Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Security Operations XDR-Engineer Passing Score

Palo Alto Networks XDR Engineer Questions and Answers

Question 5

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

Options:

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

Question 6

After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a partially protected status. In which two places can insights into what is contributing to this status be located? (Choose two.)

Options:

A.

Management Audit Logs

B.

XQL query of the endpoints dataset

C.

All Endpoints page

D.

Asset Inventory

Question 7

What will enable a custom prevention rule to block specific behavior?

Options:

A.

A correlation rule added to an Agent Blocking profile

B.

A custom behavioral indicator of compromise (BIOC) added to an Exploit profile

C.

A custom behavioral indicator of compromise (BIOC) added to a Restriction profile

D.

A correlation rule added to a Malware profile

Question 8

When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is used to turn off a component on a Windows machine?

Options:

A.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" stop

B.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop

C.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" -s stop

D.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" occp