XDR-ANALYST Exam Questions
105 real XDR-ANALYST exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Deployment
What is the standard installation disk space recommended to install a Broker VM?
Broker VMdisk spacesystem requirementsinstallation - Question #2Configuration
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
SHA256malware protection profileallowed executablesWindows policy - Question #3Advanced Topics
How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?
ransomware preventiondecoy filesfile system protectionbehavioral protection - Question #4Deployment
What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?
Broker VMsyslog collectorlog ingestionfirewall logs - Question #5Deployment
In the deployment of which Broker VM applet are you required to install a strong cipher SHA256- based SSL certificate?
Broker VMSSL certificateSHA256 cipheragent installer - Question #6Configuration
What is the outcome of creating and implementing an alert exclusion?
alert exclusionconsole alertsincident managementalert filtering - Question #7Introduction
Which statement is true for Application Exploits and Kernel Exploits?
kernel exploitapplication exploitexploit goalssecurity fundamentals - Question #8Advanced Topics
To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
BIOC ruleXQL queryevent_type fieldthreat detection - Question #9Introduction
Which of the following is an example of a successful exploit?
exploitvulnerability exploitationcode executionlocal service - Question #10Advanced Topics
Which of the following represents the correct relation of alerts to incidents?
alertsincidentscausality chainincident grouping - Question #11Configuration
Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?
malware protection flowhash verdictprotection module orderWindows agent - Question #12Incident Management
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatic...
incident managementalert exclusionsfalse positivesincident resolution - Question #13Threat Detection and Analytics
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?
network attacksCortex XDR Analyticsendpoint protectionattack patterns - Question #14Endpoint Protection
After scan, how does file quarantine function work on an endpoint?
file quarantineendpoint securitymalware responselocal drive - Question #15Policy and Exception Management
Which two types of exception profiles you can create in Cortex XDR? (Choose two.)
exception profilesagent exceptionsglobal exceptionsendpoint policy - Question #16Endpoint Protection
Which profiles can the user use to configure malware protection in the Cortex XDR console?
malware protection profilesecurity profilesCortex XDR consoleendpoint configuration - Question #17Vulnerability Management
Which module provides the best visibility to view vulnerabilities?
Host Insightsvulnerability managementCortex XDR modulesendpoint visibility - Question #18Response and Remediation
Which of the following is NOT a precanned script provided by Palo Alto Networks?
precanned scriptsscript libraryPalo Alto Networksresponse scripts - Question #19Endpoint Investigation
Live Terminal uses which type of protocol to communicate with the agent on the endpoint?
Live TerminalWebSocket protocolagent communicationremote access - Question #20Incident Management
You can star security events in which two ways? (Choose two.)
security eventsalert starringincident starringalert management - Question #21Policy and Exception Management
Where would you go to add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint?
file hash exclusionmalware profileallow listexception management - Question #22Threat Prevention and Response
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to open a malicious Word document. You learn from the WildFire report...
BTP rulesphishing preventionmalware IOCproactive threat prevention - Question #23Response and Remediation
When investigating security events, which feature in Cortex XDR is useful for reverting the changes on the endpoint?
Remediation Suggestionsendpoint remediationchange reversionincident response - Question #24Data Management and Architecture
What is the purpose of the Cortex Data Lake?
Cortex Data Lakecloud storagelog aggregationfirewall logs - Question #25Reporting and Analytics
When creating a scheduled report which is not an option?
scheduled reportsreporting optionsCortex XDR consolereport frequency - Question #26Response and Remediation
Which statement regarding scripts in Cortex XDR is true?
script managementrisk level assignmentPython scriptsscript import - Question #27Threat Detection and Analysis
What is the function of WildFire for Cortex XDR?
WildFiremalware analysisfile verdictcloud sandbox - Question #28Response and Remediation
A Linux endpoint with a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled has reported malicious activity, resulting in the creation of a file that you wish to...
