nerdexam
Palo_Alto_Networks

PCDRA · Question #67

To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?

The correct answer is A. It interferes with the pattern as soon as it is observed on the endpoint.. This question focuses on the prevention aspect of the Cortex XDR Analytics module. Once the analytics engine has identified a known malicious behavioral pattern being exhibited on an endpoint, it acts immediately - it does not wait for the full attack chain to complete before int

Submitted by layla.eg· Apr 18, 2026Cortex XDR Architecture and Agent Deployment

Question

To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?

Options

  • AIt interferes with the pattern as soon as it is observed on the endpoint.
  • BIt does not interfere with any portion of the pattern on the endpoint.
  • CIt does not need to interfere with the any portion of the pattern to prevent the attack.
  • DIt interferes with the pattern as soon as it is observed by the firewall.

How the community answered

(61 responses)
  • A
    89% (54)
  • B
    5% (3)
  • C
    2% (1)
  • D
    5% (3)

Explanation

This question focuses on the prevention aspect of the Cortex XDR Analytics module. Once the analytics engine has identified a known malicious behavioral pattern being exhibited on an endpoint, it acts immediately - it does not wait for the full attack chain to complete before interfering. Because disrupting any single step in a network attack pattern is sufficient to neutralize it, the module is designed to intervene as soon as the pattern is recognized on the endpoint, which is what answer A correctly states. Note: detection relies on pattern analysis, but response is triggered at first pattern confirmation on the endpoint.

Topics

#Cortex XDR Analytics#Endpoint Prevention#Attack Patterns

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice