Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PCDRA Practice Exam with Questions & Answers | Set: 3

Questions 21

When creating a scheduled report which is not an option?

Options:
A.

Run weekly on a certain day and time.

B.

Run quarterly on a certain day and time.

C.

Run monthly on a certain day and time.

D.

Run daily at a certain time (selectable hours and minutes).

Paloalto Networks PCDRA Premium Access
Questions 22

What does the following output tell us?

PCDRA Question 22

Options:
A.

There is one low severity incident.

B.

Host shpapy_win10 had the most vulnerabilities.

C.

There is one informational severity alert.

D.

This is an actual output of the Top 10 hosts with the most malware.

Questions 23

When is the wss (WebSocket Secure) protocol used?

Options:
A.

when the Cortex XDR agent downloads new security content

B.

when the Cortex XDR agent uploads alert data

C.

when the Cortex XDR agent connects to WildFire to upload files for analysis

D.

when the Cortex XDR agent establishes a bidirectional communication channel

Questions 24

When creating a BIOC rule, which XQL query can be used?

Options:
A.

dataset = xdr_data

| filter event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

B.

dataset = xdr_data

| filter event_type = PROCESS and

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

C.

dataset = xdr_data

| filter action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

| fields action_process_image

D.

dataset = xdr_data

| filter event_behavior = true

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

Questions 25

You can star security events in which two ways? (Choose two.)

Options:
A.

Create an alert-starring configuration.

B.

Create an Incident-starring configuration.

C.

Manually star an alert.

D.

Manually star an Incident.

Questions 26

What is the maximum number of agents one Broker VM local agent applet can support?

Options:
A.

5,000

B.

10,000

C.

15,000

D.

20,000

Questions 27

When viewing the incident directly, what is the “assigned to” field value of a new Incident that was just reported to Cortex?

Options:
A.

Pending

B.

It is blank

C.

Unassigned

D.

New

Exam Code: PCDRA
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks Certified Detection and Remediation Analyst
Last Update: Jul 17, 2025
Questions: 91