Palo Alto Networks XDR Engineer - XDR-Engineer Exam Practice Test
A malware profile is configured with all the default settings for a specific endpoint group. For the same group, a restrictions profile has also been configured with the defaults, except with the restriction as shown in the image below. A user opens a command prompt and runs a mimikatz executable from C:\temp.

What is the first alert produced on the XDR Console for that endpoint?

What is the first alert produced on the XDR Console for that endpoint?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Log events from a previously deployed Windows XDR Collector agent are no longer being observed in the console after an OS upgrade. Which aspect of the log events is the probable cause of this behavior?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
The most recent Cortex XDR agents are being installed at a newly acquired company. A list with endpoint types (i.e., OS, hardware, software) is provided to the engineer. What should be cross- referenced for the Linux systems listed regarding the OS types and OS versions supported?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which troubleshooting step should be performed first to determine why logs from a third-party firewall do not appear in Cortex XDR?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A threat hunter suspects lateral movement activity involving compromised credentials. Which telemetry combination provides the strongest evidence during investigation?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive Identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices. What may be the reason for the issue?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
What information can be used to create a dynamic endpoint group?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A threat hunter wants to prioritize investigations according to attacker objectives, techniques, and operational tactics. Which framework provides the best alignment?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).