New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Security Operations XDR-Analyst Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which function describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed?

Options:

A.

Search & destroy


B.

Isolation


C.

Quarantine


D.

Flag for removal


Expert Solution
Questions # 12:

An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?

Options:

A.

DDL Security


B.

Hot Patch Protection


C.

Kernel Integrity Monitor (KIM)


D.

Dylib Hijacking


Expert Solution
Questions # 13:

What should you do to automatically convert leads into alerts after investigating a lead?

Options:

A.

Lead threats can't be prevented in the future because they already exist in the environment.


B.

Create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.


C.

Create BIOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.


D.

Build a search query using Query Builder or XQL using a list of lOCs.


Expert Solution
Questions # 14:

Where would you view the WildFire report in an incident?

Options:

A.

next to relevant Key Artifacts in the incidents details page


B.

under Response --> Action Center


C.

under the gear icon --> Agent Audit Logs


D.

on the HUB page at apps.paloaltonetworks.com


Expert Solution
Questions # 15:

Which statement best describes how Behavioral Threat Protection (BTP) works?

Options:

A.

BTP injects into known vulnerable processes to detect malicious activity.


B.

BTP runs on the Cortex XDR and distributes behavioral signatures to all agents.


C.

BTP matches EDR data with rules provided by Cortex XDR.


D.

BTP uses machine Learning to recognize malicious activity even if it is not known.


Expert Solution
Questions # 16:

Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?

Options:

A.

UASLR


B.

JIT Mitigation


C.

Memory Limit Heap Spray Check


D.

DLL Security


Expert Solution
Questions # 17:

To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?

Options:

A.

It does not interfere with any portion of the pattern on the endpoint.


B.

It interferes with the pattern as soon as it is observed by the firewall.


C.

It does not need to interfere with the any portion of the pattern to prevent the attack.


D.

It interferes with the pattern as soon as it is observed on the endpoint.


Expert Solution
Questions # 18:

What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)

Options:

A.

Automatically close the connections involved in malicious traffic.


B.

Automatically kill the processes involved in malicious activity.


C.

Automatically terminate the threads involved in malicious activity.


D.

Automatically block the IP addresses involved in malicious traffic.


Expert Solution
Questions # 19:

Which statement is true based on the following Agent Auto Upgrade widget?

Question # 19

Options:

A.

There are a total of 689 Up To Date agents.


B.

Agent Auto Upgrade was enabled but not on all endpoints.


C.

Agent Auto Upgrade has not been enabled.


D.

There are more agents in Pending status than In Progress status.


Expert Solution
Questions # 20:

When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?

Options:

A.

Click the three dots on the widget and then choose “Save” and this will link the query to the Widget Library.


B.

This isn’t supported, you have to exit the dashboard and go into the Widget Library first to create it.


C.

Click on “Save to Action Center” in the dashboard and you will be prompted to give the query a name and description.


D.

Click on “Save to Widget Library” in the dashboard and you will be prompted to give the query a name and description.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions