Courseiva

XDR-Engineer · topic practice

Detection And Reporting practice questions

Practise Certified XDR Engineer (XDR-Engineer) Detection And Reporting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Detection And Reporting

What the exam tests

What to know about Detection And Reporting

Detection And Reporting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Detection And Reporting exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Detection And Reporting questions

20 questions · select your answer, then reveal the explanation

An analyst notices that a custom BIOC rule is generating too many false positives during normal software deployments. What is the most appropriate next step in detection engineering for this rule?

An analyst wants to create a customized dashboard widget in Cortex XDR that displays the top 10 endpoints generating the highest volume of alerts over the last 7 days. Where should the analyst configure this widget?

An administrator needs to schedule a weekly PDF report of all critical endpoint incidents to email to the security operations team. Which Cortex XDR feature should be used to accomplish this?

A security engineer is building a Port Scanning BIOC detection rule. The rule needs to evaluate multiple sequential network connection failures from the same source IP within a rolling 60-second window. Which rule configuration type must the engineer select?

An analyst writes an XQL query to aggregate alert counts by severity and action, but the query returns a parsing syntax error.

dataset = xdr_data | filter causality_actor_process_image_name != null | comp count() by causality_actor_process_image_name

What is the correct XQL syntax correction needed to successfully execute this aggregation?

A security engineer is investigating a potential lateral movement technique using WMI. The engineer wants to query the XDR backend using XQL (XDR Query Language) to search for process executions spawned by wmic.exe across all endpoints. Which XQL dataset should the query target?

An enterprise has deployed Cortex XDR agents across Windows and Linux hosts. A security engineer notices that a specific custom BIOC rule is triggering successfully on Windows endpoints but fails to fire on Linux endpoints despite identical malicious commands being executed. What is the most likely cause?

An administrator wants to create a custom BIOC (Behavioral Indicator of Compromise) rule in Cortex XDR to detect unexpected execution of PowerShell scripts downloading files from the internet. Which tool within the Cortex XDR management console should the administrator use to write and test this logic?

An analyst wants to view the complete Attack Story (causality chain) of an incident to understand how an initial phishing email led to credential dumping. Where in the Cortex XDR console should the analyst navigate?

An administrator wants to verify whether Cortex XDR successfully collected telemetry from a newly installed agent. Which reporting or query tool can be used to quickly list all active agents and their last seen timestamp?

An engineer is writing an XQL query to investigate rare process executions. The query needs to calculate the distinct count of endpoints where each process image name was executed, filtering out processes that appeared on more than 50 hosts. Which XQL snippet correctly implements this filter after aggregation?

An organization requires all custom BIOC alerts to be automatically tagged with the label 'Tier-3-Investigation' and assigned directly to a specific escalation group. Where can an administrator configure this automatic handling?

An organization utilizes custom correlation rules in Cortex XDR. An engineer needs to export these custom BIOC rules to backup configurations or migrate them to another Cortex XDR tenant. Which administrative feature supports this?

An analyst is investigating an alert generated by Analytics where a user account executed an unusual command. The analyst wants to view all other actions performed by that same user across any endpoint during a 24-hour window. Which query technique in XQL best fulfills this requirement?

An administrator wants to configure local log retention settings and verify the ingestion rate of raw endpoint telemetry within Cortex XDR. Where can the administrator monitor platform license consumption and data ingestion metrics?

An organization needs to forward all Cortex XDR incidents and alerts to an external SIEM platform in real time. Which Cortex XDR feature should the administrator configure?

An administrator created a new BIOC detection rule, but test alerts are not appearing in the Incident triage view. Upon checking the rule status, it is active and enabled. What is a common reason why a valid BIOC rule might fail to generate alerts?

An analyst wants to write an advanced XQL query that correlates network connection events with process execution events using a common join key (`causality_id`). Which XQL command operator is used to combine two datasets based on a matching field?

An analyst is reviewing an incident where a suspicious process spawned a child process. The analyst wants to check if any other endpoint in the enterprise has ever executed this exact child process image file name combined with a specific command-line argument. Which search method is most efficient?

An organization experiences repeated false positive alerts from a specific legitimate administrative script that matches a built-in Cortex XDR behavioral Analytics detection. How should the administrator handle this built-in detection alert to prevent future false positives without disabling protection entirely?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Detection And Reporting sessions

Start a Detection And Reporting only practice session

Every question in these sessions is drawn from the Detection And Reporting domain — nothing else.

Related practice questions

Related XDR-Engineer topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the XDR-Engineer exam test about Detection And Reporting?
Detection And Reporting questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Detection And Reporting questions in a focused session?
Yes — the session launcher on this page draws every question from the Detection And Reporting domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other XDR-Engineer topics?
Use the topic links above to move to related areas, or go back to the XDR-Engineer question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the XDR-Engineer exam covers. They are not copied from any real exam or dump site.