
Palo Alto NetworksCertified XDR Engineer
Domain 4Objective 1
4.1 Create Detection Rules to Align with Requirements XDR-ENGINEER Practice Questions (Page 3)
Part of the Detection and Reporting domain, which accounts for 22% of the XDR-ENGINEER exam.
32questions here
7free pages
10concepts
22%of the exam
Questions 11–15
- 11
An organization has a custom prevention rule that blocks the execution of a specific file name (e.g., 'update.exe') to prevent a known malware variant. However, a legitimate software updater also uses the same file name, causing the rule to block legitimate updates. The security team needs to allow the legitimate updater while still blocking the malware. Which configuration is most appropriate?
Select an answer first - 12
What is the primary purpose of a correlation rule in an XDR platform?
Select an answer first - 13
Which of the following is an example of an IOC?
Select an answer first - 14
A security analyst is creating a correlation rule to detect a potential data exfiltration scenario: a user downloads a large file from an internal server and then uploads it to an external cloud storage service within a short time. The analyst wants to ensure the rule is precise and does not generate alerts for normal file transfers. Which rule design is most effective?
Select an answer first - 15
A security operations team has imported a large list of IOCs from a third-party feed. The team wants to ensure that the most critical IOCs are prioritized in alerting and that stale indicators do not generate noise after a certain date. What is the best practice for managing these IOCs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.