Palo Alto Networks PCDRA Practice Test - Questions Answers, Page 8
List of questions
Question 71

While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
Question 72

Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?
Question 73

After scan, how does file quarantine function work on an endpoint?
Question 74

Which two types of exception profiles you can create in Cortex XDR? (Choose two.)
Question 75

To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?
Question 76

Cortex XDR is deployed in the enterprise and you notice a cobalt strike attack via an ongoing supply chain compromise was prevented on 1 server. What steps can you take to ensure the same protection is extended to all your servers?
Question 77

What is the difference between presets and datasets in XQL?
Question 78

What should you do to automatically convert leads into alerts after investigating a lead?
Question 79

Which type of IOC can you define in Cortex XDR?
Question 80

Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?
Question