XDR-Analyst Identity Threat Detection And Response Practice Question
When deploying and troubleshooting the integration between Cortex XDR and Active Directory for ITDR, which TWO steps or configurations are critical to ensure successful telemetry collection? (Choose two)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring the Cortex XDR Broker VM to receive and parse syslog or Windows event streams from domain controllers
Proper log forwarding via Broker VM/Collector and enabling precise Windows Security Audit policies on Domain Controllers are vital prerequisites for AD ITDR integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modifying the local BIOS boot order on every user workstation
Why it's wrong here
BIOS boot order has no bearing on Active Directory log collection.
- ✓
Configuring the Cortex XDR Broker VM to receive and parse syslog or Windows event streams from domain controllers
Why this is correct
The Broker VM is essential for collecting and forwarding logs from on-premises AD infrastructure to the Cortex data lake.
- ✓
Enabling advanced auditing policies (such as logon/logoff and account management auditing) on Domain Controllers
Why this is correct
Domain controllers must be configured to generate the required Security Event IDs for Cortex XDR to analyze.
- ✗
Installing the full Cortex XDR Agent kernel driver directly on all DNS root servers
Why it's wrong here
DNS root servers are typically managed infrastructure; Cortex XDR agents are deployed on supported endpoints and domain controllers via specialized configurations, not arbitrary DNS root servers.
- ✗
Disabling all firewall rules between endpoints and the Active Directory SYSVOL share
Why it's wrong here
Disabling firewall rules reduces security and is not required for ITDR telemetry collection.
About these practice questions
This XDR-Analyst question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This XDR-Analyst practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XDR-Analyst exam.