Certification Practice Test | PDF Questions | Actual Questions | Test Engine | Pass4Sure
PCDRA : Palo Alto Networks Certified Detection and Remediation Analyst Exam

Palo-Alto PCDRA Questions & Answers
Full Version: 244 Q&A
PCDRA Dumps PCDRA Braindumps PCDRA Real Questions PCDRA Practice Test
PCDRA Actual Questions
Palo-Alto
PCDRA
Palo Alto Networks Certified Detection and Remediation Analyst
https://killexams.com/pass4sure/exam-detail/PCDRA
Question: 226
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion .
What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
mark the incident as Unresolved
create a BIOC rule excluding this behavior
create an exception to prevent future false positives
mark the incident as Resolved C False Positive
Answer: D
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate- endpoint-alerts/alert-exclusions/add-an-alert-exclusion.html
Question: 227
To create a BIOC rule with XQL query you must at a minimum filter on which field inorder for it to be a valid BIOC rule?
causality_chain
endpoint_name
threat_event
event_type
Answer: D
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr- indicators/working-with-biocs/create-a-bioc-rule.html
Question: 228
After scan, how does file quarantine function work on an endpoint?
Quarantine takes ownership of the files and folders and prevents execution through access control.
Quarantine disables the network adapters and locks down access preventing any communications with the endpoint.
Quarantine removes a specific file from its location on a local or removable drive to a protected folder and prevents it from being executed.
Quarantine prevents an endpoint from communicating with anything besides the listed exceptions in the agent profile and Cortex XD
Answer: C
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate- files/manage-quarantined-files
Question: 229
Which statement is true for Application Exploits and Kernel Exploits?
The ultimate goal of any exploit is to reach the application.
Kernel exploits are easier to prevent then application exploits.
The ultimate goal of any exploit is to reach the kernel.
Application exploits leverage kernel vulnerability.
Answer: A
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/cortex-xdr-prevent-overview/about- cortex-xdr-protection.html
Question: 230
Which of the following best defines the Windows Registry as used by the Cortex XDRagent?
a hierarchical database that stores settings for the operating system and for applications
a system of files used by the operating system to commit memory that exceeds the available hardware resources. Also known as the âswapâ
a central system, available via the internet, for registering officially licensed versions of software to prove ownership
a ledger for maintaining accurate and up-to-date information on total disk usage and disk space remaining available to the operating system
Answer: A
Explanation:
Reference: https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/windows-registry-advanced-users
Question: 231
What kind of the threat typically encrypts userfiles?
ransomware
SQL injection attacks
Zero-day exploits
supply-chain attacks
Answer: A
Explanation:
Reference: https://www.proofpoint.com/us/threat- reference/ransomware#:~:text=Ransomware%20is%20a%20type%20of,ransom%20fee%20to%20the%20attacker
A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate . Which statement is correct for the incident?
It is true positive.
It is false positive.
It is a false negative.
It is true negative.
Answer: B
Explanation:
Reference: https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-cloud2model-manager-1-005/td- p/391391
Question: 233
LiveTerminal uses which type of protocol to communicate with the agent on the endpoint?
NetBIOS over TCP
WebSocket
UDP and a random port
TCP, over port 80
Answer: B
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/communication- between-cortex-xdr-and-agents.html
Question: 234
What are two purposes of âRespond to Malicious Causality Chainsâ in a Cortex XDR Windows Malware profile? (Choose two.)
Automatically close the connections involved in malicious traffic.
Automatically kill the processes involved in malicious activity.
Automatically terminate the threads involved in malicious activity.
Automaticallyblock the IP addresses involved in malicious traffic.
Answer: A,D
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security- profiles/add-malware-security- profile.html#:~:text=With%20Behavioral%20threat%20protection%2C%20the,appear%20legitimate%20if%20inspected%20individu ally
Which of the following policy exceptions applies to the following description? âAn exception allowing specific PHP filesâ
Support exception
Local file threat examination exception
Behavioral threat protection rule exception
Process exception
Answer: B Question: 236
Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
Security Manager Dashboard
Data Ingestion Dashboard
Security Admin Dashboard
Incident Management Dashboard
Answer: A
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features- introduced/features-introduced-in-2021.html
Question: 237
When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)
Assign incidents to an analyst in bulk.
Change the status of multiple incidents.
Investigate several Incidents at once.
Delete the selected Incidents.
Answer: A,B
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features- introduced/features-introduced-in-2021.html
Question: 238
Which of the following represents the correct relation of alerts to incidents?
Only alerts with the same host are grouped together into one Incident in a given time frame.
Alerts that occur within a three hour time frame are grouped together into one Incident.
Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
Every alert creates a new Incident.
Answer: A
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate- incidents/cortex-xdr-incidents.html
Question: 239
If you have an isolated network that is prevented from connecting to the Cortex Data Lake, which type of Broker VM setup can you use to facilitate the communication?
Broker VM Pathfinder
Local Agent Proxy
Local Agent Installer and Content Caching
Broker VM Syslog Collector
Answer: C
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the- agent-proxy-for-closed-networks.html
Question: 240
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
Click the three dots on the widget andthen choose âSaveâ and this will link the query to the Widget Library.
This isnât supported, you have to exit the dashboard and go into the Widget Library first to create it.
Click on âSave to Action Centerâ in the dashboard and you will be promptedto give the query a name and description.
Click on âSave to Widget Libraryâ in the dashboard and you will be prompted to give the query a name and description.
Answer: D
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/monitoring/cortex-xdr-dashboard/widget- library.html
Question: 241
Phishing belongs which of the following MITRE ATT&CK tactics?
Initial Access, Persistence
Persistence, Command and Control
Reconnaissance, Persistence
Reconnaissance, Initial Access
Answer: D Question: 242
When creating a BIOC rule, which XQL query can be used?
dataset = xdr_data
| filterevent_sub_type = PROCESS_START and action_process_image_name ~= ".*?.(?:pdf|docx).exe"
dataset = xdr_data
| filter event_type = PROCESS and event_sub_type = PROCESS_START and
action_process_image_name ~= ".*?.(?:pdf|docx).exe"
dataset = xdr_data
| filter action_process_image_name ~= ".*?.(?:pdf|docx).exe"
| fields action_process_image
dataset = xdr_data
| filter event_behavior = true event_sub_type = PROCESS_START and
action_process_image_name ~=".*?.(?:pdf|docx).exe"
Answer: B
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr- indicators/working-with-biocs/create-a-bioc-rule.html
Question: 242
When creating a scheduled report which is not an option?
Run weekly on a certain day and time.
Run quarterly on a certain day and time.
Run monthly on a certain day and time.
Run daily at a certain time (selectable hours and minutes).
Answer: B
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/monitoring/cortex-xdr-dashboard/run-or- schedule-reports.html
Question: 243
When using the âFile Search and Destroyâ feature, which of the following search hash type is supported?
SHA256 hash of the file
AES256 hash of the file
MD5 hash of the file
SHA1 hash of the file
Answer: A
Explanation:
Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-
actions/search-file-and-destroy.html
Question: 244
Which statement best describes how Behavioral Threat Protection (BTP) works?
BTP injects into known vulnerable processes to detect malicious activity.
BTP runs on the Cortex XDR and distributes behavioral signatures to all agents.
BTP matches EDR data with rules provided by Cortex XD
BTP uses machine Learning to recognize malicious activity even if it is not known.
Answer: A
Explanation:
Reference: https://www.khipu-networks.com/matchmadein/wp-content/uploads/cortex-xdr- endpoint-protection-solution-guide.pdf
User: Olyssia*****![]() ![]() ![]() ![]() ![]() I was ranked very low among my classmates until I registered for assistance with Killexams.com for a few exams. It was the intensive study program provided by Killexams.com that helped me become one of the high-ranking college students in my class. Their PCDRA PDF, PCDRA practice tests, and PCDRA books were precise and significantly beneficial in my preparation. Thank you, Killexams.com, for helping me achieve my goals. |
User: Prisha*****![]() ![]() ![]() ![]() ![]() I owe my high ranking amongst my classmates to Killexams.com, which provided me with valuable assistance for my exams. The learning resources were instrumental in helping me join the ranks of other exceptional students in my class. The resources on the website, such as the EC PDF, EC practice tests, and EC books, are particularly exceptional and immensely beneficial for students like me. I am grateful to Killexams.com for their exceptional resources and support, and I am pleased to express my appreciation. |
User: Odessa*****![]() ![]() ![]() ![]() ![]() I initially thought that I wasted money on the PALO ALTO NETWORKS CERTIFIED DETECTION AND REMEDIATION ANALYST brain dump test because I was not aware of the exam update. However, after contacting the killexams.com support team, I was reassured that the exam was updated and that their material was up to date. I was impressed by their performance and customer support, and I am looking forward to taking my PALO ALTO NETWORKS CERTIFIED DETECTION AND REMEDIATION ANALYST exam in two weeks. |
User: Sophia*****![]() ![]() ![]() ![]() ![]() I am thrilled to share that purchasing PCDRA exam practice tests was a wise decision. The PCDRA exam is notoriously challenging due to its extensive coverage of the subject matter. However, killexams.com provided me with a comprehensive preparation source that covered everything flawlessly, with many associated questions on the exam. |
User: Victoria*****![]() ![]() ![]() ![]() ![]() Thanks to killexams.com, I was able to get the fine degree of guidance needed to achieve splendid scores on the pcdra exam. I enjoyed the interesting manner in which the topics were presented, and with the help of killexams.com, I was able to develop my knowledge and understanding of the subject. It made my guidance a lot less complex and allowed me to excel in the exam. |
Features of iPass4sure PCDRA Exam
- Files: PDF / Test Engine
- Premium Access
- Online Test Engine
- Instant download Access
- Comprehensive Q&A
- Success Rate
- Real Questions
- Updated Regularly
- Portable Files
- Unlimited Download
- 100% Secured
- Confidentiality: 100%
- Success Guarantee: 100%
- Any Hidden Cost: $0.00
- Auto Recharge: No
- Updates Intimation: by Email
- Technical Support: Free
- PDF Compatibility: Windows, Android, iOS, Linux
- Test Engine Compatibility: Mac / Windows / Android / iOS / Linux
Premium PDF with 244 Q&A
Get Full VersionAll Palo-Alto Exams
Palo-Alto ExamsCertification and Entry Test Exams
Complete exam list