Summer Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dealsixty

XDR-Engineer Exam Dumps - Paloalto Networks Security Operations Questions and Answers

Question # 4

What are two possible actions that can be triggered by a dashboard drilldown? (Choose two.)

Options:

A.

Navigate to a different dashboard

B.

Initiate automated response actions

C.

Link to an XQL query

D.

Send alerts to console users

Buy Now
Question # 5

An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts by automatically isolating the affected endpoint and notifying the security team via email. The playbook should only trigger for alerts generated by the Cortex XDR analytics engine, not custom BIOCs. Which two conditions should the engineer include in the playbook trigger to meet these requirements? (Choose two.)

Options:

A.

Alert severity is High

B.

Alert source is Cortex XDR Analytics

C.

Alert category is Malware

D.

Alert status is New

Buy Now
Question # 6

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

Options:

A.

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Buy Now
Question # 7

What will be the output of the function below?

L_TRIM("a* aapple", "a")

Options:

A.

' aapple'

B.

" aapple"

C.

"pple"

D.

" aapple-"

Buy Now
Question # 8

An analyst considers an alert with the category of lateral movement to be allowed and not needing to be checked in the future. Based on the image below, which action can an engineer take to address the requirement?

Options:

A.

Create a behavioral indicator of compromise (BIOC) suppression rule for the parent process and the specific BIOC: Lateral movement

B.

Create an alert exclusion rule by using the alert source and alert name

C.

Create a disable injection and prevention rule for the parent process indicated in the alert

D.

Create an exception rule for the parent process and the exact command indicated in the alert

Buy Now
Question # 9

A query is created that will run weekly via API. After it is tested and ready, it is reviewed in the Query Center. Which available column should be checked to determine how many compute units will be used when the query is run?

Options:

A.

Query Status

B.

Compute Unit Usage

C.

Simulated Compute Units

D.

Compute Unit Quota

Buy Now
Question # 10

When using Kerberos as the authentication method for Pathfinder, which two settings must be validated on the DNS server? (Choose two.)

Options:

A.

DNS forwarders

B.

Reverse DNS zone

C.

Reverse DNS records

D.

AD DS-integrated zones

Buy Now
Question # 11

How are dynamic endpoint groups created and managed in Cortex XDR?

Options:

A.

Endpoint groups require intervention to update the group with new endpoints when a new device is added to the network

B.

Each endpoint can belong to multiple groups simultaneously, allowing different security policies to be applied to the same device at the same time

C.

After an endpoint group is created, its assigned security policy cannot be changed without deleting and recreating the group

D.

Endpoint groups are defined based on fields such as OS type, OS version, and network segment

Buy Now
Question # 12

An engineer wants to automate the handling of alerts in Cortex XDR and defines several automation rules with different actions to be triggered based on specific alert conditions. Some alerts do not trigger the automation rules as expected. Which statement explains why the automation rules might not apply to certain alerts?

Options:

A.

They are executed in sequential order, so alerts may not trigger the correct actions if the rules are not configured properly

B.

They only apply to new alerts grouped into incidents by the system and only alerts that generateincidents trigger automation actions

C.

They can only be triggered by alerts with high severity; alerts with low or informational severity will not trigger the automation rules

D.

They can be applied to any alert, but they only work if the alert is manually grouped into an incident by the analyst

Buy Now
Question # 13

A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appear as expected. What may be the cause of this behavior?

Options:

A.

The Broker VM is offline

B.

The parsing rule corrupted the database

C.

The filter stage is dropping the logs

D.

The XDR Collector is dropping the logs

Buy Now
Exam Code: XDR-Engineer
Exam Name: Palo Alto Networks XDR Engineer
Last Update: May 18, 2025
Questions: 50
XDR-Engineer pdf

XDR-Engineer PDF

$34  $84.99
XDR-Engineer Engine

XDR-Engineer Testing Engine

$38  $94.99
XDR-Engineer PDF + Engine

XDR-Engineer PDF + Testing Engine

$54  $134.99