Palo Alto Networks PCDRA - Palo Alto Networks Certified Detection and Remediation Analyst Exam

Question #11 (Topic: Exam A)
In incident-related widgets, how would you filter the display to only show incidents that were “starred”?
A. Create a custom XQL widget B. This is not currently supported C. Create a custom report and filter on starred incidents D. Click the star in the widget
Answer: D
Question #12 (Topic: Exam A)
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page B. under Response --> Action Center C. under the gear icon --> Agent Audit Logs D. on the HUB page at apps.paloaltonetworks.com
Answer: A
Question #13 (Topic: Exam A)
What does the following output tell us?
A. There is one low severity incident. B. Host shpapy_win10 had the most vulnerabilities. C. There is one informational severity alert. D. This is an actual output of the Top 10 hosts with the most malware.
Answer: A
Question #14 (Topic: Exam A)
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine B. Causality Analysis Engine C. Log Stitching Engine D. Causality Chain Engine
Answer: B
Question #15 (Topic: Exam A)
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor B. Discovery C. Network D. Dropper
Answer: D
Download Exam
Page: 3 / 20
Total 96 questions