Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Palo Alto Networks XDR Analyst

Last Update 21 hours ago Total Questions : 91

The Palo Alto Networks XDR Analyst content is now fully updated, with all current exam questions added 21 hours ago. Deciding to include XDR-Analyst practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our XDR-Analyst exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these XDR-Analyst sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Palo Alto Networks XDR Analyst practice test comfortably within the allotted time.

Question # 11

Cortex XDR is deployed in the enterprise and you notice a cobalt strike attack via an ongoing supply chain compromise was prevented on 1 server. What steps can you take to ensure the same protection is extended to all your servers?

A.

Conduct a thorough Endpoint Malware scan.

B.

Enable DLL Protection on all servers but there might be some false positives.

C.

Enable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.

D.

Create lOCs of the malicious files you have found to prevent their execution.

Question # 12

Which of the following represents a common sequence of cyber-attack tactics?

A.

Actions on the objective » Reconnaissance » Weaponization & Delivery » Exploitation » Installation » Command & Control

B.

Installation > > Reconnaissance » Weaponization & Delivery » Exploitation » Command & Control » Actions on the objective

C.

Reconnaissance » Weaponization & Delivery » Exploitation » Installation » Command & Control » Actions on the objective

D.

Reconnaissance > > Installation » Weaponization & Delivery » Exploitation » Command & Control » Actions on the objective

Question # 13

What contains a logical schema in an XQL query?

A.

Bin

B.

Array expand

C.

Field

D.

Dataset

Question # 14

Which of the following represents the correct relation of alerts to incidents?

A.

Only alerts with the same host are grouped together into one Incident in a given time frame.

B.

Alerts that occur within a three-hour time frame are grouped together into one Incident.

C.

Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.

D.

Every alert creates a new Incident.

Question # 15

Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?

A.

in the macOS Malware Protection Profile to indicate allowed signers

B.

in the Linux Malware Protection Profile to indicate allowed Java libraries

C.

SHA256 hashes cannot be used in Cortex XDR Malware Protection Profiles

D.

in the Windows Malware Protection Profile to indicate allowed executables

Question # 16

Where would you view the WildFire report in an incident?

A.

next to relevant Key Artifacts in the incidents details page

B.

under Response -- > Action Center

C.

under the gear icon -- > Agent Audit Logs

D.

on the HUB page at apps.paloaltonetworks.com

Question # 17

Which type of BIOC rule is currently available in Cortex XDR?

A.

Threat Actor

B.

Discovery

C.

Network

D.

Dropper

Question # 18

What is the action taken out by Managed Threat Hunting team for Zero Day Exploits?

A.

MTH researches for threats in the tenant and generates a report with the findings.

B.

MTH researches for threats in the logs and reports to engineering.

C.

MTH runs queries and investigative actions and no further action is taken.

D.

MTH pushes content updates to prevent against the zero-day exploits.

Question # 19

Which two types of exception profiles you can create in Cortex XDR? (Choose two.)

A.

exception profiles that apply to specific endpoints

B.

agent exception profiles that apply to specific endpoints

C.

global exception profiles that apply to all endpoints

D.

role-based profiles that apply to specific endpoints

Question # 20

What is the purpose of the Unit 42 team?

A.

Unit 42 is responsible for automation and orchestration of products

B.

Unit 42 is responsible for the configuration optimization of the Cortex XDR server

C.

Unit 42 is responsible for threat research, malware analysis and threat hunting

D.

Unit 42 is responsible for the rapid deployment of Cortex XDR agents

Go to page: