Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free Palo Alto Networks XDR Analyst Practice Questions

Exams4sure Dumps

Exam style questions across every XDR-Analyst domain

Last Update 1 day ago
Total Questions : 91

Start with our free XDR-Analyst practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Security Operations exam. Each XDR-Analyst exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Paloalto Networks weak domains, see where you're losing marks, and build a focused study plan in minutes.

XDR-Analyst PDF

XDR-Analyst PDF (Printable)
$54.25
$154.99

XDR-Analyst Testing Engine

XDR-Analyst PDF (Printable)
$59.5
$169.99

XDR-Analyst PDF + Testing Engine

XDR-Analyst PDF (Printable)
$74.55
$212.99
Question # 11

With a Cortex XDR Prevent license, which objects are considered to be sensors?

Options:

A.  

Syslog servers

B.  

Third-Party security devices

C.  

Cortex XDR agents

D.  

Palo Alto Networks Next-Generation Firewalls

Discussion 0
Question # 12

In incident-related widgets, how would you filter the display to only show incidents that were “starred”?

Options:

A.  

Create a custom XQL widget

B.  

This is not currently supported

C.  

Create a custom report and filter on starred incidents

D.  

Click the star in the widget

Discussion 0
Question # 13

What is the difference between presets and datasets in XQL?

Options:

A.  

A dataset is a Cortex data lake data source only; presets are built-in data source.

B.  

A dataset is a built-in or third-party source; presets group XDR data fields.

C.  

A dataset is a database; presets is a field.

D.  

A dataset is a third-party data source; presets are built-in data source.

Discussion 0
Question # 14

Which function describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed?

Options:

A.  

Search & destroy

B.  

Isolation

C.  

Quarantine

D.  

Flag for removal

Discussion 0
Question # 15

When creating a scheduled report which is not an option?

Options:

A.  

Run weekly on a certain day and time.

B.  

Run quarterly on a certain day and time.

C.  

Run monthly on a certain day and time.

D.  

Run daily at a certain time (selectable hours and minutes).

Discussion 0
Question # 16

Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?

Options:

A.  

Hash Verdict Determination

B.  

Behavioral Threat Protection

C.  

Restriction Policy

D.  

Child Process Protection

Discussion 0
Question # 17

If you have an isolated network that is prevented from connecting to the Cortex Data Lake, which type of Broker VM setup can you use to facilitate the communication?

Options:

A.  

Broker VM Pathfinder

B.  

Local Agent Proxy

C.  

Local Agent Installer and Content Caching

D.  

Broker VM Syslog Collector

Discussion 0
Question # 18

Phishing belongs to which of the following MITRE ATT&CK tactics?

Options:

A.  

Initial Access, Persistence

B.  

Persistence, Command and Control

C.  

Reconnaissance, Persistence

D.  

Reconnaissance, Initial Access

Discussion 0
Question # 19

Which of the following is an example of a successful exploit?

Options:

A.  

connecting unknown media to an endpoint that copied malware due to Autorun.

B.  

a user executing code which takes advantage of a vulnerability on a local service.

C.  

identifying vulnerable services on a server.

D.  

executing a process executable for well-known and signed software.

Discussion 0
Question # 20

Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?

Options:

A.  

Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.

B.  

Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.

C.  

Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.

D.  

Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.

Discussion 0

Free Exams Sample Questions