Official Bank 0/48

Palo Alto XDR Engineer (Palo Alto XDR Engineer) - PaloAlto Networks Exam Questions

Last updated on July 22, 2026

97% Exam Compliance
48 Total Questions
1
Question
[Detection Engineering] During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Windows endpoints by non-technical business units. Which rule type should be implemented?
Options
A Correlation
B Indicator of Compromise (IOC)
C Behavioral Indicator of Compromise (BIOC)
D Analytics Behavioral Indicator of Compromise (ABIOC)
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
[Maintenance and Troubleshooting] Log events from a previously deployed Windows XDR Collector agent are no longer being observed in the console after an OS upgrade. Which aspect of the log events is the probable cause of this behavior?
Options
A They are in Filebeat format
B They are in Winlogbeat format
C They are less than 1MB
D They are greater than 5MB
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
[Dashboards and Reporting]

What are two possible actions that can be triggered by a dashboard drilldown? (Choose two.)
Select 2
Options
A Link to an XQL query
B Initiate automated response actions
C Send alerts to console users
D Navigate to a different dashboard
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
[Data Ingestion and Integration]

What should be configured in Cortex XDR to integrate asset data from Microsoft Azure for better visibility and incident investigation?
Options
A Azure Network Watcher
B Microsoft 365
C Cloud Identity Engine
D Cloud Inventory
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
[Maintenance and Troubleshooting] An insider compromise investigation has been requested to provide evidence of an unauthorized removable drive being mounted on a company laptop. Cortex XDR agent is installed with default prevention agent settings profile and default extension "Device Configuration" profile. Where can an engineer find the evidence?
Options
A Check Host Inventory -> Mounts
B dataset = xdr_data | filter event_type = ENUM.MOUNT and event_sub_type =
ENUM.MOUNT_DRIVE_MOUNT
C preset = device_control
D The requested data requires additional configuration to be captured
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.