Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

XSIAM-Engineer Palo Alto Networks XSIAM Engineer Questions and Answers

Questions 4

When Cortex XDR agents are on servers in a zone with no internet access, which configuration will keep them communicating with the platform?

Options:

A.

Logging service in the isolated zone

B.

Broker VM

C.

Integration using filebeat

D.

Engine

Buy Now
Questions 5

In which two locations can correlation rules be monitored for errors? (Choose two.)

Options:

A.

XDR Collector audit logs (type = Rules, subtype = Error)

B.

correlations_auditing dataset through XQL

C.

Management audit logs (type = Rules, subtype = Error)

D.

Alerts table as a health alert

Buy Now
Questions 6

A sub-playbook is configured to loop with a For Each Input. The following inputs are given to the sub-playbook:

Input x: W,X,Y,Z

Input y: a,b,c,d

Input z: 9

Which inputs will be used for the second iteration of the loop?

Options:

A.

a,b,c,d

B.

X,b,9

C.

X,b

D.

X,b,c

Buy Now
Questions 7

A vulnerability analyst asks a Cortex XSIAM engineer to identify assets vulnerable to newly reported zero-day CVE affecting the " ai_app " application and versions 12.1, 12.2, 12.4, and 12.5.

Which XQL query will provide the required result?

A)

XSIAM-Engineer Question 7

B)

XSIAM-Engineer Question 7

C)

XSIAM-Engineer Question 7

D)

XSIAM-Engineer Question 7

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 8

Based on the images below, which command will allow the context data to be displayed as a table when troubleshooting a playbook task?

XSIAM-Engineer Question 8

Options:

A.

!ConvertTableToHTML table=${parentIncidentFields.custom_fields}

B.

!JsonToTable value=${parentIncidentFields.custom_fields}

C.

!ToTable data=${parentIncidentFields.custom_fields.incidentassignment}

D.

!ExtractHTMLTables html=${parentIncidentFields.custom_fields.incidentassignment}

Buy Now
Questions 9

An engineer needs to migrate Cortex XDR agents without internet connection from Cortex XSIAM tenant A to Cortex XSIAM tenant B. There is a broker configured for each tenant. This is the communication flow:

XDR agents < - > Broker A < - > XSIAM tenant A

XDR agents < - > Broker B < - > XSIAM tenant B

Which two steps should be taken before moving the agents? (Choose two.)

Options:

A.

Install a new Broker C on site B, and register it into Cortex XSIAM tenant A.

B.

Install a new Broker C on site and register it into Cortex XSIAM tenant B.

C.

Also register Broker A to Cortex XSIAM tenant B.

D.

Select all endpoints in the console and add a new Broker C as proxy.

Buy Now
Questions 10

A Cortex XSIAM engineer adds a disable injection and prevention rule for a specific running process. After an hour, the engineer disables the rule to reinstate the security capabilities, but the capabilities are not applied.

What is the explanation for this behavior?

Options:

A.

The engineer needs to restart the process to get back the security capabilities.

B.

The engineer needs a support exception to get back the security capabilities.

C.

The engineer needs to wait for the time period configured in the rule to pass first.

D.

The engineer can disable the rule, but security capabilities are not applied to the process.

Buy Now
Questions 11

When activating the Cortex XSIAM tenant, how is the data at rest configured with AES 128 encryption?

Options:

A.

Under Advanced - > Encryption Method, choose the desired encryption method during the initial setup of the tenant.

B.

Under Advanced, choose " BYOK, " and adhere to the wizard ' s instructions as outlined in the encryption method section.

C.

Create encryption keys with AES 128 and upload it securely through Cortex Gateway.

D.

Under Advanced - > Encryption Method, choose the desired encryption method after the initial setup of the tenant.

Buy Now
Questions 12

A Behavioral Threat Protection (BTP) alert is triggered with an action of " Prevented (Blocked) " on one of several application servers running Windows Server 2022. The investigation determines the involved processes to be legitimate core OS binaries, and the description from the triggered BTP rule is an acceptable risk for the company to allow the same activity in the future.

This type of activity is only expected on the endpoints that are members of the endpoint group " AppServers, " which already has a separate prevention policy rule with an exceptions profile named " Exceptions-AppServers " and a malware profile named " Malware-AppServers. "

The CGO that was terminated has the following properties:

SHA256: eb71ea69dd19f728ab9240565e8c7efb59821e19e3788e289301e1e74940c208

File path: C:\Windows\System32\cmd.exe

Digital Signer: Microsoft Corporation

How should the exception be created so that it is scoped as narrowly as possible to minimize the security gap?

Options:

A.

Create the exception via the alert itself, selecting the CGO hash, CGO signer, CGO process path, and applying the scope to the " Exceptions-AppServers " profile.

B.

Create a Disable Prevention Rule via Exceptions Configuration with the following selections:

12

C.

Create a Legacy Agent Exception via Exceptions Configuration with the following selections:

12

D.

Create the exception via the alert itself, selecting the CGO hash, CGO signer, CGO process path, and applying the scope to " Global. "

Buy Now
Questions 13

Which cytool command will look up the policy being applied to a Cortex XDR agent?

Options:

A.

cytool adaptive_policy interval 0

B.

cytool payload_execution query

C.

cytool adaptive_policy recalc

D.

cytool persist print agent_settings.db

Buy Now
Questions 14

An engineer wants to onboard data from a third-party vendor’s firewall. There is no content pack available for it, so the engineer creates custom data source integration and parsing rules to generate a dataset with the firewall data.

How can the analytics capabilities of Cortex XSIAM be used on the data?

Options:

A.

Create a behavioral indicator of compromise (BIOC) rule on the network fields (source IP, source port, target IP, target port. IP protocol).

B.

Create a data model rule with network fields mapped (source IP. source port, target IP. target port. IP protocol).

C.

Create a correlation rule on the network fields (source IP. source port, target IP. target port. IP protocol).

D.

Create a parsing rule and ensure the network fields exist (source IP. source port, target IP. target port. IP protocol).

Buy Now
Questions 15

Based on the _raw_log and XQL query information below, what will be the result(s) of the temp_value?

XSIAM-Engineer Question 15

Options:

A.

123

192.168.10.1

B.

20

C.

10.120.80.2

D.

149.235.219.208

59977

Buy Now
Questions 16

What is the reason all Broker VM options are greyed out when a user attempts to select a Broker VM as a download source in the Agent Settings profile?

Options:

A.

The Broker VM is offline.

B.

NTP is not synchronized properly on the Broker VM.

C.

Local Agent Setting applet is currently activated without SSL certificate.

D.

Local Agent Setting applet is currently activated without FQDN.

Buy Now
Questions 17

Using the integrationContext object, how is data stored and retrieved between integration command runs in Cortex XSIAM?

Options:

A.

The integrationContex object can only store strings, not key-value dictionaries.

B.

The integrationContex object is retrieved and set using the test-module command.

C.

The get_integration_context() method overrides the existing object that is stored.

D.

The integrationContex object supports get_integration_context() and set_integration_context().

Buy Now
Exam Code: XSIAM-Engineer
Exam Name: Palo Alto Networks XSIAM Engineer
Last Update: May 21, 2026
Questions: 59

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11