Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

XDR-Engineer Palo Alto Networks XDR Engineer Questions and Answers

Questions 4

What should be configured in Cortex XDR to integrate asset data from Microsoft Azure for better visibility and incident investigation?

Options:

A.

Azure Network Watcher

B.

Cloud Identity Engine

C.

Cloud Inventory

D.

Microsoft 365

Buy Now
Questions 5

Which method will drop undesired logs and reduce the amount of data being ingested?

Options:

A.

[COLLECT:vendor="vendor", product="product", target_brokers="", no_hit=drop] * drop _raw_log contains "undesired logs";

B.

[INGEST:vendor="vendor", product="product", target_dataset="vendor_product_raw", no_hit=drop] * filter _raw_log not contains "undesired logs";

C.

[COLLECT:vendor="vendor", product="product", target_dataset="", no_hit=drop] * drop _raw_log contains "undesired logs";

D.

[INGEST:vendor="vendor", product="product", target_brokers="vendor_product_raw", no_hit=keep] * filter _raw_log not contains "undesired logs";

Buy Now
Questions 6

Which configuration profile option with an available built-in template can be applied to both Windows and Linux systems by using XDR Collector?

Options:

A.

Filebeat

B.

HTTP Collector template

C.

XDR Collector settings

D.

Winlogbeat

Buy Now
Questions 7

When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?

Options:

A.

Conduct an XQL query for NGFW log data

B.

Wait for an incident that involves the NGFW to populate

C.

Confirm that the selected device has a valid certificate

D.

Retrieve device certificate from NGFW dashboard

Buy Now
Questions 8

Log events from a previously deployed Windows XDR Collector agent are no longer being observed in the console after an OS upgrade. Which aspect of the log events is the probable cause of this behavior?

Options:

A.

They are greater than 5MB

B.

They are in Winlogbeat format

C.

They are in Filebeat format

D.

They are less than 1MB

Buy Now
Questions 9

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

Options:

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

Buy Now
Questions 10

A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive Identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices. What may be the reason for the issue?

Options:

A.

The XDR tenant is not in the same region as the Cloud Identity Engine

B.

The Cloud Identity Engine plug-in has not been installed and configured

C.

The Cloud Identity Engine needs to be activated in all global regions

D.

The ITDR add-on is not compatible with the Cloud Identity Engine

Buy Now
Questions 11

Based on the image of a validated false positive alert below, which action is recommended for resolution?

XDR-Engineer Question 11

Options:

A.

Create an alert exclusion for OUTLOOK.EXE

B.

Disable an action to the CGO Process DWWIN.EXE

C.

Create an exception for the CGO DWWIN.EXE for ROP Mitigation Module

D.

Create an exception for OUTLOOK.EXE for ROP Mitigation Module

Buy Now
Questions 12

An insider compromise investigation has been requested to provide evidence of an unauthorized removable drive being mounted on a company laptop. Cortex XDR agent is installed with default prevention agent settings profile and default extension "Device Configuration" profile. Where can an engineer find the evidence?

Options:

A.

Check Host Inventory - > Mounts

B.

dataset = xdr_data | filter event_type = ENUM.MOUNT and event_sub_type = ENUM.MOUNT_DRIVE_MOUNT

C.

The requested data requires additional configuration to be captured

D.

preset = device_control

Buy Now
Questions 13

How can a customer ingest additional events from a Windows DHCP server into Cortex XDR with minimal configuration?

Options:

A.

Activate Windows Event Collector (WEC)

B.

Install the XDR Collector

C.

Enable HTTP collector integration

D.

Install the Cortex XDR agent

Buy Now
Questions 14

Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?

Options:

A.

Add entries in Configuration section of Security Settings

B.

Add entries in the Allowed Domains section of Security Settings for the tenant

C.

Add entries in Exceptions Configuration section of Isolation Exceptions

D.

Add entries in Response Actions section of Agent Settings profile

Buy Now
Questions 15

What will enable a custom prevention rule to block specific behavior?

Options:

A.

A correlation rule added to an Agent Blocking profile

B.

A custom behavioral indicator of compromise (BIOC) added to an Exploit profile

C.

A custom behavioral indicator of compromise (BIOC) added to a Restriction profile

D.

A correlation rule added to a Malware profile

Buy Now
Exam Code: XDR-Engineer
Exam Name: Palo Alto Networks XDR Engineer
Last Update: May 11, 2026
Questions: 50

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now XDR-Engineer testing engine

PDF (Q&A)

$43.57  $124.49
buy now XDR-Engineer pdf