
Palo Alto NetworksCertified XDR Engineer
Domain 5Objective 2
5.2 Troubleshoot Data Management Issues (e.g., Data Ingestion, Parsing) XDR-ENGINEER Practice Questions (Page 2)
Part of the Maintenance and Troubleshooting domain, which accounts for 20% of the XDR-ENGINEER exam.
27questions here
6free pages
7concepts
20%of the exam
Questions 6–10
- 6
What does validating a data source in the XDR platform primarily confirm?
Select an answer first - 7
An organization has a data source that is sending logs to Cortex XDR, but the data volume is significantly lower than expected. The source status is 'healthy' and there are no parsing errors. The administrator suspects the source is not sending all its logs. What is the most effective way to validate the data source?
Select an answer first - 8
An analyst is reviewing data quality and notices that the 'event_time' field for events from a specific source is consistently 5 hours behind the actual time. The source is a network appliance that is configured to use UTC. What is the most likely cause?
Select an answer first - 9
An organization is ingesting Windows Event Logs from a new domain controller. The data is arriving, but the Cortex XDR search interface shows the Event ID field is empty for all events from this source. Other fields like timestamp and hostname are populated correctly. What is the most likely cause of this issue?
Select an answer first - 10
A team is onboarding a new custom application that sends JSON logs. The administrator has created a parsing rule, but the Cortex XDR search interface shows that the 'user' field is not being populated. The raw log clearly contains a 'user' key. What is the most efficient way to validate the parsing rule?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.