Courseiva
Identity Threat Detection And ResponsehardMultiple SelectObjective-mapped

XDR-Analyst Identity Threat Detection And Response Practice Question

When deploying and troubleshooting the integration between Cortex XDR and Active Directory for ITDR, which TWO steps or configurations are critical to ensure successful telemetry collection? (Choose two)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configuring the Cortex XDR Broker VM to receive and parse syslog or Windows event streams from domain controllers

Proper log forwarding via Broker VM/Collector and enabling precise Windows Security Audit policies on Domain Controllers are vital prerequisites for AD ITDR integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modifying the local BIOS boot order on every user workstation

    Why it's wrong here

    BIOS boot order has no bearing on Active Directory log collection.

  • Configuring the Cortex XDR Broker VM to receive and parse syslog or Windows event streams from domain controllers

    Why this is correct

    The Broker VM is essential for collecting and forwarding logs from on-premises AD infrastructure to the Cortex data lake.

  • Enabling advanced auditing policies (such as logon/logoff and account management auditing) on Domain Controllers

    Why this is correct

    Domain controllers must be configured to generate the required Security Event IDs for Cortex XDR to analyze.

  • Installing the full Cortex XDR Agent kernel driver directly on all DNS root servers

    Why it's wrong here

    DNS root servers are typically managed infrastructure; Cortex XDR agents are deployed on supported endpoints and domain controllers via specialized configurations, not arbitrary DNS root servers.

  • Disabling all firewall rules between endpoints and the Active Directory SYSVOL share

    Why it's wrong here

    Disabling firewall rules reduces security and is not required for ITDR telemetry collection.

About these practice questions

This XDR-Analyst question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This XDR-Analyst practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XDR-Analyst exam.