Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Engineer

Domain 3Objective 5

3.5 Configure Parsing Rules XDR-ENGINEER Practice Questions (Page 2)

Part of the Ingestion and Automation domain, which accounts for 22% of the XDR-ENGINEER exam.

23questions here
5free pages
6concepts
22%of the exam

Questions 6–10

  1. 6foundation · easy

    What is the purpose of testing a parsing rule against sample log data?

    Select an answer first
  2. 7application · medium

    A team is creating a parsing rule for a log source that uses a format like '2025-03-01 12:00:00,user=jdoe,action=login'. They need to extract the 'user' and 'action' fields. What are the components of the parsing rule that they need to configure?

    Select an answer first
  3. 8expert · hard

    A security team is ingesting logs from a custom application that uses a mix of key-value pairs and JSON. Some logs are in the format 'event=login user=jdoe', while others are '{"event":"login","user":"jdoe"}'. They need to normalize the 'user' field for both formats. What is the most efficient approach?

    Select an answer first
  4. 9foundation · easy

    When creating a new parsing rule in the XDR interface, which of the following must be specified first?

    Select an answer first
  5. 10expert · medium

    An analyst is testing a parsing rule with a sample log and sees that the 'src_ip' field is extracted as '192.168.1.1' but the 'dst_ip' field is extracted as '10.0.0.2:8080'. The log line is 'src_ip=192.168.1.1 dst_ip=10.0.0.2:8080'. The regex is 'src_ip=(?<src_ip>\S+) dst_ip=(?<dst_ip>\S+)'. What is the most likely cause of the 'dst_ip' including the port?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.