Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified XDR Engineer

Domain 5Objective 2

5.2 Troubleshoot Data Management Issues (e.g., Data Ingestion, Parsing) XDR-ENGINEER Practice Questions (Page 5)

Part of the Maintenance and Troubleshooting domain, which accounts for 20% of the XDR-ENGINEER exam.

27questions here
6free pages
7concepts
20%of the exam

Questions 21–25

  1. 21application · medium

    An administrator is troubleshooting why no data is appearing in Cortex XDR from a new endpoint group. The agents on the endpoints show as 'connected' in the console. Which of the following is the most likely reason for the missing data?

    Select an answer first
  2. 22foundation · easy

    Which issue is most likely to be caused by a parsing error?

    Select an answer first
  3. 23application · medium

    An administrator is reviewing data quality in Cortex XDR and notices that events from a specific Linux server have a 'user' field that is consistently populated with the value 'unknown'. The raw logs from the server contain the correct username. What is the most likely cause?

    Select an answer first
  4. 24foundation · easy

    What is the primary purpose of data parsing in the XDR platform?

    Select an answer first
  5. 25expert · hard

    A security team is ingesting logs from a custom application that uses a non-standard timestamp format. The parsing rule correctly extracts all other fields, but the 'event_time' field is empty. The raw log contains a timestamp like '2024-03-15T14:30:00.123Z'. The administrator has verified the timestamp is present in the raw log. What is the most likely reason the field is empty?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XDR-ENGINEER” is a trademark of its owner, used for identification only.