
Palo Alto NetworksCertified XDR Engineer
Domain 3Objective 5
3.5 Configure Parsing Rules XDR-ENGINEER Practice Questions (Page 1)
Part of the Ingestion and Automation domain, which accounts for 22% of the XDR-ENGINEER exam.
23questions here
5free pages
6concepts
22%of the exam
Questions 1–5
- 1
A parsing rule is not extracting fields from a new log format. What is the most likely cause?
Select an answer first - 2
A parsing rule for a network device log fails to match any logs. The log format is 'timestamp=2025-03-01T12:00:00Z src_ip=192.168.1.1 dst_ip=10.0.0.2'. The rule uses the pattern 'timestamp=(?<timestamp>\S+) src_ip=(?<src_ip>\S+) dst_ip=(?<dst_ip>\S+)'. The test with a sample log succeeds, but live logs do not match. What is the most likely cause?
Select an answer first - 3
Why does rule order matter when multiple parsing rules could match the same log?
Select an answer first - 4
An organization ingests logs from multiple sources, including firewalls, endpoints, and cloud services. Each source has a different log format. They want to normalize the 'src_ip' field across all sources so that detection rules can use a single field name. What is the primary purpose of creating parsing rules in this scenario?
Select an answer first - 5
What is the impact of disabling a parsing rule in XDR?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.