Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Palo Alto Networks Certified Detection and Remediation Analyst Question and Answers

Palo Alto Networks Certified Detection and Remediation Analyst

Last Update May 5, 2024
Total Questions : 91

We are offering FREE PCDRA Paloalto Networks exam questions. All you do is to just go and sign up. Give your details, prepare PCDRA free exam questions and then go for complete pool of Palo Alto Networks Certified Detection and Remediation Analyst test questions that will help you more.

PCDRA pdf

PCDRA PDF

$35  $99.99
PCDRA Engine

PCDRA Testing Engine

$42  $119.99
PCDRA PDF + Engine

PCDRA PDF + Testing Engine

$56  $159.99
Questions 1

While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires anexclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?

Options:

A.  

mark the incident as Unresolved

B.  

create a BIOC rule excluding this behavior

C.  

create an exception to prevent future false positives

D.  

mark the incident as Resolved – False Positive

Discussion 0
Questions 2

Which engine, of the following, in CortexXDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?

Options:

A.  

Sensor Engine

B.  

Causality Analysis Engine

C.  

Log Stitching Engine

D.  

Causality Chain Engine

Discussion 0
Questions 3

An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module canprevent this attack?

Options:

A.  

DDL Security

B.  

Hot Patch Protection

C.  

Kernel Integrity Monitor (KIM)

D.  

Dylib Hijacking

Discussion 0
Questions 4

Network attacks follow predictable patterns. If you interfere withany portion of this pattern, the attack will be neutralized. Which of the following statements is correct?

Options:

A.  

Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.

B.  

Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.

C.  

Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.

D.  

Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.

Discussion 0
Questions 5

When viewing the incident directly, what is the “assigned to” field value of a new Incident that was just reported to Cortex?

Options:

A.  

Pending

B.  

It is blank

C.  

Unassigned

D.  

New

Discussion 0
Questions 6

Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?

Options:

A.  

Security Manager Dashboard

B.  

Data Ingestion Dashboard

C.  

Security Admin Dashboard

D.  

Incident Management Dashboard

Discussion 0
Questions 7

Which statement regarding scripts in Cortex XDR is true?

Options:

A.  

Any version of Python script can be run.

B.  

The level of risk is assigned to the script upon import.

C.  

Any script can be imported including Visual Basic (VB) scripts.

D.  

The script is run on the machine uploading the script to ensure that it is operational.

Discussion 0
Questions 8

What is the standard installation disk space recommended to install a Broker VM?

Options:

A.  

1GB disk space

B.  

2GB disk space

C.  

512GB disk space

D.  

256GB disk space

Discussion 0
Questions 9

What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)

Options:

A.  

Automatically close the connections involved in malicious traffic.

B.  

Automatically kill the processes involved in malicious activity.

C.  

Automatically terminate the threads involved in malicious activity.

D.  

Automaticallyblock the IP addresses involved in malicious traffic.

Discussion 0