New Year Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Paloalto Networks XDR-Analyst - Palo Alto Networks XDR Analyst

Page: 1 / 3
Total 91 questions

Which type of IOC can you define in Cortex XDR?

A.

Destination IP Address

B.

Source IP Address

C.

Source port

D.

Destination IP Address: Destination

In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?

A.

Agent Proxy

B.

Agent Installer and Content Caching

C.

Syslog Collector

D.

CSV Collector

Which type of BIOC rule is currently available in Cortex XDR?

A.

Threat Actor

B.

Discovery

C.

Network

D.

Dropper

When investigating security events, which feature in Cortex XDR is useful for reverting the changes on the endpoint?

A.

Remediation Automation

B.

Machine Remediation

C.

Automatic Remediation

D.

Remediation Suggestions

A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?

A.

It is true positive.

B.

It is false positive.

C.

It is a false negative.

D.

It is true negative.

Which of the following paths will successfully activate Remediation Suggestions?

A.

Incident View > Actions > Remediation Suggestions

B.

Causality View > Actions > Remediation Suggestions

C.

Alerts Table > Right-click on a process node > Remediation Suggestions

D.

Alerts Table > Right-click on an alert > Remediation Suggestions

What contains a logical schema in an XQL query?

A.

Bin

B.

Array expand

C.

Field

D.

Dataset

What is the function of WildFire for Cortex XDR?

A.

WildFire runs in the cloud and analyses alert data from the XDR agent to check for behavioural threats.

B.

WildFire is the engine that runs on the local agent and determines whether behavioural threats are occurring on the endpoint.

C.

WildFire accepts and analyses a sample to provide a verdict.

D.

WildFire runs entirely on the agent to quickly analyse samples and provide a verdict.

In incident-related widgets, how would you filter the display to only show incidents that were “starred”?

A.

Create a custom XQL widget

B.

This is not currently supported

C.

Create a custom report and filter on starred incidents

D.

Click the star in the widget

Which of the following best defines the Windows Registry as used by the Cortex XDR agent?

A.

a hierarchical database that stores settings for the operating system and for applications

B.

a system of files used by the operating system to commit memory that exceeds the available hardware resources. Also known as the “swap”

C.

a central system, available via the internet, for registering officially licensed versions of software to prove ownership

D.

a ledger for maintaining accurate and up-to-date information on total disk usage and disk space remaining available to the operating system