Weekend Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

Page: 1 / 2
Total 15 questions
Exam Code: XDR-Engineer                Update: Sep 14, 2025
Exam Name: Palo Alto Networks XDR Engineer

Paloalto Networks Palo Alto Networks XDR Engineer XDR-Engineer Exam Dumps: Updated Questions & Answers (September 2025)

Question # 1

An engineer is building a dashboard to visualize the number of alerts from various sources. One of the widgets from the dashboard is shown in the image below:

The engineer wants to configure a drilldown on this widget to allow dashboard users to select any of the alert names and view those alerts with additional relevant details. The engineer has configured the following XQL query to meet the requirement:

dataset = alerts

| fields alert_name, description, alert_source, severity, original_tags, alert_id, incident_id

| filter alert_name =

| sort desc _time

How will the engineer complete the third line of the query (filter alert_name =) to allow dynamic filtering on a selected alert name?

A.

$y_axis.value

B.

$x_axis.value

C.

$x_axis.name

D.

$y_axis.name

Question # 2

A static endpoint group is created by adding 321 endpoints using the Upload From File feature. However, after group creation, the members count field shows 244 endpoints. What are two possible reasons why endpoints were not added to the group? (Choose two.)

A.

Static groups have a limit of 250 endpoints when adding by file

B.

Endpoints added to the new group were previously added to an existing group

C.

Endpoints added to the group were in Disconnected or Connection Lost status when groupmembership was added

D.

The IP address, hostname, or alias of the endpoints must match an existing agent that has registered with the tenant

Question # 3

Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard’s interactivity and data insights?

A.

Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header

B.

Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats

C.

Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches

D.

Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards

Question # 4

During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Windows endpoints by non-technical business units. Which rule type should be implemented?

A.

Analytics Behavioral Indicator of Compromise (ABIOC)

B.

Behavioral Indicator of Compromise (BIOC)

C.

Correlation

D.

Indicator of Compromise (IOC)

Question # 5

Which action is being taken with the query below?

dataset = xdr_data

| fields agent_hostname, _time, _product

| comp latest as latest_time by agent_hostname, _product

| join type=inner (dataset = endpoints

| fields endpoint_name, endpoint_status, endpoint_type) as lookup lookup.endpoint_name = agent_hostname

| filter endpoint_status = ENUM.CONNECTED

| fields agent_hostname, endpoint_status, latest_time, _product

A.

Monitoring the latest activity of endpoints

B.

Identifying endpoints that have disconnected from the network

C.

Monitoring the latest activity of connected firewall endpoints

D.

Checking for endpoints with outdated agent versions

Question # 6

Which two steps should be considered when configuring the Cortex XDR agent for a sensitive and highly regulated environment? (Choose two.)

A.

Enable critical environment versions

B.

Create an agent settings profile where the agent upgrade scope is maintenance releases only

C.

Create an agent settings profile, enable content auto-update, and include a delay of four days

D.

Enable minor content version updates

Question # 7

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

Question # 8

In addition to using valid authentication credentials, what is required to enable the setup of the Database Collector applet on the Broker VM to ingest database activity?

A.

Valid SQL query targeting the desired data

B.

Access to the database audit log

C.

Database schema exported in the correct format

D.

Access to the database transaction log

Question # 9

What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?

A.

Sending endpoint logs to the NGFW for analysis

B.

Blocking network traffic based on Cortex XDR detections

C.

Enabling additional analysis through enhanced application logging

D.

Automated downloading of malware signatures from the NGFW

Question # 10

After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a partially protected status. In which two places can insights into what is contributing to this status be located? (Choose two.)

A.

Management Audit Logs

B.

XQL query of the endpoints dataset

C.

All Endpoints page

D.

Asset Inventory

Page: 1 / 2
Total 15 questions

Most Popular Certification Exams

Payment

       

Contact us

dumpscollection live chat

Site Secure

mcafee secure

TESTED 14 Sep 2025