
2023 100% Free PCDRA Daily Practice Exam With 62 Questions
PCDRA exam torrent Palo Alto Networks study guide
Get to know about the topics of the Palo Alto Networks PCDRA Certification Exam
The topics of the Palo Alto Networks PCDRA Certification Exam defined in the PCDRA Dumps is given as follows:
- Architecture: 15%
- Remediation: 15%
- Prevention and Detection: 20%
- Threat Hunting: 10%
NEW QUESTION 10
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
- A. Create a new rule exception and use the singer as the characteristic.
- B. Add the signer to the allow list in the malware profile.
- C. In the Restrictions Profile, add the file name and path to the Executable Files allow list.
- D. Add the signer to the allow list under the action center page.
Answer: B
NEW QUESTION 11
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
- A. Sensor Engine
- B. Causality Chain Engine
- C. Causality Analysis Engine
- D. Log Stitching Engine
Answer: C
NEW QUESTION 12
Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
- A. Data Ingestion Dashboard
- B. Security Manager Dashboard
- C. Incident Management Dashboard
- D. Security Admin Dashboard
Answer: B
NEW QUESTION 13
When is the wss (WebSocket Secure) protocol used?
- A. when the Cortex XDR agent connects to WildFire to upload files for analysis
- B. when the Cortex XDR agent establishes a bidirectional communication channel
- C. when the Cortex XDR agent downloads new security content
- D. when the Cortex XDR agent uploads alert data
Answer: B
NEW QUESTION 14
An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?
- A. DDL Security
- B. Kernel Integrity Monitor (KIM)
- C. Hot Patch Protection
- D. Dylib Hijacking
Answer: D
Explanation:
Reference:
%20process
NEW QUESTION 15
When creating a scheduled report which is not an option?
- A. Run daily at a certain time (selectable hours and minutes).
- B. Run monthly on a certain day and time.
- C. Run quarterly on a certain day and time.
- D. Run weekly on a certain day and time.
Answer: C
NEW QUESTION 16
A Linux endpoint with a Cortex XDR Pro per Endpoint license and Enhanced Endpoint Data enabled has reported malicious activity, resulting in the creation of a file that you wish to delete. Which action could you take to delete the file?
- A. Initiate Remediate Suggestions to automatically delete the file.
- B. Manually remediate the problem on the endpoint in question.
- C. Open an NFS connection from the Cortex XDR console and delete the file.
- D. Open X2go from the Cortex XDR console and delete the file via X2go.
Answer: B
NEW QUESTION 17
What is the standard installation disk space recommended to install a Broker VM?
- A. 256GB disk space
- B. 512GB disk space
- C. 1GB disk space
- D. 2GB disk space
Answer: B
NEW QUESTION 18
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
- A. in the Linux Malware Protection Profile to indicate allowed Java libraries
- B. in the Windows Malware Protection Profile to indicate allowed executables
- C. in the macOS Malware Protection Profile to indicate allowed signers
- D. SHA256 hashes cannot be used in Cortex XDR Malware Protection Profiles
Answer: B
NEW QUESTION 19
What is by far the most common tactic used by ransomware to shut down a victim's operation?
- A. preventing the victim from being able to access APIs to cripple infrastructure
- B. restricting access to administrative accounts to the victim
- C. denying traffic out of the victims network until payment is received
- D. encrypting certain files to prevent access by the victim
Answer: D
NEW QUESTION 20
What is the purpose of the Unit 42 team?
- A. Unit 42 is responsible for the rapid deployment of Cortex XDR agents
- B. Unit 42 is responsible for threat research, malware analysis and threat hunting
- C. Unit 42 is responsible for the configuration optimization of the Cortex XDR server
- D. Unit 42 is responsible for automation and orchestration of products
Answer: B
NEW QUESTION 21
What is the purpose of the Cortex Data Lake?
- A. the interface between firewalls and the Cortex XDR agents
- B. a cloud-based storage facility where your firewall logs are stored
- C. a local storage facility where your logs and alert data can be aggregated
- D. the workspace for your Cortex XDR agents to detonate potential malware files
Answer: B
NEW QUESTION 22
Which of the following represents the correct relation of alerts to incidents?
- A. Only alerts with the same host are grouped together into one Incident in a given time frame.
- B. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- C. Alerts that occur within a three hour time frame are grouped together into one Incident.
- D. Every alert creates a new Incident.
Answer: A
NEW QUESTION 23
Live Terminal uses which type of protocol to communicate with the agent on the endpoint?
- A. WebSocket
- B. TCP, over port 80
- C. UDP and a random port
- D. NetBIOS over TCP
Answer: A
NEW QUESTION 24
Which of the following is an example of a successful exploit?
- A. connecting unknown media to an endpoint that copied malware due to Autorun.
- B. a user executing code which takes advantage of a vulnerability on a local service.
- C. identifying vulnerable services on a server.
- D. executing a process executable for well-known and signed software.
Answer: C
NEW QUESTION 25
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
- A. create a BIOC rule excluding this behavior
- B. create an exception to prevent future false positives
- C. mark the incident as Unresolved
- D. mark the incident as Resolved - False Positive
Answer: D
NEW QUESTION 26
When using the "File Search and Destroy" feature, which of the following search hash type is supported?
- A. MD5 hash of the file
- B. AES256 hash of the file
- C. SHA256 hash of the file
- D. SHA1 hash of the file
Answer: C
NEW QUESTION 27
......
Use Valid New PCDRA Test Notes & PCDRA Valid Exam Guide: https://www.passreview.com/PCDRA_exam-braindumps.html
PCDRA Actual Questions Answers PDF 100% Cover Real Exam Questions: https://drive.google.com/open?id=10OF_TEeGiZnLJ5jSKTg15EOGo0CqXH7i