Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Paloalto Networks PCDRA - Palo Alto Networks Certified Detection and Remediation Analyst

Page: 2 / 3
Total 91 questions

How can you pivot within a row to Causality view and Timeline views for further investigate?

A.

Using the Open Card Only

B.

Using the Open Card and Open Timeline actions respectively

C.

You can't pivot within a row to Causality view and Timeline views

D.

Using Open Timeline Actions Only

Which Exploit Prevention Module (EPM) provides better entropy for randomization of memory locations?

A.

Memory Limit Heap spray check

B.

UASLR

C.

JIT Mitigation

D.

DLL Security

What is the function of WildFire for Cortex XDR?

A.

WildFire runs in the cloud and analyses alert data from the XDR agent to check for behavioural threats.

B.

WildFire is the engine that runs on the local agent and determines whether behavioural threats are occurring on the endpoint.

C.

WildFire accepts and analyses a sample to provide a verdict.

D.

WildFire runs entirely on the agent to quickly analyse samples and provide a verdict.

What kind of malware uses encryption, data theft, denial of service, and possibly harassment to take advantage of a victim?

A.

Ransomware

B.

Worm

C.

Keylogger

D.

Rootkit

In Cortex XDR management console scheduled reports can be forwarded to which of the following applications/services?

A.

Salesforce

B.

Jira

C.

Service Now

D.

Slack

Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?

A.

Hash Verdict Determination

B.

Behavioral Threat Protection

C.

Restriction Policy

D.

Child Process Protection

What types of actions you can execute with live terminal session?

A.

Manage Network configurations, Quarantine Files, Run PowerShell scripts

B.

Manage Processes, Manage Files, Run Operating System Commands, Run Ruby Commands and Scripts

C.

Apply patches, Reboot System, send notification for end user, Run Python Commands and Scripts

D.

Manage Processes, Manage Files, Run Operating System Commands, Run Python Commands and Scripts

Can you disable the ability to use the Live Terminal feature in Cortex XDR?

A.

Yes, via the Cortex XDR console or with an installation switch.

B.

No, a separate installer package without Live Terminal is required.

C.

No, it is a required feature of the agent.

D.

Yes, via Agent Settings Profile.

What is an example of an attack vector for ransomware?

A.

Performing DNS queries for suspicious domains

B.

Performing SSL Decryption on an endpoint

C.

Phishing emails containing malicious attachments

D.

A URL filtering feature enabled on a firewall

Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?

A.

The endpoint is disconnected or the verdict from WildFire is of a type benign.

B.

The endpoint is disconnected or the verdict from WildFire is of a type unknown.

C.

The endpoint is disconnected or the verdict from WildFire is of a type malware.

D.

The endpoint is disconnected or the verdict from WildFire is of a type grayware.