
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 4
5.4 Explain Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) CYBERSECURITY-PRACTITIONER Practice Questions (Page 5)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
29questions here
6free pages
7concepts
15%of the exam
Questions 21–25
- 21
A security team needs to understand the full timeline of an attack, including what files were created, what processes ran, and what network connections were made on an endpoint. Which EDR capability provides this information?
Select an answer first - 22
A security architect is deciding between EDR and XDR. The organization has a mature endpoint security program but needs to improve visibility into network and cloud threats. What is the primary advantage of XDR over EDR in this scenario?
Select an answer first - 23
During an incident response, an analyst needs to contain a threat that is spreading laterally across multiple endpoints. The analyst wants to stop the spread while preserving the ability to investigate the attack. Which action is most appropriate?
Select an answer first - 24
Which activity is an example of threat hunting supported by EDR or XDR?
Select an answer first - 25
A company's security team is evaluating a new tool. They need a solution that not only blocks known malware but also records endpoint activity, detects suspicious behavior, and allows them to investigate and respond to incidents. How does EDR differ from traditional antivirus in this context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.