Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Paloalto Networks Security Operations XDR-Engineer Questions and answers with ValidTests

Exam XDR-Engineer All Questions
Exam XDR-Engineer Premium Access

View all detail and faqs for the XDR-Engineer exam

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

Options:

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

Expert Solution
Questions # 12:

Multiple remote desktop users complain of in-house applications no longer working. The team uses macOS with Cortex XDR agents version 8.7.0, and the applications were previously allowed by disable prevention rules attached to the Exceptions Profile "Engineer-Mac." Based on the images below, what is a reason for this behavior?

Question # 12

Options:

A.

Endpoint IP address changed from 192.168.0.0 range to 192.168.100.0 range

B.

The Cloud Identity Engine is disconnected or removed

C.

XDR agent version was downgraded from 8.7.0 to 8.4.0

D.

Installation type changed from VDI to Kubernetes

Expert Solution
Questions # 13:

What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?

Options:

A.

Sending endpoint logs to the NGFW for analysis

B.

Blocking network traffic based on Cortex XDR detections

C.

Enabling additional analysis through enhanced application logging

D.

Automated downloading of malware signatures from the NGFW

Expert Solution
Questions # 14:

Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?

Question # 14

Options:

A.

It will immediately execute

B.

It will not execute

C.

It will execute after one hour

D.

It will execute after the second attempt

Expert Solution
Questions # 15:

Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which endpoint(s) data will be accessible?

Question # 15

Options:

A.

E1 only

B.

E2 only

C.

E1, E2, and E3

D.

E1, E2, E3, and E4

Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions