
Palo Alto NetworksCertified XDR Engineer
Domain 4Objective 1
4.1 Create Detection Rules to Align with Requirements XDR-ENGINEER Practice Questions (Page 4)
Part of the Detection and Reporting domain, which accounts for 22% of the XDR-ENGINEER exam.
32questions here
7free pages
10concepts
22%of the exam
Questions 16–20
- 16
Which scenario best illustrates the value of a correlation rule over a simple single-event detection rule?
Select an answer first - 17
In a correlation rule, what is the function of a time window?
Select an answer first - 18
A SOC manager is reviewing a correlation rule that detects 'multiple failed logons followed by a successful logon' on the same host within 10 minutes. The rule is generating a high volume of alerts, and an initial review shows that most are from a legacy application that uses a service account which periodically fails authentication before succeeding. The manager wants to reduce false positives without missing real brute-force attacks. Which tuning approach is most effective?
Select an answer first - 19
In a custom prevention rule, what is the purpose of an exception?
Select an answer first - 20
What is an indicator of compromise (IOC)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.