
Palo Alto NetworksCertified Cybersecurity Practitioner
Domain 5Objective 7
5.7 Explain the Features and Functionality of Cortex XDR CYBERSECURITY-PRACTITIONER Practice Questions (Page 5)
Part of the Endpoint Security domain, which accounts for 15% of the CYBERSECURITY-PRACTITIONER exam.
26questions here
6free pages
5concepts
15%of the exam
Questions 21–25
- 21
A security analyst is investigating an alert that shows a process making outbound connections to a known command-and-control (C2) server. The process is a legitimate system utility. The analyst wants to confirm the alert and determine the scope of the compromise. Which action should the analyst take?
Select an answer first - 22
A security analyst is responding to an alert that indicates a malicious file was downloaded and executed on a user's endpoint. The analyst wants to remove the file and prevent it from running again. Which Cortex XDR action should the analyst take?
Select an answer first - 23
Which component is a core part of the Cortex XDR architecture?
Select an answer first - 24
How does Cortex XDR primarily collect endpoint telemetry?
Select an answer first - 25
A small company with 50 endpoints wants to improve its security posture by detecting advanced threats that evade traditional antivirus. The company has no dedicated security team and wants a solution that provides visibility across endpoints, network, and cloud without deploying multiple separate products. Which approach best aligns with these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “CYBERSECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.