Palo Alto Networks XDR-Engineer - Palo Alto Networks XDR Engineer Exam
Page: 2 / 12
Total 59 questions
Question #6 (Topic: Exam A)
What are two possible actions that can be triggered by a dashboard drilldown? (Choose two.)
A. Initiate automated response actions.
B. Navigate to a different dashboard.
C. Send alerts to console users.
D. Link to an XQL query.
Answer: BD
Question #7 (Topic: Exam A)
An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources.
Which section of the parsing rule should the administrator use to define these reusable rules in Cortex XDR?
Which section of the parsing rule should the administrator use to define these reusable rules in Cortex XDR?
A. RULE
B. INGEST
C. FILTER
D. CONST
Answer: A
Question #8 (Topic: Exam A)
Which method will drop undesired logs and reduce the amount of data being ingested?
A. [INGEST:vendor= “vendor”, product= “product”, target_dataset= “vendor_product_raw”, no_hit=drop] filter _raw_log not contains “undesired logs”;
B. [COLLECT:vendor= “vendor”, product= “product”, target_dataset=*, no_hit=drop] drop _raw_log contains “undesired logs”;
C. [INGEST:vendor= “vendor”, product= “product”, target_brokers= “vendor_product_raw”, no_hit=keep] filter _raw_log not contains “undesired logs”;
D. [COLLECT:vendor= “vendor”, product= “product”, target_brokers=*, no_hit=drop] drop _raw_log contains “undesired logs”;
Answer: B
Question #9 (Topic: Exam A)
A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appear as expected.
What may be the cause of this behavior?
What may be the cause of this behavior?
A. The XDR Collector is dropping the logs.
B. The filter stage is dropping the logs.
C. The Broker VM is offline.
D. The parsing rule corrupted the database.
Answer: B
Question #10 (Topic: Exam A)
What should be configured in Cortex XDR to integrate asset data from Microsoft Azure for better visibility and incident investigation?
A. Cloud Inventory
B. Cloud Identity Engine
C. Microsoft 365
D. Azure Network Watcher
Answer: A