Summer Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

XDR-Engineer Sample Questions Answers

Questions 4

The most recent Cortex XDR agents are being installed at a newly acquired company. A list with endpoint types (i.e., OS, hardware, software) is provided to the engineer. What should be cross-referenced for the Linux systems listed regarding the OS types and OS versions supported?

Options:

A.

Content Compatibility Matrix

B.

Kernel Module Version Support

C.

End-of-Life Summary

D.

Agent Installer Certificate

Buy Now
Questions 5

When using Kerberos as the authentication method for Pathfinder, which two settings must be validated on the DNS server? (Choose two.)

Options:

A.

DNS forwarders

B.

Reverse DNS zone

C.

Reverse DNS records

D.

AD DS-integrated zones

Buy Now
Questions 6

Which action is being taken with the query below?

dataset = xdr_data

| fields agent_hostname, _time, _product

| comp latest as latest_time by agent_hostname, _product

| join type=inner (dataset = endpoints

| fields endpoint_name, endpoint_status, endpoint_type) as lookup lookup.endpoint_name = agent_hostname

| filter endpoint_status = ENUM.CONNECTED

| fields agent_hostname, endpoint_status, latest_time, _product

Options:

A.

Monitoring the latest activity of endpoints

B.

Identifying endpoints that have disconnected from the network

C.

Monitoring the latest activity of connected firewall endpoints

D.

Checking for endpoints with outdated agent versions

Buy Now
Questions 7

Multiple remote desktop users complain of in-house applications no longer working. The team uses macOS with Cortex XDR agents version 8.7.0, and the applications were previously allowed by disable prevention rules attached to the Exceptions Profile "Engineer-Mac." Based on the images below, what is a reason for this behavior?

Options:

A.

Endpoint IP address changed from 192.168.0.0 range to 192.168.100.0 range

B.

The Cloud Identity Engine is disconnected or removed

C.

XDR agent version was downgraded from 8.7.0 to 8.4.0

D.

Installation type changed from VDI to Kubernetes

Buy Now
Questions 8

A query is created that will run weekly via API. After it is tested and ready, it is reviewed in the Query Center. Which available column should be checked to determine how many compute units will be used when the query is run?

Options:

A.

Query Status

B.

Compute Unit Usage

C.

Simulated Compute Units

D.

Compute Unit Quota

Buy Now
Questions 9

Based on the image of a validated false positive alert below, which action is recommended for resolution?

Options:

A.

Create an alert exclusion for OUTLOOK.EXE

B.

Disable an action to the CGO Process DWWIN.EXE

C.

Create an exception for the CGO DWWIN.EXE for ROP Mitigation Module

D.

Create an exception for OUTLOOK.EXE for ROP Mitigation Module

Buy Now
Questions 10

Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?

Options:

A.

It will immediately execute

B.

It will not execute

C.

It will execute after one hour

D.

It will execute after the second attempt

Buy Now
Questions 11

After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a partially protected status. In which two places can insights into what is contributing to this status be located? (Choose two.)

Options:

A.

Management Audit Logs

B.

XQL query of the endpoints dataset

C.

All Endpoints page

D.

Asset Inventory

Buy Now
Questions 12

A cloud administrator reports high network bandwidth costs attributed to Cortex XDR operations and asks for bandwidth usage to be optimized without compromising agent functionality. Which two techniques should the engineer implement? (Choose two.)

Options:

A.

Configure P2P download sources for agent upgrades and content updates

B.

Enable minor content version updates

C.

Enable agent content management bandwidth control

D.

Deploy a Broker VM and activate the local agent settings applet

Buy Now
Questions 13

An engineer wants to automate the handling of alerts in Cortex XDR and defines several automation rules with different actions to be triggered based on specific alert conditions. Some alerts do not trigger the automation rules as expected. Which statement explains why the automation rules might not apply to certain alerts?

Options:

A.

They are executed in sequential order, so alerts may not trigger the correct actions if the rules are not configured properly

B.

They only apply to new alerts grouped into incidents by the system and only alerts that generateincidents trigger automation actions

C.

They can only be triggered by alerts with high severity; alerts with low or informational severity will not trigger the automation rules

D.

They can be applied to any alert, but they only work if the alert is manually grouped into an incident by the analyst

Buy Now
Questions 14

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

Options:

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

Buy Now
Questions 15

Some company employees are able to print documents when working from home, but not on network-attached printers, while others are able to print only to file. What can be inferred about the affected users’ inability to print?

Options:

A.

They may be attached to the default extensions policy and profile

B.

They may have a host firewall profile set to block activity to all network-attached printers

C.

They may have different disk encryption profiles that are not allowing print jobs on encrypted files

D.

They may be on different device extensions profiles set to block different print jobs

Buy Now
Exam Code: XDR-Engineer
Exam Name: Palo Alto Networks XDR Engineer
Last Update: Jul 10, 2025
Questions: 50
$66  $164.99
$50  $124.99
$42  $104.99
buy now XDR-Engineer