nerdexam
Palo_Alto_Networks

PCDRA · Question #92

Which statement best describes how Behavioral Threat Protection (BTP) works?

The correct answer is D. BTP uses machine Learning to recognize malicious activity even if it is not known.. BTP uses machine learning to recognize malicious activity even if it is not known. BTP is a feature of Cortex XDR that allows you to define custom rules to detect and block malicious behaviors on endpoints. BTP uses machine learning to profile behavior and detect anomalies indica

Submitted by luis.pe· Apr 18, 2026Detection and Alert Management

Question

Which statement best describes how Behavioral Threat Protection (BTP) works?

Options

  • ABTP injects into known vulnerable processes to detect malicious activity.
  • BBTP runs on the Cortex XDR and distributes behavioral signatures to all agents.
  • CBTP matches EDR data with rules provided by Cortex XDR.
  • DBTP uses machine Learning to recognize malicious activity even if it is not known.

How the community answered

(68 responses)
  • A
    6% (4)
  • B
    1% (1)
  • C
    3% (2)
  • D
    90% (61)

Explanation

BTP uses machine learning to recognize malicious activity even if it is not known. BTP is a feature of Cortex XDR that allows you to define custom rules to detect and block malicious behaviors on endpoints. BTP uses machine learning to profile behavior and detect anomalies indicative of attack. BTP can recognize malicious activity based on file attributes, registry keys, processes, network connections, and other criteria, even if the activity is not associated with any known malware or threat. BTP rules are updated through content updates and can be managed from the Cortex XDR console.

Topics

#Behavioral Threat Protection (BTP)#Machine Learning#Threat Detection#Cortex XDR Features

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice