Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

Palo Alto Networks XDR Engineer Question and Answers

Palo Alto Networks XDR Engineer

Last Update Oct 2, 2025
Total Questions : 50

We are offering FREE XDR-Engineer Paloalto Networks exam questions. All you do is to just go and sign up. Give your details, prepare XDR-Engineer free exam questions and then go for complete pool of Palo Alto Networks XDR Engineer test questions that will help you more.

XDR-Engineer pdf

XDR-Engineer PDF

$42  $104.99
XDR-Engineer Engine

XDR-Engineer Testing Engine

$50  $124.99
XDR-Engineer PDF + Engine

XDR-Engineer PDF + Testing Engine

$66  $164.99
Questions 1

After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a partially protected status. In which two places can insights into what is contributing to this status be located? (Choose two.)

Options:

A.  

Management Audit Logs

B.  

XQL query of the endpoints dataset

C.  

All Endpoints page

D.  

Asset Inventory

Discussion 0
Questions 2

Which configuration profile option with an available built-in template can be applied to both Windows and Linux systems by using XDR Collector?

Options:

A.  

Filebeat

B.  

HTTP Collector template

C.  

XDR Collector settings

D.  

Winlogbeat

Discussion 0
Questions 3

A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive Identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices. What may be the reason for the issue?

Options:

A.  

The XDR tenant is not in the same region as the Cloud Identity Engine

B.  

The Cloud Identity Engine plug-in has not been installed and configured

C.  

The Cloud Identity Engine needs to be activated in all global regions

D.  

The ITDR add-on is not compatible with the Cloud Identity Engine

Discussion 0
Questions 4

During the deployment of a Broker VM in a high availability (HA) environment, after configuring the Broker VM FQDN, an XDR engineer must ensure agent installer availability and efficient content caching to maintain performance consistency across failovers. Which additionalconfiguration steps should the engineer take?

Options:

A.  

Use shared SSL certificates and keys for all Broker VMs and configure a single IP address for failover

B.  

Upload the-signed SSL server certificate and key and deploy a load balancer

C.  

Deploy a load balancer and configure SSL termination at the load balancer

D.  

Enable synchronized session persistence across Broker VMs and use a self-signed certificate and key

Discussion 0
Questions 5

How are dynamic endpoint groups created and managed in Cortex XDR?

Options:

A.  

Endpoint groups require intervention to update the group with new endpoints when a new device is added to the network

B.  

Each endpoint can belong to multiple groups simultaneously, allowing different security policies to be applied to the same device at the same time

C.  

After an endpoint group is created, its assigned security policy cannot be changed without deleting and recreating the group

D.  

Endpoint groups are defined based on fields such as OS type, OS version, and network segment

Discussion 0
Questions 6

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

Options:

A.  

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.  

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.  

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.  

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Discussion 0
Questions 7

How long is data kept in the temporary hot storage cache after being queried from cold storage?

Options:

A.  

1 hour, re-queried to a maximum of 12 hours

B.  

24 hours, re-queried to a maximum of 7 days

C.  

24 hours, re-queried to a maximum of 14 days

D.  

1 hour, re-queried to a maximum of 24 hours

Discussion 0
Questions 8

What will enable a custom prevention rule to block specific behavior?

Options:

A.  

A correlation rule added to an Agent Blocking profile

B.  

A custom behavioral indicator of compromise (BIOC) added to an Exploit profile

C.  

A custom behavioral indicator of compromise (BIOC) added to a Restriction profile

D.  

A correlation rule added to a Malware profile

Discussion 0
Questions 9

A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appear as expected. What may be the cause of this behavior?

Options:

A.  

The Broker VM is offline

B.  

The parsing rule corrupted the database

C.  

The filter stage is dropping the logs

D.  

The XDR Collector is dropping the logs

Discussion 0
Questions 10

Multiple remote desktop users complain of in-house applications no longer working. The team uses macOS with Cortex XDR agents version 8.7.0, and the applications were previously allowed by disable prevention rules attached to the Exceptions Profile "Engineer-Mac." Based on the images below, what is a reason for this behavior?

Options:

A.  

Endpoint IP address changed from 192.168.0.0 range to 192.168.100.0 range

B.  

The Cloud Identity Engine is disconnected or removed

C.  

XDR agent version was downgraded from 8.7.0 to 8.4.0

D.  

Installation type changed from VDI to Kubernetes

Discussion 0
Questions 11

A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:

    All devices are running healthy Cortex XDR agents.

    A single host-based firewall rule to block all outbound RDP is implemented.

    The policy hosting the profile containing the rule applies to all Windows endpoints.

    The logic within the firewall rule is adequate.

    Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.

    Network location configuration in Agent Settings is enabled on all Windows endpoints.What is the likely reason the RDP connections are not being blocked?

Options:

A.  

The profile's default action for outbound traffic is set to Allow

B.  

The pertinent host-based firewall rule group is only applied to external rule groups

C.  

Report mode is set to Enabled in the report settings under the profile configuration

D.  

The pertinent host-based firewall rule group is only applied to internal rule groups

Discussion 0
Questions 12

An engineer is building a dashboard to visualize the number of alerts from various sources. One of the widgets from the dashboard is shown in the image below:

The engineer wants to configure a drilldown on this widget to allow dashboard users to select any of the alert names and view those alerts with additional relevant details. The engineer has configured the following XQL query to meet the requirement:

dataset = alerts

| fields alert_name, description, alert_source, severity, original_tags, alert_id, incident_id

| filter alert_name =

| sort desc _time

How will the engineer complete the third line of the query (filter alert_name =) to allow dynamic filtering on a selected alert name?

Options:

A.  

$y_axis.value

B.  

$x_axis.value

C.  

$x_axis.name

D.  

$y_axis.name

Discussion 0
Questions 13

What will be the output of the function below?

L_TRIM("a* aapple", "a")

Options:

A.  

' aapple'

B.  

" aapple"

C.  

"pple"

D.  

" aapple-"

Discussion 0
Questions 14

How can a customer ingest additional events from a Windows DHCP server into Cortex XDR with minimal configuration?

Options:

A.  

Activate Windows Event Collector (WEC)

B.  

Install the XDR Collector

C.  

Enable HTTP collector integration

D.  

Install the Cortex XDR agent

Discussion 0
Questions 15

When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that logs are being ingested successfully after a device is selected and verified?

Options:

A.  

Conduct an XQL query for NGFW log data

B.  

Wait for an incident that involves the NGFW to populate

C.  

Confirm that the selected device has a valid certificate

D.  

Retrieve device certificate from NGFW dashboard

Discussion 0