Q: 11
Which two outcomes can result from custom prioritization configuration? (Choose two)
Options
Discussion
A/B? Not totally sure but both sound like what custom prioritization is meant for.
A and B. Clear question, saw similar on practice tests.
Be respectful. No spam.
Q: 12
The causality chain in Cortex XDR helps analysts:
Options
Discussion
Seriously why is Palo Alto obsessed with visualization? Wouldn't D make more sense with alert handling?
Be respectful. No spam.
Q: 13
Why is the timeline view useful during investigations?
Options
Discussion
Really clear question, nice. A is right since the timeline helps see each event in order, making it easier to piece together how the attack unfolded. Pretty sure that's what most exam reports say too.
Its D doesn’t sound right since grouping alerts is different from seeing them in order. I think A makes more sense because timeline view is about connecting events step by step. Not 100% sure though, somebody else agree?
Be respectful. No spam.
Q: 14
Which agent operational state indicates the endpoint is installed but not actively enforcing protection?
Options
Discussion
Why wouldn't it be B? If it's disconnected, doesn't that mean it's not enforcing protection?
Be respectful. No spam.
Q: 15
Which two functions are supported in XQL queries? (Choose two)
Options
Discussion
A and B tbh. XQL uses COUNT() and SUM() for aggregation, but PATCH() and REMEDIATE() are more for actions not queries. Seen similar picks on practice tests.
Be respectful. No spam.
Q: 16
Which Cortex XDR feature enables automated responses to certain threats?
Options
Discussion
A imo, since playbooks with XSOAR are what automate responses in Cortex XDR. Other options are manual or config changes only. Clear and to the point question.
Be respectful. No spam.
Q: 17
Which of the following can be configured in a prevention policy but not in an extension profile?
Options
Discussion
Its A. You can only set malware blocking rules in a prevention policy, not in an extension profile. Extension (agent settings) profiles are more about agent operations and enabling modules, but malware rules specifically live inside the prevention policy. Pretty sure this lines up with how Cortex XDR splits configuration. Correct me if I’m off!
Probably A, saw a similar question in practice exams and malware blocking rules are set via prevention policy only.
Be respectful. No spam.
Q: 18
What type of data source is xdr_data considered?
Options
Discussion
B tbh
Be respectful. No spam.
Q: 19
When building an IOC hunting query, analysts should focus on:
Options
Discussion
A
Its A, seen similar in practice Qs, has to be known bad hashes or domains for IOC hunting.
A , since only known bad domains or hashes actually give you something concrete to search for with IOC hunting queries.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2