Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Security Operations Professional

Domain 3Objective 3

3.3 Identify Use Cases in Which an Organization Would Benefit from Cortex XDR Compared to an Endpoint Detection and Response (EDR) Solution SECURITY-OPERATIONS-PROFESSIONAL Practice Questions (Page 5)

Part of the Cortex XDR domain, which accounts for 23% of the SECURITY-OPERATIONS-PROFESSIONAL exam.

34questions here
7free pages
10concepts
23%of the exam

Questions 21–25

  1. 21expert · hard

    A company is deciding whether to invest in Cortex XDR or stick with their current EDR. They have a well-staffed SOC that is comfortable with the EDR and has built custom detections. However, they are seeing an increase in attacks that involve cloud services, and they are struggling to correlate endpoint alerts with cloud activity. They also want to reduce the number of tools they use. Which factor should be the primary driver for adopting Cortex XDR?

    Select an answer first
  2. 22expert · hard

    A company is evaluating whether to replace their traditional EDR with Cortex XDR. They have a mature security stack that includes a next-generation firewall (NGFW) from another vendor, a cloud access security broker (CASB) for SaaS applications, and a SIEM that aggregates logs from all sources. Their primary concern is improving detection of threats that span on-premises endpoints and their AWS workloads. The security team is already proficient with their current tools. Which factor should most influence their decision to adopt Cortex XDR?

    Select an answer first
  3. 23foundation · easy

    How does Cortex XDR's investigation workflow differ from a traditional EDR's workflow?

    Select an answer first
  4. 24foundation · easy

    When evaluating whether to adopt Cortex XDR instead of an EDR, which factor is most important to consider?

    Select an answer first
  5. 25expert · hard

    A security team is investigating a series of alerts that appear to be part of a coordinated attack. The EDR has flagged several endpoints with suspicious PowerShell activity, but each alert is treated as a separate incident. The team suspects that the PowerShell activity is related to a larger campaign that involves network reconnaissance and data staging in a cloud storage account. They want to confirm the relationship and respond as a single incident. Which Cortex XDR capability would enable this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “SECURITY-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.