
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 4
5.4 Explain Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) CYBERSECURITY-PRACTITIONER Practice Questions (Page 1)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
29questions here
6free pages
7concepts
15%of the exam
Questions 1–5
- 1
During an incident, a security analyst needs to quickly determine the scope of a compromise by identifying all endpoints that have communicated with a known malicious IP address. Which EDR capability is most useful for this task?
Select an answer first - 2
A company currently relies on traditional antivirus that only quarantines files based on known signatures. After a recent breach, the security team needs to detect suspicious behavior that may not have a known signature and respond to threats that are already active on endpoints. Which solution should they implement?
Select an answer first - 3
Which statement correctly compares the detection capabilities of EDR and XDR?
Select an answer first - 4
Which functionality is typically provided by EDR but NOT by traditional antivirus?
Select an answer first - 5
Which data source is commonly integrated into an XDR platform to enhance detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.