %TEMP% directory or Cyvera installation logs
C.The Windows Installer verbose log generated during the installation process (e.g., using msiexec /i installer.msi /l*v install.log)
D.The BIOS firmware boot order configuration screen
E.The local router routing table via the arp -a command
AnswersA, B, C

Event logs record Windows Service control manager and installer events.

Why this answer

Windows agent installation logs can be found in the system TEMP directory, MSI installer verbose logs, and Cortex XDR installation logs.

Page 1 of 3

Page 2

All pages