Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PCDRA Practice Exam with Questions & Answers

Questions 1

How can you pivot within a row to Causality view and Timeline views for further investigate?

Options:
A.

Using the Open Card Only

B.

Using the Open Card and Open Timeline actions respectively

C.

You can't pivot within a row to Causality view and Timeline views

D.

Using Open Timeline Actions Only

Paloalto Networks PCDRA Premium Access
Questions 2

What motivation do ransomware attackers have for returning access to systems once their victims have paid?

Options:
A.

There is organized crime governance among attackers that requires the return of access to remain in good standing. B. Nation-states enforce the return of system access through the use of laws and regulation.

B.

Failure to restore access to systems undermines the scheme because others will not believe their valuables would be returned.

C.

The ransomware attackers hope to trace the financial trail back and steal more from traditional banking institutions. -

Questions 3

What should you do to automatically convert leads into alerts after investigating a lead?

Options:
A.

Lead threats can't be prevented in the future because they already exist in the environment.

B.

Create IOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.

C.

Create BIOC rules based on the set of the collected attribute-value pairs over the affected entities concluded during the lead hunting.

D.

Build a search query using Query Builder or XQL using a list of lOCs.

Questions 4

Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?

Options:
A.

in the macOS Malware Protection Profile to indicate allowed signers

B.

in the Linux Malware Protection Profile to indicate allowed Java libraries

C.

SHA256 hashes cannot be used in Cortex XDR Malware Protection Profiles

D.

in the Windows Malware Protection Profile to indicate allowed executables

Questions 5

Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?

Options:
A.

Security Manager Dashboard

B.

Data Ingestion Dashboard

C.

Security Admin Dashboard

D.

Incident Management Dashboard

Questions 6

Which module provides the best visibility to view vulnerabilities?

Options:
A.

Live Terminal module

B.

Device Control Violations module

C.

Host Insights module

D.

Forensics module

Questions 7

Which statement regarding scripts in Cortex XDR is true?

Options:
A.

Any version of Python script can be run.

B.

The level of risk is assigned to the script upon import.

C.

Any script can be imported including Visual Basic (VB) scripts.

D.

The script is run on the machine uploading the script to ensure that it is operational.

Questions 8

While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?

Options:
A.

mark the incident as Unresolved

B.

create a BIOC rule excluding this behavior

C.

create an exception to prevent future false positives

D.

mark the incident as Resolved – False Positive

Questions 9

When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)

Options:
A.

Assign incidents to an analyst in bulk.

B.

Change the status of multiple incidents.

C.

Investigate several Incidents at once.

D.

Delete the selected Incidents.

Questions 10

If you have an isolated network that is prevented from connecting to the Cortex Data Lake, which type of Broker VM setup can you use to facilitate the communication?

Options:
A.

Broker VM Pathfinder

B.

Local Agent Proxy

C.

Local Agent Installer and Content Caching

D.

Broker VM Syslog Collector

Exam Code: PCDRA
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks Certified Detection and Remediation Analyst
Last Update: Oct 14, 2025
Questions: 91