New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Paloalto Networks XDR-Analyst Practice Exam with Questions & Answers | Set: 3

Questions 21

Live Terminal uses which type of protocol to communicate with the agent on the endpoint?

Options:
A.

NetBIOS over TCP

B.

WebSocket

C.

UDP and a random port

D.

TCP, over port 80

Paloalto Networks XDR-Analyst Premium Access
Questions 22

Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?

Options:
A.

The endpoint is disconnected or the verdict from WildFire is of a type benign.

B.

The endpoint is disconnected or the verdict from WildFire is of a type unknown.

C.

The endpoint is disconnected or the verdict from WildFire is of a type malware.

D.

The endpoint is disconnected or the verdict from WildFire is of a type grayware.

Questions 23

Which of the following best defines the Windows Registry as used by the Cortex XDR agent?

Options:
A.

a hierarchical database that stores settings for the operating system and for applications

B.

a system of files used by the operating system to commit memory that exceeds the available hardware resources. Also known as the “swap”

C.

a central system, available via the internet, for registering officially licensed versions of software to prove ownership

D.

a ledger for maintaining accurate and up-to-date information on total disk usage and disk space remaining available to the operating system

Questions 24

When creating a BIOC rule, which XQL query can be used?

Options:
A.

dataset = xdr_data

| filter event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

B.

dataset = xdr_data

| filter event_type = PROCESS and

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

C.

dataset = xdr_data

| filter action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

| fields action_process_image

D.

dataset = xdr_data

| filter event_behavior = true

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

Questions 25

Which function describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed?

Options:
A.

Search & destroy

B.

Isolation

C.

Quarantine

D.

Flag for removal

Questions 26

You can star security events in which two ways? (Choose two.)

Options:
A.

Create an alert-starring configuration.

B.

Create an Incident-starring configuration.

C.

Manually star an alert.

D.

Manually star an Incident.

Questions 27

To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?

Options:
A.

It does not interfere with any portion of the pattern on the endpoint.

B.

It interferes with the pattern as soon as it is observed by the firewall.

C.

It does not need to interfere with the any portion of the pattern to prevent the attack.

D.

It interferes with the pattern as soon as it is observed on the endpoint.

Exam Code: XDR-Analyst
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks XDR Analyst
Last Update: Dec 14, 2025
Questions: 91