XDR-ENGINEER · Question #22
When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?
The correct answer is A. Conduct an XQL query for NGFW log data. Conducting an XQL (Extended Query Language) query for NGFW log data is the active verification step that confirms logs are actually flowing into Cortex XDR after onboarding - it gives you real, queryable evidence of ingestion rather than just assuming the connection works. Why…
Question
When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?
Options
- AConduct an XQL query for NGFW log data
- BWait for an incident that involves the NGFW to populate
- CConfirm that the selected device has a valid certificate
- DRetrieve device certificate from NGFW dashboard
How the community answered
(22 responses)- A91% (20)
- B5% (1)
- C5% (1)
Explanation
Conducting an XQL (Extended Query Language) query for NGFW log data is the active verification step that confirms logs are actually flowing into Cortex XDR after onboarding - it gives you real, queryable evidence of ingestion rather than just assuming the connection works.
Why the distractors are wrong:
- B is wrong because waiting for an incident is passive and unreliable - incidents may not occur immediately, and their absence doesn't confirm logs are being ingested.
- C is wrong because certificate validation happens earlier in the onboarding process (during device verification), not as a post-onboarding confirmation step.
- D is wrong for the same reason as C - retrieving the certificate is part of the initial setup/verification phase, not a log ingestion check.
Memory tip: Think of XQL as your "receipt" - after onboarding, you run an XQL query to prove the logs arrived, just like checking a bank statement to confirm a deposit went through rather than just trusting it did.
Topics
Community Discussion
No community discussion yet for this question.