
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 4
5.4 Explain Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) CYBERSECURITY-PRACTITIONER Practice Questions (Page 3)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
29questions here
6free pages
7concepts
15%of the exam
Questions 11–15
- 11
A security team is evaluating a new endpoint security tool. They need to detect fileless attacks that leave no signature and respond to threats that are already running in memory. Their current antivirus solution has failed to detect these attacks. What is the most important capability the new tool must have?
Select an answer first - 12
After detecting a malicious file on an endpoint, an analyst wants to prevent the file from executing on other endpoints while allowing the security team to analyze it. Which EDR response action is most appropriate?
Select an answer first - 13
An organization has a mature EDR deployment but is experiencing alert fatigue because the EDR generates many alerts that are not related to actual threats. They want to reduce noise while improving detection of multi-stage attacks. What is the most effective approach?
Select an answer first - 14
How does EDR differ from traditional antivirus in its approach to threat detection?
Select an answer first - 15
Which security layer is typically included in XDR but NOT in EDR?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.