Linux endpointfile remediationRemediation SuggestionsPro per Endpoint license - Question #29Endpoint Investigation
Which of the following best defines the Windows Registry as used by the Cortex XDR agent?
Windows Registryhierarchical databaseoperating system settingsagent behavior - Question #30Threat Detection and Analytics
Which statement best describes how Behavioral Threat Protection (BTP) works?
Behavioral Threat Protectionmachine learningbehavioral signaturesmalware detection - Question #31Policy and Exception Management
Which of the following policy exceptions applies to the following description? `An exception allowing specific PHP files'
local file threat examinationpolicy exceptionsPHP file exclusionexception types - Question #32Cortex XDR Agent Management
In the Cortex XDR console, from which two pages are you able to manually perform the agent upgrade action? (Choose two.)
agent upgradeconsole navigationasset managementendpoint administration - Question #33Threat Intelligence and Attack Techniques
What motivation do ransomware attackers have for returning access to systems once their victims have paid?
ransomwareattack motivationthreat actorscybercrime - Question #34Cortex XDR Managed Threat Hunting
What is the action taken out by Managed Threat Hunting team for Zero Day Exploits?
Managed Threat Huntingzero-day exploitsMTH reportingthreat research - Question #35Cortex XDR Exploit Prevention
Which Exploit Prevention Module (EPM) provides better entropy for randomization of memory locations?
Exploit Prevention ModuleUASLRmemory randomizationASLR - Question #36Cortex XDR Reporting and Monitoring
Which statement is correct based on the report output below?
report interpretationforensic inventoryhost inventorydisk encryption - Question #37XQL Query Language
What contains a logical schema in an XQL query?
XQLquery languagedataset schemafield - Question #38Cortex XDR Malware Prevention
Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?
Local AnalysisWildFirefile verdictoffline analysis - Question #39Cortex XDR Reporting and Monitoring
In Cortex XDR management console scheduled reports can be forwarded to which of the following applications/services?
scheduled reportsSlack integrationreport forwardingconsole features - Question #40Cortex XDR Agent Configuration
Can you disable the ability to use the Live Terminal feature in Cortex XDR?
Live Terminalagent settings profilefeature configurationconsole management - Question #41Threat Intelligence and Attack Techniques
Which of the following represents a common sequence of cyber-attack tactics?
cyber kill chainattack sequenceMITRE ATT&CKattack lifecycle - Question #42Cortex XDR Infrastructure and Deployment
What is the maximum number of agents one Broker VM local agent applet can support?
Broker VMagent capacityscalabilityinfrastructure limits - Question #43Cortex XDR Exploit Prevention
Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?
Exploit Prevention ModuleJIT mitigationOS function protectionEPM - Question #44Threat Intelligence and Attack Techniques
Why would one threaten to encrypt a hypervisor or, potentially, a multiple number of virtual machines running on a server?
ransomwarehypervisor attackvirtual machine encryptionextortion - Question #45Cortex XDR Infrastructure and Deployment
Which minimum Cortex XDR agent version is required for Kubernetes Cluster?
Kubernetesagent version requirementscontainer securitydeployment prerequisites - Question #46Cortex XDR Policy and Exception Management
The Cortex XDR console has triggered an incident, blocking a vitally important piece of software in your organization that is known to be benign. Which of the following options wou...
global exceptionexclusion policyfalse positive remediationalert management - Question #47Cortex XDR Incident Response
Which of the following paths will successfully activate Remediation Suggestions?
Remediation SuggestionsCausality Viewincident responseconsole navigation - Question #48Threat Intelligence and Attack Techniques
What is an example of an attack vector for ransomware?
ransomwareattack vectorphishingmalicious attachments - Question #49Cortex XDR Malware Prevention
What is the Wildfire analysis file size limit for Windows PE files?
WildFirefile size limitPE filesmalware analysis - Question #50Cortex XDR Investigation and Response
How can you pivot within a row to Causality view and Timeline views for further investigate?
Causality ViewTimeline Viewinvestigation pivotconsole navigation