Palo Alto Networks Certified XDR Engineer Free Sample Questions

20 free sample questions200 in the full practice test

Try simulator

xdr-engineer Sample Questions

  1. Question 1

    A global financial institution is deploying Cortex XDR across a hybrid environment with 50,000 endpoints. The primary objective is to centralize log collection from legacy syslog devices, cloud flow logs, and Palo Alto Networks NGFWs, while minimizing latency for real-time threat hunting. The security architect must decide on the optimal Broker VM architecture. Given the requirements for high availability, geographic distribution, and performance, which Broker VM deployment strategy should the architect recommend?

    Answer and explanation

    Correct answer: C

    For a large, geographically dispersed hybrid environment, a distributed Broker VM cluster is the optimal design. This architecture provides high availability through failover, reduces latency by processing logs closer to the source, and offers horizontal scalability by adding more nodes. A single cluster creates a single point of failure and introduces significant latency. Independent instances lack the centralized management and automatic failover capabilities inherent in a cluster. A cloud-only deployment would create unnecessary latency and cost for forwarding on-premises logs to the cloud for processing.

  2. Question 2

    Multiple answers

    A security engineer is creating a new endpoint security profile for a group of developers who frequently work with unsigned binaries and custom scripts for testing purposes. The goal is to provide strong protection without impeding their development workflow. Which TWO settings within the Malware Protection profile should be configured to achieve this balance? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    Enabling "Behavioral Threat Protection" is crucial as it analyzes process behavior rather than just static signatures, providing protection against malicious actions from legitimate-looking developer tools.

    Setting "Unsigned Executable Files" to "Report" allows developers to run their custom binaries while still giving the security team visibility into this activity without blocking them.

  3. Question 3

    True or False: The Cortex XDR Broker VM can be configured with a Syslog Collector applet to receive, parse, and forward logs from third-party devices to the Cortex Data Lake.

    Answer and explanation

    Correct answer: A

    True. The Broker VM is the primary component for collecting logs from on-premises third-party sources. It uses applets, such as the Syslog Collector applet, to ingest data from various sources like firewalls, proxies, and servers, then normalizes and forwards this data to the Cortex Data Lake for analysis.

  4. Question 4

    A healthcare organization has recently deployed Cortex XDR and is concerned about sophisticated lateral movement techniques. Their environment consists of Windows servers hosting electronic health record (EHR) systems and workstations used by clinical staff. The threat intelligence team has warned about adversaries using legitimate administrative tools like PsExec for lateral movement after gaining an initial foothold. The SOC manager wants to create a high-fidelity detection rule that specifically identifies anomalous PsExec usage targeting critical EHR servers.

    The EHR servers are all part of an Active Directory group named "EHR-Servers". Normal administrative activity originates from a dedicated set of bastion hosts within the 10.100.50.0/24 subnet. The SOC team has observed that attackers often launch PsExec from compromised user workstations, which are in different subnets. The goal is to generate an alert only when PsExec is used to connect to an EHR server from a source that is NOT one of the authorized bastion hosts.

    Which XQL query would be most effective for creating a Correlation Rule to detect this specific suspicious activity?

    Answer and explanation

    Correct answer: D

    This XQL query is the most accurate and effective. It correctly filters for process launch events (event_type = PROCESS_LAUNCH), specifically for psexec.exe, targets the critical servers by their endpoint group (agent_hostname in (group_name="EHR-Servers")), and critically, excludes legitimate traffic from the bastion host subnet (not actor_ip_address in("10.100.50.0/24")). The other options are flawed: one only counts usage, another incorrectly filters on pre-built stories and the wrong IP field, and the third checks for a causality ID without filtering by the crucial source IP.

  5. Question 5

    During a routine health check, a Cortex XDR administrator notices that several endpoints in a remote branch office have not checked in for over 24 hours. The administrator has confirmed network connectivity between the branch office and the corporate data center. The cytool command-line utility is available on one of the affected endpoints. Which cytool command should the administrator run first to diagnose the agent's communication status with the Cortex XDR console?

    Answer and explanation

    Correct answer: B

    The cytool checkin command forces the Cortex XDR agent to attempt an immediate check-in with the server. The output provides detailed information about the connection attempt, including TLS handshake errors, DNS resolution problems, or server connectivity issues. This makes it the most direct first step for diagnosing communication problems. cytool status provides general agent status but doesn't actively test connectivity. cytool runtime query is for querying agent processes, and cytool persist list shows the agent's database of persistent data.

  6. Question 6

    A security engineer is designing a data ingestion pipeline using a Broker VM to collect logs from multiple on-premises sources. The sources include a custom application generating logs in a unique key-value format, a Cisco ASA firewall sending standard syslog, and a database server sending audit logs over TCP. The goal is to normalize all these logs into the Cortex XDR format before forwarding them to the Cortex Data Lake. Which sequence of components and actions within the Broker VM correctly represents the processing flow for the custom application logs?

    flowchart LR subgraph Broker_VM A[Collector Applet] --> B{Parsing Rule}; B --> C[Normalization]; C --> D[Forwarder]; end subgraph Custom_App E[Log Source] end subgraph CDL F[Cortex Data Lake] end E --> A; D --> F;

    Answer and explanation

    Correct answer: C

    The correct flow for custom logs sent over TCP is to first receive them with a generic TCP Collector applet. Since the format is unique, a standard parser won't work. A custom Parsing Rule, typically using RegEx, must be applied to extract the fields. After parsing, the data is normalized to the XDR schema and then forwarded to the Cortex Data Lake. A Syslog Collector expects a specific syslog format, not a generic TCP stream. A Filebeat applet is used for collecting logs from files.

  7. Question 7

    A Cortex XDR administrator is configuring user roles for a multi-tiered SOC. The requirements are to create a 'Tier 1 Analyst' role with view-only access to incidents and endpoint data, but no ability to perform response actions like isolating an endpoint. Which specific permission should be explicitly denied or not granted when creating this custom role?

    Answer and explanation

    Correct answer: C

    The 'Endpoint Administration' permission grants the ability to perform response actions on endpoints, such as isolation, termination of processes, and file retrieval. To create a view-only role for a Tier 1 Analyst, this permission must be withheld. Permissions like 'View Incidents' and 'Run Queries' are necessary for their investigative duties.

  8. Question 8

    An organization is using the Host Firewall module on Cortex XDR to enforce network policies on its endpoints. The security team needs to create a rule that blocks all inbound traffic to developer workstations from the corporate guest Wi-Fi network (172.16.32.0/20), but allows all other traffic. How should this rule be configured in the Host Firewall profile?

    Answer and explanation

    Correct answer: C

    The requirement is to block inbound traffic from a specific subnet. Therefore, the rule must be configured with Action: Block, Direction: Inbound, and the Remote Address set to the guest Wi-Fi subnet 172.16.32.0/20. Since the default rule is typically 'Allow All', this specific block rule will take precedence for matching traffic, achieving the desired outcome.

  9. Question 9

    A SOC analyst is investigating an alert and needs to find all DNS queries made by a specific host (workstation-123.acme.corp) in the last 7 days that were not to the internal corporate DNS servers (10.1.1.10, 10.2.1.10). Which XQL query will retrieve this information most efficiently?

    Answer and explanation

    Correct answer: C

    This query correctly filters the xdr_data dataset for DNS lookup events from the specified host. The key part is and not (action_device_ip_address = "10.1.1.10" or action_device_ip_address = "10.2.1.10"), which accurately excludes queries directed to the internal DNS servers. action_device_ip_address is the field that contains the IP address of the DNS server that received the query.

  10. Question 10

    An XDR engineer is troubleshooting a data ingestion issue where logs from a custom application are being received by the Broker VM but are not appearing in the XDR console. The engineer suspects a problem with the custom parsing rule. Which component or log file should be checked first to validate if the parsing rule is correctly extracting fields from the raw logs?

    Answer and explanation

    Correct answer: B

    The Broker VM uses Fluentd for its logging pipeline. When a parsing rule is applied, the results, including successful field extractions and any errors, are logged in the fluentd.log file on the Broker VM's file system. This log is the most direct place to verify the behavior of a custom parsing rule and diagnose issues with field extraction or data normalization.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 200 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon