XDR-Analyst Palo Alto Networks XDR Analyst Questions and Answers
Which of the following is NOT a precanned script provided by Palo Alto Networks?
The Cortex XDR console has triggered an incident, blocking a vitally important piece of software in your organization that is known to be benign. Which of the following options would prevent Cortex XDR from blocking this software in the future, for all endpoints in your organization?
Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?
Which function describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed?
To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to open a malicious Word document. You learn from the WildFire report and AutoFocus that this document is known to have been used in Phishing campaigns since 2018. What steps can you take to ensure that the same document is not opened by other users in your organization protected by the Cortex XDR agent?
How can you pivot within a row to Causality view and Timeline views for further investigate?
In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
Cortex XDR Analytics can alert when detecting activity matching the following MITRE ATT & CKTM techniques.
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?


