Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Paloalto Networks XDR-Engineer Palo Alto Networks XDR Engineer Exam Practice Test

Demo: 14 questions
Total 50 questions

Palo Alto Networks XDR Engineer Questions and Answers

Question 1

Which two steps should be considered when configuring the Cortex XDR agent for a sensitive and highly regulated environment? (Choose two.)

Options:

A.

Enable critical environment versions

B.

Create an agent settings profile where the agent upgrade scope is maintenance releases only

C.

Create an agent settings profile, enable content auto-update, and include a delay of four days

D.

Enable minor content version updates

Question 2

What will enable a custom prevention rule to block specific behavior?

Options:

A.

A correlation rule added to an Agent Blocking profile

B.

A custom behavioral indicator of compromise (BIOC) added to an Exploit profile

C.

A custom behavioral indicator of compromise (BIOC) added to a Restriction profile

D.

A correlation rule added to a Malware profile

Question 3

What are two possible actions that can be triggered by a dashboard drilldown? (Choose two.)

Options:

A.

Navigate to a different dashboard

B.

Initiate automated response actions

C.

Link to an XQL query

D.

Send alerts to console users

Question 4

Log events from a previously deployed Windows XDR Collector agent are no longer being observed in the console after an OS upgrade. Which aspect of the log events is the probable cause of this behavior?

Options:

A.

They are greater than 5MB

B.

They are in Winlogbeat format

C.

They are in Filebeat format

D.

They are less than 1MB

Question 5

Which method will drop undesired logs and reduce the amount of data being ingested?

Options:

A.

[COLLECT:vendor="vendor", product="product", target_brokers="", no_hit=drop] * drop _raw_log contains "undesired logs";

B.

[INGEST:vendor="vendor", product="product", target_dataset="vendor_product_raw",no_hit=drop] * filter _raw_log not contains "undesired logs";

C.

[COLLECT:vendor="vendor", product="product", target_dataset="", no_hit=drop] * drop _raw_log contains "undesired logs";

D.

[INGEST:vendor="vendor", product="product", target_brokers="vendor_product_raw", no_hit=keep] * filter _raw_log not contains "undesired logs";

Question 6

The most recent Cortex XDR agents are being installed at a newly acquired company. A list with endpoint types (i.e., OS, hardware, software) is provided to the engineer. What should be cross-referenced for the Linux systems listed regarding the OS types and OS versions supported?

Options:

A.

Content Compatibility Matrix

B.

Kernel Module Version Support

C.

End-of-Life Summary

D.

Agent Installer Certificate

Question 7

Some company employees are able to print documents when working from home, but not on network-attached printers, while others are able to print only to file. What can be inferred about the affected users’ inability to print?

Options:

A.

They may be attached to the default extensions policy and profile

B.

They may have a host firewall profile set to block activity to all network-attached printers

C.

They may have different disk encryption profiles that are not allowing print jobs on encrypted files

D.

They may be on different device extensions profiles set to block different print jobs

Question 8

How can a customer ingest additional events from a Windows DHCP server into Cortex XDR with minimal configuration?

Options:

A.

Activate Windows Event Collector (WEC)

B.

Install the XDR Collector

C.

Enable HTTP collector integration

D.

Install the Cortex XDR agent

Question 9

Which components may be included in a Cortex XDR content update?

Options:

A.

Device control profiles, agent versions, and kernel support

B.

Behavioral Threat Protection (BTP) rules and local analysis logic

C.

Antivirus definitions and agent versions

D.

Firewall rules and antivirus definitions

Question 10

Which step is required to configure a proxy for an XDR Collector?

Options:

A.

Edit the YAML configuration file with the new proxy information

B.

Restart the XDR Collector after configuring the proxy settings

C.

Connect the XDR Collector to the Pathfinder

D.

Configure the proxy settings on the Cortex XDR tenant

Question 11

Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which endpoint(s) data will be accessible?

Options:

A.

E1 only

B.

E2 only

C.

E1, E2, and E3

D.

E1, E2, E3, and E4

Question 12

How long is data kept in the temporary hot storage cache after being queried from cold storage?

Options:

A.

1 hour, re-queried to a maximum of 12 hours

B.

24 hours, re-queried to a maximum of 7 days

C.

24 hours, re-queried to a maximum of 14 days

D.

1 hour, re-queried to a maximum of 24 hours

Question 13

Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?

Options:

A.

It will immediately execute

B.

It will not execute

C.

It will execute after one hour

D.

It will execute after the second attempt

Question 14

A query is created that will run weekly via API. After it is tested and ready, it is reviewed in the Query Center. Which available column should be checked to determine how many compute units will be used when the query is run?

Options:

A.

Query Status

B.

Compute Unit Usage

C.

Simulated Compute Units

D.

Compute Unit Quota

Demo: 14 questions
Total 50 questions