Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

XDR-Engineer Palo Alto Networks XDR Engineer Questions and Answers

Questions 4

An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by automatically isolating the affected endpoint and notifying the security team via email. The playbook should only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)

Options:

A.

Alert severity is High

B.

Alert source is Cortex XDR Analytics

C.

Alert category is Malware

D.

Alert status is New

Buy Now
Questions 5

What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?

Options:

A.

Sending endpoint logs to the NGFW for analysis

B.

Blocking network traffic based on Cortex XDR detections

C.

Enabling additional analysis through enhanced application logging

D.

Automated downloading of malware signatures from the NGFW

Buy Now
Questions 6

When using Kerberos as the authentication method for Pathfinder, which two settings must be validated on the DNS server? (Choose two.)

Options:

A.

DNS forwarders

B.

Reverse DNS zone

C.

Reverse DNS records

D.

AD DS-integrated zones

Buy Now
Questions 7

The most recent Cortex XDR agents are being installed at a newly acquired company. A list with endpoint types (i.e., OS, hardware, software) is provided to the engineer. What should be cross-referenced for the Linux systems listed regarding the OS types and OS versions supported?

Options:

A.

Content Compatibility Matrix

B.

Kernel Module Version Support

C.

End-of-Life Summary

D.

Agent Installer Certificate

Buy Now
Questions 8

An XDR engineer is creating a correlation rule to monitor login activity on specific systems. When the activity is identified, an alert is created. The alerts are being generated properly but are missing the username when viewed. How can the username information be included in the alerts?

Options:

A.

Select “Initial Access” in the MITRE ATT&CK mapping to include the username

B.

Update the query in the correlation rule to include the username field

C.

Add a mapping for the username field in the alert fields mapping

D.

Add a drill-down query to the alert which pulls the username field

Buy Now
Questions 9

Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?

Options:

A.

Add entries in Configuration section of Security Settings

B.

Add entries in the Allowed Domains section of Security Settings for the tenant

C.

Add entries in Exceptions Configuration section of Isolation Exceptions

D.

Add entries in Response Actions section of Agent Settings profile

Buy Now
Questions 10

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

Options:

A.

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Buy Now
Questions 11

How long is data kept in the temporary hot storage cache after being queried from cold storage?

Options:

A.

1 hour, re-queried to a maximum of 12 hours

B.

24 hours, re-queried to a maximum of 7 days

C.

24 hours, re-queried to a maximum of 14 days

D.

1 hour, re-queried to a maximum of 24 hours

Buy Now
Questions 12

What should be configured in Cortex XDR to integrate asset data from Microsoft Azure for better visibility and incident investigation?

Options:

A.

Azure Network Watcher

B.

Cloud Identity Engine

C.

Cloud Inventory

D.

Microsoft 365

Buy Now
Questions 13

When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is used to turn off a component on a Windows machine?

Options:

A.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" stop

B.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop

C.

"C:\Program Files\Palo Alto Networks\Traps\xdr.exe" -s stop

D.

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" occp

Buy Now
Questions 14

When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?

Options:

A.

Conduct an XQL query for NGFW log data

B.

Wait for an incident that involves the NGFW to populate

C.

Confirm that the selected device has a valid certificate

D.

Retrieve device certificate from NGFW dashboard

Buy Now
Questions 15

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

Options:

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

Buy Now
Exam Code: XDR-Engineer
Exam Name: Palo Alto Networks XDR Engineer
Last Update: Jun 1, 2025
Questions: 50

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now XDR-Engineer testing engine

PDF (Q&A)

$36.75  $104.99
buy now XDR-Engineer pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 04 Jun 2025