
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 7
5.7 Explain the Features and Functionality of Cortex XDR CYBERSECURITY-PRACTITIONER Practice Questions (Page 4)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
26questions here
6free pages
5concepts
15%of the exam
Questions 16–20
- 16
A security analyst notices a series of alerts for a single workstation that, taken individually, appear benign: a PowerShell script that queries Active Directory, a scheduled task creation, and an outbound connection to a rarely-used IP. The analyst wants to determine if these events are part of a coordinated attack. Which Cortex XDR capability should the analyst use to correlate these events into a single incident?
Select an answer first - 17
Which step is part of the investigation workflow in Cortex XDR?
Select an answer first - 18
A company uses Palo Alto Networks next-generation firewalls and Cortex XDR. The security team wants to share threat intelligence between the firewall and Cortex XDR to improve detection. Which feature should the team enable?
Select an answer first - 19
Which statement best describes the primary purpose of Cortex XDR?
Select an answer first - 20
An analyst is investigating an alert that shows a legitimate business application attempting to modify a registry key that is also a known persistence technique. The application is used by the finance department and cannot be taken offline. The analyst needs to determine if this is a true positive or a false positive. Which approach should the analyst take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.