Month End Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

XDR-Engineer Palo Alto Networks XDR Engineer Questions and Answers

Questions 4

A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive Identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices. What may be the reason for the issue?

Options:

A.

The XDR tenant is not in the same region as the Cloud Identity Engine

B.

The Cloud Identity Engine plug-in has not been installed and configured

C.

The Cloud Identity Engine needs to be activated in all global regions

D.

The ITDR add-on is not compatible with the Cloud Identity Engine

Buy Now
Questions 5

A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:

    All devices are running healthy Cortex XDR agents.

    A single host-based firewall rule to block all outbound RDP is implemented.

    The policy hosting the profile containing the rule applies to all Windows endpoints.

    The logic within the firewall rule is adequate.

    Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.

    Network location configuration in Agent Settings is enabled on all Windows endpoints.What is the likely reason the RDP connections are not being blocked?

Options:

A.

The profile's default action for outbound traffic is set to Allow

B.

The pertinent host-based firewall rule group is only applied to external rule groups

C.

Report mode is set to Enabled in the report settings under the profile configuration

D.

The pertinent host-based firewall rule group is only applied to internal rule groups

Buy Now
Questions 6

A static endpoint group is created by adding 321 endpoints using the Upload From File feature. However, after group creation, the members count field shows 244 endpoints. What are two possible reasons why endpoints were not added to the group? (Choose two.)

Options:

A.

Static groups have a limit of 250 endpoints when adding by file

B.

Endpoints added to the new group were previously added to an existing group

C.

Endpoints added to the group were in Disconnected or Connection Lost status when groupmembership was added

D.

The IP address, hostname, or alias of the endpoints must match an existing agent that has registered with the tenant

Buy Now
Questions 7

A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appear as expected. What may be the cause of this behavior?

Options:

A.

The Broker VM is offline

B.

The parsing rule corrupted the database

C.

The filter stage is dropping the logs

D.

The XDR Collector is dropping the logs

Buy Now
Questions 8

A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)

[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]

Options:

A.

Apply an alert exception

B.

Apply an alert exclusion to the XDR behavioral indicator of compromise (BIOC) alert

C.

Apply an alert exclusion to the XDR agent alert

D.

Modify the behavioral indicator of compromise (BIOC) logic

Buy Now
Questions 9

What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?

Options:

A.

Sending endpoint logs to the NGFW for analysis

B.

Blocking network traffic based on Cortex XDR detections

C.

Enabling additional analysis through enhanced application logging

D.

Automated downloading of malware signatures from the NGFW

Buy Now
Questions 10

Multiple remote desktop users complain of in-house applications no longer working. The team uses macOS with Cortex XDR agents version 8.7.0, and the applications were previously allowed by disable prevention rules attached to the Exceptions Profile "Engineer-Mac." Based on the images below, what is a reason for this behavior?

Options:

A.

Endpoint IP address changed from 192.168.0.0 range to 192.168.100.0 range

B.

The Cloud Identity Engine is disconnected or removed

C.

XDR agent version was downgraded from 8.7.0 to 8.4.0

D.

Installation type changed from VDI to Kubernetes

Buy Now
Questions 11

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

Options:

A.

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Buy Now
Questions 12

Log events from a previously deployed Windows XDR Collector agent are no longer being observed in the console after an OS upgrade. Which aspect of the log events is the probable cause of this behavior?

Options:

A.

They are greater than 5MB

B.

They are in Winlogbeat format

C.

They are in Filebeat format

D.

They are less than 1MB

Buy Now
Questions 13

In addition to using valid authentication credentials, what is required to enable the setup of the Database Collector applet on the Broker VM to ingest database activity?

Options:

A.

Valid SQL query targeting the desired data

B.

Access to the database audit log

C.

Database schema exported in the correct format

D.

Access to the database transaction log

Buy Now
Questions 14

How are dynamic endpoint groups created and managed in Cortex XDR?

Options:

A.

Endpoint groups require intervention to update the group with new endpoints when a new device is added to the network

B.

Each endpoint can belong to multiple groups simultaneously, allowing different security policies to be applied to the same device at the same time

C.

After an endpoint group is created, its assigned security policy cannot be changed without deleting and recreating the group

D.

Endpoint groups are defined based on fields such as OS type, OS version, and network segment

Buy Now
Questions 15

An insider compromise investigation has been requested to provide evidence of an unauthorized removable drive being mounted on a company laptop. Cortex XDR agent is installed with default prevention agent settings profile and default extension "Device Configuration" profile. Where can an engineer find the evidence?

Options:

A.

Check Host Inventory -> Mounts

B.

dataset = xdr_data | filter event_type = ENUM.MOUNT and event_sub_type = ENUM.MOUNT_DRIVE_MOUNT

C.

The requested data requires additional configuration to be captured

D.

preset = device_control

Buy Now
Exam Code: XDR-Engineer
Exam Name: Palo Alto Networks XDR Engineer
Last Update: May 19, 2025
Questions: 50
XDR-Engineer pdf

XDR-Engineer PDF

$25.5  $84.99
XDR-Engineer Engine

XDR-Engineer Testing Engine

$30  $99.99
XDR-Engineer PDF + Engine

XDR-Engineer PDF + Testing Engine

$40.5  $134.99