
Palo Alto NetworksCertified XDR Engineer
Domain 4Objective 1
4.1 Create Detection Rules to Align with Requirements XDR-ENGINEER Practice Questions (Page 2)
Part of the Detection and Reporting domain, which accounts for 22% of the XDR-ENGINEER exam.
32questions here
7free pages
10concepts
22%of the exam
Questions 6–10
- 6
A SOC team has deployed a correlation rule that alerts when a user account is created and then added to the Domain Admins group within 1 hour. During a two-week validation period, the rule generated 150 alerts, but only 5 were confirmed as malicious. The team wants to reduce the false positive rate while still catching the true positives. Which tuning action is most appropriate?
Select an answer first - 7
What happens when a detection rule that includes a BIOC condition matches an event?
Select an answer first - 8
What is the purpose of versioning for custom prevention rules?
Select an answer first - 9
A security team is building a correlation rule to detect a multi-stage attack: an attacker exploits a web server, then uses the compromised server to scan the internal network, and finally attempts to authenticate to a domain controller. The team wants to minimize false positives while ensuring the rule catches the full attack chain. Which rule design is most effective?
Select an answer first - 10
What is the purpose of assigning a severity level to an IOC or BIOC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.