
Practice Palo Alto Certifications and Accreditations PCDRA exam. Online Exam Practice Tests with detailed explanations! Pass PCDRA with confidence!
PCDRA - Palo Alto Networks Certified Detection and Remediation Analyst Practice Tests 2023 | DumpsTests
NEW QUESTION 30
Which of the following is an example of a successful exploit?
- A. a user executing code which takes advantage of a vulnerability on a local service.
- B. executing a process executable for well-known and signed software.
- C. connecting unknown media to an endpoint that copied malware due to Autorun.
- D. identifying vulnerable services on a server.
Answer: D
NEW QUESTION 31
What license would be required for ingesting external logs from various vendors?
- A. Cortex XDR Cloud per Host
- B. Cortex XDR Pro per TB
- C. Cortex XDR Pro per Endpoint
- D. Cortex XDR Vendor Agnostic Pro
Answer: B
NEW QUESTION 32
When is the wss (WebSocket Secure) protocol used?
- A. when the Cortex XDR agent establishes a bidirectional communication channel
- B. when the Cortex XDR agent connects to WildFire to upload files for analysis
- C. when the Cortex XDR agent downloads new security content
- D. when the Cortex XDR agent uploads alert data
Answer: A
NEW QUESTION 33
What kind of the threat typically encrypts user files?
- A. SQL injection attacks
- B. Zero-day exploits
- C. supply-chain attacks
- D. ransomware
Answer: D
NEW QUESTION 34
When viewing the incident directly, what is the "assigned to" field value of a new Incident that was just reported to Cortex?
- A. New
- B. Pending
- C. Unassigned
- D. It is blank
Answer: A
NEW QUESTION 35
Live Terminal uses which type of protocol to communicate with the agent on the endpoint?
- A. WebSocket
- B. UDP and a random port
- C. NetBIOS over TCP
- D. TCP, over port 80
Answer: A
NEW QUESTION 36
Which module provides the best visibility to view vulnerabilities?
- A. Device Control Violations module
- B. Forensics module
- C. Live Terminal module
- D. Host Insights module
Answer: D
Explanation:
Host Insights, an add-on module for Cortex XDR, combines vulnerability assessment, application and system visibility, and a powerful Search and Destroy feature to help you identify and contain threats. Vulnerability Assessment provides you real-time visibility into vulnerability exposure and current patch levels across your end-points. Host inventory presents detailed information about your host applications and settings whileSearch and Destroy lets you swiftly find and eradicate threats across all endpoints. Host Insights offers a holistic approach to endpoint visibility and attack containment, helping reduce your exposure to threats so you can avoid future breached.
NEW QUESTION 37
What is the outcome of creating and implementing an alert exclusion?
- A. The Cortex XDR console will hide those alerts.
- B. The Cortex XDR agent will allow the process that was blocked to run on the endpoint.
- C. The Cortex XDR agent will not create an alert for this event in the future.
- D. The Cortex XDR console will delete those alerts and block ingestion of them in the future.
Answer: A
NEW QUESTION 38
Which of the following best defines the Windows Registry as used by the Cortex XDR agent?
- A. a hierarchical database that stores settings for the operating system and for applications
- B. a central system, available via the internet, for registering officially licensed versions of software to prove ownership
- C. a ledger for maintaining accurate and up-to-date information on total disk usage and disk space remaining available to the operating system
- D. a system of files used by the operating system to commit memory that exceeds the available hardware resources. Also known as the "swap"
Answer: A
NEW QUESTION 39
An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?
- A. Kernel Integrity Monitor (KIM)
- B. DDL Security
- C. Dylib Hijacking
- D. Hot Patch Protection
Answer: C
Explanation:
Reference:
%20process
NEW QUESTION 40
Which of the following represents the correct relation of alerts to incidents?
- A. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- B. Only alerts with the same host are grouped together into one Incident in a given time frame.
- C. Every alert creates a new Incident.
- D. Alerts that occur within a three hour time frame are grouped together into one Incident.
Answer: B
NEW QUESTION 41
Which type of BIOC rule is currently available in Cortex XDR?
- A. Network
- B. Discovery
- C. Dropper
- D. Threat Actor
Answer: C
NEW QUESTION 42
When creating a scheduled report which is not an option?
- A. Run quarterly on a certain day and time.
- B. Run weekly on a certain day and time.
- C. Run daily at a certain time (selectable hours and minutes).
- D. Run monthly on a certain day and time.
Answer: A
NEW QUESTION 43
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?
- A. Create IOCs of the malicious files you have found to prevent their execution.
- B. Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.
- C. Enable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.
- D. Enable DLL Protection on all servers but there might be some false positives.
Answer: B
NEW QUESTION 44
After scan, how does file quarantine function work on an endpoint?
- A. Quarantine removes a specific file from its location on a local or removable drive to a protected folder and prevents it from being executed.
- B. Quarantine prevents an endpoint from communicating with anything besides the listed exceptions in the agent profile and Cortex XDR.
- C. Quarantine takes ownership of the files and folders and prevents execution through access control.
- D. Quarantine disables the network adapters and locks down access preventing any communications with the endpoint.
Answer: A
NEW QUESTION 45
What are two purposes of "Respond to Malicious Causality Chains" in a Cortex XDR Windows Malware profile? (Choose two.)
- A. Automatically kill the processes involved in malicious activity.
- B. Automatically close the connections involved in malicious traffic.
- C. Automatically block the IP addresses involved in malicious traffic.
- D. Automatically terminate the threads involved in malicious activity.
Answer: B,C
Explanation:
Reference:
%20threat%20protection%2C%20the,appear%20legitimate%20if%20inspected%20individually
NEW QUESTION 46
What is the purpose of the Cortex Data Lake?
- A. the interface between firewalls and the Cortex XDR agents
- B. a cloud-based storage facility where your firewall logs are stored
- C. a local storage facility where your logs and alert data can be aggregated
- D. the workspace for your Cortex XDR agents to detonate potential malware files
Answer: B
NEW QUESTION 47
......
Get instant access to PCDRA practice exam questions: https://drive.google.com/open?id=1iauJAWKfz7WmvLBF4-v6VtrfxbaY3CJv
The best PCDRA exam study material and preparation tool is here: https://www.dumpstests.com/PCDRA-latest-test-dumps.html