
Palo Alto NetworksCertified XDR Engineer
Domain 3Objective 5
3.5 Configure Parsing Rules XDR-ENGINEER Practice Questions (Page 2)
Part of the Ingestion and Automation domain, which accounts for 22% of the XDR-ENGINEER exam.
23questions here
5free pages
6concepts
22%of the exam
Questions 6–10
- 6
What is the purpose of testing a parsing rule against sample log data?
Select an answer first - 7
A team is creating a parsing rule for a log source that uses a format like '2025-03-01 12:00:00,user=jdoe,action=login'. They need to extract the 'user' and 'action' fields. What are the components of the parsing rule that they need to configure?
Select an answer first - 8
A security team is ingesting logs from a custom application that uses a mix of key-value pairs and JSON. Some logs are in the format 'event=login user=jdoe', while others are '{"event":"login","user":"jdoe"}'. They need to normalize the 'user' field for both formats. What is the most efficient approach?
Select an answer first - 9
When creating a new parsing rule in the XDR interface, which of the following must be specified first?
Select an answer first - 10
An analyst is testing a parsing rule with a sample log and sees that the 'src_ip' field is extracted as '192.168.1.1' but the 'dst_ip' field is extracted as '10.0.0.2:8080'. The log line is 'src_ip=192.168.1.1 dst_ip=10.0.0.2:8080'. The regex is 'src_ip=(?<src_ip>\S+) dst_ip=(?<dst_ip>\S+)'. What is the most likely cause of the 'dst_ip' including the port?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.