nerdexam
Palo_Alto_Networks

XDR-ENGINEER · Question #29

Which components may be included in a Cortex XDR content update?

The correct answer is B. Behavioral Threat Protection (BTP) rules and local analysis logic. Option B is correct because Cortex XDR content updates are specifically designed to deliver threat intelligence and detection logic improvements - including Behavioral Threat Protection (BTP) rules (which govern how the agent detects suspicious process behaviors) and local…

Agent Management

Question

Which components may be included in a Cortex XDR content update?

Options

  • ADevice control profiles, agent versions, and kernel support
  • BBehavioral Threat Protection (BTP) rules and local analysis logic
  • CAntivirus definitions and agent versions
  • DFirewall rules and antivirus definitions

How the community answered

(65 responses)
  • A
    2% (1)
  • B
    94% (61)
  • C
    3% (2)
  • D
    2% (1)

Explanation

Option B is correct because Cortex XDR content updates are specifically designed to deliver threat intelligence and detection logic improvements - including Behavioral Threat Protection (BTP) rules (which govern how the agent detects suspicious process behaviors) and local analysis logic (the machine learning models used for local verdict decisions) - without requiring a full agent upgrade.

Why the distractors are wrong:

  • A - Agent versions and kernel support are distributed as agent software updates, not content updates. Device control profiles are policy configurations managed in the console.
  • C - Antivirus definitions and agent versions conflate two separate update channels; Cortex XDR content updates do not include agent version packages.
  • D - Firewall rules are policy-based configurations, and antivirus definitions (as a standalone concept) belong to legacy AV architecture - neither fits the Cortex XDR content update model.

Memory tip: Think "content = detection smarts." Content updates keep the brain of the agent sharp (BTP rules + local analysis models) without touching the agent binary itself - if it changes how threats are identified, it's a content update.

Topics

#content updates#BTP rules#local analysis logic#agent content

Community Discussion

No community discussion yet for this question.

Full XDR-ENGINEER Practice