Palo Alto Networks PCDRA Practice Test - Questions Answers, Page 8
List of questions
Question 71
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
Question 72
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?
Question 73
After scan, how does file quarantine function work on an endpoint?
Question 74
Which two types of exception profiles you can create in Cortex XDR? (Choose two.)
Question 75
To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?
Question 76
Cortex XDR is deployed in the enterprise and you notice a cobalt strike attack via an ongoing supply chain compromise was prevented on 1 server. What steps can you take to ensure the same protection is extended to all your servers?
Question 77
What is the difference between presets and datasets in XQL?
Question 78
What should you do to automatically convert leads into alerts after investigating a lead?
Question 79
Which type of IOC can you define in Cortex XDR?
Question 80
Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?
Question