Palo Alto Networks XDR-Engineer - Palo Alto Networks XDR Engineer Exam
Page: 3 / 12
Total 59 questions
Question #11 (Topic: Exam A)
A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:
All devices are running healthy Cortex XDR agents.
A single host-based firewall rule to block all outbound RDP is implemented.
The policy hosting the profile containing the rule applies to all Windows endpoints.
The logic within the firewall rule is adequate.
Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.
Network location configuration in Agent Settings is enabled on all Windows endpoints.
What is the likely reason the RDP connections are not being blocked?
All devices are running healthy Cortex XDR agents.
A single host-based firewall rule to block all outbound RDP is implemented.
The policy hosting the profile containing the rule applies to all Windows endpoints.
The logic within the firewall rule is adequate.
Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.
Network location configuration in Agent Settings is enabled on all Windows endpoints.
What is the likely reason the RDP connections are not being blocked?
A. The pertinent host-based firewall rule group is only applied to external rule groups.
B. Report mode is set to Enabled in the report settings under the profile configuration.
C. The pertinent host-based firewall rule group is only applied to internal rule groups.
D. The profile’s default action for outbound traffic is set to Allow.
Answer: C
Question #12 (Topic: Exam A)
Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?
A.
B.
C.
D.
B.
C.
D.
Answer: D
Question #13 (Topic: Exam A)
A multinational company with over 300,000 employees has recently deployed Cortex XDR in North America. The solution includes the Identity Threat Detection and Response (ITDR) add-on, and the Cortex team has onboarded the Cloud Identity Engine to the North American tenant. After waiting the required soak period and deploying enough agents to receive identity and threat analytics detections, the team does not see user, group, or computer details for individuals from the European offices.
What may be the reason for the issue?
What may be the reason for the issue?
A. The Cloud Identity Engine plug-in has not been installed and configured.
B. The Cloud Identity Engine needs to be activated in all global regions.
C. The ITDR add-on is not compatible with the Cloud Identity Engine.
D. The XDR tenant is not in the same region as the Cloud Identity Engine.
Answer: B
Question #14 (Topic: Exam A)
Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?
A. Add entries in the Allowed Domains section of Security Settings for the tenant.
B. Add entries in Configuration section of Security Settings.
C. Add entries in Response Actions section of Agent Settings profile.
D. Add entries in Exceptions Configuration section of Isolation Exceptions.
Answer: D
Question #15 (Topic: Exam A)
When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is used to turn off a component on a Windows machine?
A. C:\Program Files\Palo Alto Networks\Traps\cytool.exe stop <component>
B. C:\Program Files\Palo Alto Networks\Traps\xdr.exe runtime stop <component>
C. C:\Program Files\Palo Alto Networks\Traps\cytool.exe runtime stop <component>
D. C:\Program Files\Palo Alto Networks\Traps\xdr.exe stop <component>
Answer: C