Pass the Paloalto Networks Palo Alto Certifications and Accreditations PCDRA Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

After scan, how does file quarantine function work on an endpoint?

Options:

A.

Quarantine takes ownership of the files and folders and prevents execution through access control.


B.

Quarantine disables the network adapters and locks down access preventing any communications with the endpoint.


C.

Quarantine removes a specific file from its location on a local or removable drive to a protected folder and prevents it from being executed.


D.

Quarantine prevents an endpoint from communicating with anything besides the listed exceptions in the agent profile and Cortex XDR.


Expert Solution
Questions # 2:

Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?

Options:

A.

Sensor Engine


B.

Causality Analysis Engine


C.

Log Stitching Engine


D.

Causality Chain Engine


Expert Solution
Questions # 3:

Which minimum Cortex XDR agent version is required for Kubernetes Cluster?

Options:

A.

Cortex XDR 6.1


B.

Cortex XDR 7.4


C.

Cortex XDR 7.5


D.

Cortex XDR 5.0


Expert Solution
Questions # 4:

In incident-related widgets, how would you filter the display to only show incidents that were “starred”?

Options:

A.

Create a custom XQL widget


B.

This is not currently supported


C.

Create a custom report and filter on starred incidents


D.

Click the star in the widget


Expert Solution
Questions # 5:

As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to open a malicious Word document. You learn from the WildFire report and AutoFocus that this document is known to have been used in Phishing campaigns since 2018. What steps can you take to ensure that the same document is not opened by other users in your organization protected by the Cortex XDR agent?

Options:

A.

Enable DLL Protection on all endpoints but there might be some false positives.


B.

Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.


C.

No step is required because Cortex shares IOCs with our fellow Cyber Threat Alliance members.


D.

No step is required because the malicious document is already stopped.


Expert Solution
Questions # 6:

What is the outcome of creating and implementing an alert exclusion?

Options:

A.

The Cortex XDR agent will allow the process that was blocked to run on the endpoint.


B.

The Cortex XDR console will hide those alerts.


C.

The Cortex XDR agent will not create an alert for this event in the future.


D.

The Cortex XDR console will delete those alerts and block ingestion of them in the future.


Expert Solution
Questions # 7:

In the Cortex XDR console, from which two pages are you able to manually perform the agent upgrade action? (Choose two.)

Options:

A.

Asset Management


B.

Agent Installations


C.

Action Center


D.

Endpoint Administration


Expert Solution
Questions # 8:

Which of the following paths will successfully activate Remediation Suggestions?

Options:

A.

Incident View > Actions > Remediation Suggestions


B.

Causality View > Actions > Remediation Suggestions


C.

Alerts Table > Right-click on a process node > Remediation Suggestions


D.

Alerts Table > Right-click on an alert > Remediation Suggestions


Expert Solution
Questions # 9:

Which of the following is NOT a precanned script provided by Palo Alto Networks?

Options:

A.

delete_file


B.

quarantine_file


C.

process_kill_name


D.

list_directories


Expert Solution
Questions # 10:

What is the standard installation disk space recommended to install a Broker VM?

Options:

A.

1GB disk space


B.

2GB disk space


C.

512GB disk space


D.

256GB disk space


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions