nerdexam
Palo_Alto_Networks

PCDRA · Question #76

Which statement best describes how Behavioral Threat Protection (BTP) works?

The correct answer is C. BTP matches EDR data with rules provided by Cortex XDR.. Behavioral Threat Protection (BTP) operates by continuously collecting endpoint activity data (EDR telemetry-process events, file operations, network connections, registry changes, etc.) and matching that behavioral data against behavioral rules and signatures distributed by Cort

Submitted by yousef_jo· Apr 18, 2026Detection and Alert Management

Question

Which statement best describes how Behavioral Threat Protection (BTP) works?

Options

  • ABTP injects into known vulnerable processes to detect malicious activity.
  • BBTP runs on the Cortex XDR and distributes behavioral signatures to all agents.
  • CBTP matches EDR data with rules provided by Cortex XDR.
  • DBTP matches the signature with the existing database of malicious files.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    86% (25)
  • D
    3% (1)

Explanation

Behavioral Threat Protection (BTP) operates by continuously collecting endpoint activity data (EDR telemetry-process events, file operations, network connections, registry changes, etc.) and matching that behavioral data against behavioral rules and signatures distributed by Cortex XDR. When a sequence of behaviors matches a known malicious pattern, BTP triggers a response. BTP does not inject into processes to detect activity (A)-that describes API hooking used by some legacy AV engines. BTP distributes rules to agents from Cortex XDR but the matching happens on the endpoint agent, not solely in the cloud (B). And BTP is explicitly behavioral, not hash/signature-based file matching (D), which is traditional antivirus.

Topics

#Behavioral Threat Protection#Cortex XDR Detection#EDR Data Analysis#Detection Rules

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice