XDR-ENGINEER Exam Questions
50 real XDR-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 1.
- Question #1Log Management and Data Ingestion
Which method will drop undesired logs and reduce the amount of data being ingested?
COLLECT directivelog filteringno_hit parameterdata ingestion - Question #2Alert Triage and Incident Response
Based on the image of a validated false positive alert below, which action is recommended for resolution?
false positiveROP mitigationexception rulesalert management - Question #3Integration and Data Collection
What should be configured in Cortex XDR to integrate asset data from Microsoft Azure for better visibility and incident investigation?
Cloud InventoryAzure integrationasset visibilityincident investigation - Question #4Agent Deployment and Management
What happens when the XDR Collector is uninstalled from an endpoint by using the Cortex XDR console?
XDR Collectoragent uninstallheartbeat communicationendpoint lifecycle - Question #5Troubleshooting and Log Management
Log events from a previously deployed Windows XDR Collector agent are no longer being observed in the console after an OS upgrade. Which aspect of the log events is the probable ca...
log size limitsWindows XDR CollectorOS upgradelog collection troubleshooting - Question #6XQL Query and Investigation
Which action is being taken with the query below? dataset = xdr_data | fields agent_hostname, _time, _product | comp latest as latest_time by agent_hostname, _product | join type=i...
XQL querydataset joinendpoint monitoringagent activity - Question #7Security Configuration and Access Control
Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which endpoint(s) data will be accessible?
SBACpermissive modeendpoint access controltenant configuration - Question #8Alert Triage and Incident Response
An analyst considers an alert with the category of lateral movement to be allowed and not needing to be checked in the future. Based on the image below, which action can an enginee...
alert exclusionlateral movementBIOC suppressionalert management - Question #9Endpoint Policy and Profile Management
Some company employees are able to print documents when working from home, but not on network-attached printers, while others are able to print only to file. What can be inferred a...
host firewall profilenetwork printingdevice restrictionsendpoint policy - Question #10Agent Deployment and Management
Which two steps should be considered when configuring the Cortex XDR agent for a sensitive and highly regulated environment? (Choose two.)
agent settings profilemaintenance releasescontent auto-updateregulated environment - Question #11Troubleshooting and Agent Management
When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is used to turn off a component on a Windows machine?
cytoolWindows agentcomponent isolationagent troubleshooting - Question #12Agent Deployment and Management
During deployment of Cortex XDR for Linux Agents, the security engineering team is asked to implement memory monitoring for agent health monitoring. Which agent service should be m...
Linux agentpmd servicememory monitoringagent health - Question #13Agent Deployment and Management
The most recent Cortex XDR agents are being installed at a newly acquired company. A list with endpoint types (i.e., OS, hardware, software) is provided to the engineer. What shoul...
Linux agent deploymentkernel module compatibilityOS support matrixagent installation - Question #14Endpoint Monitoring and Management
After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a partially protected status. In which two places can insights into what is contributing...
partially protected statusXQL queryAll Endpoints pageendpoint health - Question #15Integration and Data Collection
What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?
NGFW integrationlog ingestionapplication loggingPalo Alto Networks - Question #16Automation and Incident Response
An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by automatically isolating the affected endpoint and notifying the security team vi...
automation playbookplaybook trigger conditionsalert severitymalware category - Question #17Log Management and Data Ingestion
An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule...
parsing rulesCONST sectionreusable ruleslog field extraction - Question #18XQL Query and Data Parsing
What will be the output of the function below? L_TRIM("a* aapple", "a")
L_TRIM functionstring manipulationXQL functionsparsing functions - Question #19Endpoint Security Policy
Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?
malware profileapplication execution preventionunknown applicationendpoint protection policy - Question #20Agent Deployment and Configuration
Which configuration profile option with an available built-in template can be applied to both Windows and Linux systems by using XDR Collector?
XDR CollectorFilebeatcross-platform templateconfiguration profile - Question #21Detection Engineering
What is the earliest time frame an alert could be automatically generated once the conditions of a new correlation rule are met?
correlation rulesalert generation timingdetection latency - Question #22Data Ingestion and Integration
When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?
NGFW onboardinglog ingestion verificationXQL queryCortex XDR integration - Question #23Detection Engineering
During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Wind...
BIOC rulesbehavioral detectionrule type selectionendpoint detection - Question #24Endpoint Management and Policy
Multiple remote desktop users complain of in-house applications no longer working. The team uses macOS with Cortex XDR agents version 8.7.0, and the applications were previously al...
Exceptions Profileprevention rulesVDI endpointsIP address change - Question #25Data Ingestion and Integration
A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appe...
parsing ruleslog filteringfilter stagedata pipeline - Question #26Detection Engineering
Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?
XQL queryBIOC rulescustom prevention rulesevent_type PROCESS - Question #27Infrastructure and Deployment
Which step is required to configure a proxy for an XDR Collector?
XDR Collectorproxy configurationYAML configurationcollector setup - Question #28Data Management and Storage
How long is data kept in the temporary hot storage cache after being queried from cold storage?
hot storagecold storagedata retentionstorage cache - Question #29Agent Management
Which components may be included in a Cortex XDR content update?
content updatesBTP ruleslocal analysis logicagent content - Question #30Incident Investigation and Response
An insider compromise investigation has been requested to provide evidence of an unauthorized removable drive being mounted on a company laptop. Cortex XDR agent is installed with...
device controlremovable drivesHost Inventoryforensic investigation - Question #31Endpoint Management and Policy
A static endpoint group is created by adding 321 endpoints using the Upload From File feature. However, after group creation, the members count field shows 244 endpoints. What are...
static endpoint groupsgroup membershipUpload From Fileagent status - Question #32Dashboard and Reporting
What are two possible actions that can be triggered by a dashboard drilldown? (Choose two.)
dashboard drilldownXQL query linkingwidget actionsvisualization - Question #33Identity Threat Detection and Response
A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-o...
Cloud Identity EngineITDRregional tenancyidentity analytics - Question #34Infrastructure and Deployment
When using Kerberos as the authentication method for Pathfinder, which two settings must be validated on the DNS server? (Choose two.)
Kerberos authenticationPathfinderDNS configurationreverse DNS - Question #35Data Ingestion and Integration
How can a customer ingest additional events from a Windows DHCP server into Cortex XDR with minimal configuration?
XDR CollectorWindows DHCPlog ingestionminimal configuration - Question #36Endpoint Management and Policy
How are dynamic endpoint groups created and managed in Cortex XDR?
dynamic endpoint groupsgroup managementOS-based filteringpolicy assignment - Question #37Dashboard and Reporting
An engineer is building a dashboard to visualize the number of alerts from various sources. One of the widgets from the dashboard is shown in the image below: The engineer wants to...
dashboard drilldownXQL filter variablex_axis valuewidget configuration - Question #38Detection Engineering
An XDR engineer is creating a correlation rule to monitor login activity on specific systems. When the activity is identified, an alert is created. The alerts are being generated p...
correlation rulesalert field mappingusername fieldalert customization - Question #39Detection Engineering
A correlation rule is created to detect potential insider threats by correlating user login events from one dataset with file access events from another dataset. The rule must reta...
XQL joinleft joincorrelation rulesmulti-dataset queries - Question #40Infrastructure and Deployment
A cloud administrator reports high network bandwidth costs attributed to Cortex XDR operations and asks for bandwidth usage to be optimized without compromising agent functionality...
bandwidth optimizationP2P agent updatescontent managementBroker VM - Question #41Prevention and Detection
How can a Malware profile be configured to prevent a specific executable from being uploaded to the cloud?
Malware profileexclusion rulesfile upload preventioncloud protection - Question #42Deployment and Configuration
During the deployment of a Broker VM in a high availability (HA) environment, after configuring the Broker VM FQDN, an XDR engineer must ensure agent installer availability and eff...
Broker VMhigh availabilitySSL certificateload balancer - Question #43Prevention and Detection
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Bas...
Custom prevention rulefalse positive tuningalert exceptionBIOC - Question #44Deployment and Configuration
In addition to using valid authentication credentials, what is required to enable the setup of the Database Collector applet on the Broker VM to ingest database activity?
Database CollectorBroker VMSQL querydatabase activity ingestion - Question #45Reporting and Analytics
Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard's interactivity and data insights?
dashboardfixed filtersdrilldownsdata visualization - Question #46Investigation and Response
An engineer wants to automate the handling of alerts in Cortex XDR and defines several automation rules with different actions to be triggered based on specific alert conditions. S...
automation rulesalert handlingsequential executionincident grouping - Question #47Prevention and Detection
What will enable a custom prevention rule to block specific behavior?
custom prevention ruleBIOCRestriction profilebehavior blocking - Question #48Reporting and Analytics
A query is created that will run weekly via API. After it is tested and ready, it is reviewed in the Query Center. Which available column should be checked to determine how many co...
Query Centercompute unitsXQLAPI queries - Question #49Prevention and Detection
A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the follo...
host-based firewallRDP blockingnetwork locationfirewall rule groups - Question #50Investigation and Response
Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?
endpoint isolationisolation exceptionsIP allowlistnetwork access control