Summer Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

XDR-Engineer Palo Alto Networks XDR Engineer Questions and Answers

Questions 4

Based on the image of a validated false positive alert below, which action is recommended for resolution?

XDR-Engineer Question 4

Options:

A.

Create an alert exclusion for OUTLOOK.EXE

B.

Disable an action to the CGO Process DWWIN.EXE

C.

Create an exception for the CGO DWWIN.EXE for ROP Mitigation Module

D.

Create an exception for OUTLOOK.EXE for ROP Mitigation Module

Buy Now
Questions 5

Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?

XDR-Engineer Question 5

Options:

A.

It will immediately execute

B.

It will not execute

C.

It will execute after one hour

D.

It will execute after the second attempt

Buy Now
Questions 6

Which two steps should be considered when configuring the Cortex XDR agent for a sensitive and highly regulated environment? (Choose two.)

Options:

A.

Enable critical environment versions

B.

Create an agent settings profile where the agent upgrade scope is maintenance releases only

C.

Create an agent settings profile, enable content auto-update, and include a delay of four days

D.

Enable minor content version updates

Buy Now
Questions 7

When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is used to turn off a component on a Windows machine?

Options:

A.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" stop

B.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop

C.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" -s stop

D.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" occp

Buy Now
Questions 8

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

Options:

A.

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Buy Now
Questions 9

A cloud administrator reports high network bandwidth costs attributed to Cortex XDR operations and asks for bandwidth usage to be optimized without compromising agent functionality. Which two techniques should the engineer implement? (Choose two.)

Options:

A.

Configure P2P download sources for agent upgrades and content updates

B.

Enable minor content version updates

C.

Enable agent content management bandwidth control

D.

Deploy a Broker VM and activate the local agent settings applet

Buy Now
Questions 10

A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive Identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices. What may be the reason for the issue?

Options:

A.

The XDR tenant is not in the same region as the Cloud Identity Engine

B.

The Cloud Identity Engine plug-in has not been installed and configured

C.

The Cloud Identity Engine needs to be activated in all global regions

D.

The ITDR add-on is not compatible with the Cloud Identity Engine

Buy Now
Questions 11

An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by automatically isolating the affected endpoint and notifying the security team via email. The playbook should only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)

Options:

A.

Alert severity is High

B.

Alert source is Cortex XDR Analytics

C.

Alert category is Malware

D.

Alert status is New

Buy Now
Questions 12

When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?

Options:

A.

Conduct an XQL query for NGFW log data

B.

Wait for an incident that involves the NGFW to populate

C.

Confirm that the selected device has a valid certificate

D.

Retrieve device certificate from NGFW dashboard

Buy Now
Questions 13

How can a Malware profile be configured to prevent a specific executable from being uploaded to the cloud?

Options:

A.

Disable on-demand file examination for the executable

B.

Set PE and DLL examination for the executable to report action mode

C.

Add the executable to the allow list for executions

D.

Create an exclusion rule for the executable

Buy Now
Questions 14

Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?

Options:

A.

Add entries in Configuration section of Security Settings

B.

Add entries in the Allowed Domains section of Security Settings for the tenant

C.

Add entries in Exceptions Configuration section of Isolation Exceptions

D.

Add entries in Response Actions section of Agent Settings profile

Buy Now
Questions 15

Some company employees are able to print documents when working from home, but not on network-attached printers, while others are able to print only to file. What can be inferred about the affected users’ inability to print?

Options:

A.

They may be attached to the default extensions policy and profile

B.

They may have a host firewall profile set to block activity to all network-attached printers

C.

They may have different disk encryption profiles that are not allowing print jobs on encrypted files

D.

They may be on different device extensions profiles set to block different print jobs

Buy Now
Exam Code: XDR-Engineer
Exam Name: Palo Alto Networks XDR Engineer
Last Update: May 31, 2025
Questions: 50

PDF + Testing Engine

$66  $164.99

Testing Engine

$50  $124.99
buy now XDR-Engineer testing engine

PDF (Q&A)

$42  $104.99
buy now XDR-Engineer pdf