Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

Check Real Palo Alto Networks PCDRA Exam Question for Free (2024) [Q23-Q39]

Share

Check Real Palo Alto Networks PCDRA Exam Question for Free (2024)

Get Ready to Boost your Prepare for your PCDRA Exam with 93 Questions

NEW QUESTION # 23
When using the "File Search and Destroy" feature, which of the following search hash type is supported?

  • A. SHA1 hash of the file
  • B. MD5 hash of the file
  • C. SHA256 hash of the file
  • D. AES256 hash of the file

Answer: C


NEW QUESTION # 24
What is the purpose of the Unit 42 team?

  • A. Unit 42 is responsible for threat research, malware analysis and threat hunting
  • B. Unit 42 is responsible for the configuration optimization of the Cortex XDR server
  • C. Unit 42 is responsible for the rapid deployment of Cortex XDR agents
  • D. Unit 42 is responsible for automation and orchestration of products

Answer: A


NEW QUESTION # 25
Which minimum Cortex XDR agent version is required for Kubernetes Cluster?

  • A. Cortex XDR 7.4
  • B. Cortex XDR 7.5
  • C. Cortex XDR 6.1
  • D. Cortex XDR 5.0

Answer: B

Explanation:
Explanation
The minimum Cortex XDR agent version required for Kubernetes Cluster is Cortex XDR 7.5. This version introduces the Cortex XDR agent for Kubernetes hosts, which provides protection and visibility for Linux hosts that run on Kubernetes clusters. The Cortex XDR agent for Kubernetes hosts supports the following features:
* Anti-malware protection
* Behavioral threat protection
* Exploit protection
* File integrity monitoring
* Network security
* Audit and remediation
* Live terminal
To install the Cortex XDR agent for Kubernetes hosts, you need to deploy the Cortex XDR agent as a DaemonSet on your Kubernetes cluster. You also need to configure the agent settings profile and the agent installer in the Cortex XDR management console. References:
* Cortex XDR Agent Release Notes: This document provides the release notes for Cortex XDR agent versions, including the new features, enhancements, and resolved issues.
* Install the Cortex XDR Agent for Kubernetes Hosts: This document explains how to install and configure the Cortex XDR agent for Kubernetes hosts using the Cortex XDR management console and the Kubernetes command-line tool.


NEW QUESTION # 26
Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?

  • A. Restriction Policy
  • B. Hash Verdict Determination
  • C. Child Process Protection
  • D. Behavioral Threat Protection

Answer: B

Explanation:
Explanation
The first protection module that is checked in the Cortex XDR Windows agent malware protection flow is the Hash Verdict Determination. This module compares the hash of the executable file that is about to run on the endpoint with a list of known malicious hashes stored in the Cortex XDR cloud. If the hash matches a malicious hash, the agent blocks the execution and generates an alert. If the hash does not match a malicious hash, the agent proceeds to the next protection module, which is the Restriction Policy1.
The Hash Verdict Determination module is the first line of defense against malware, as it can quickly and efficiently prevent known threats from running on the endpoint. However, this module cannot protect against unknown or zero-day threats, which have no known hash signature. Therefore, the Cortex XDR agent relies on other protection modules, such as Behavioral Threat Protection, Child Process Protection, and Exploit Protection, to detect and block malicious behaviors and exploits that may occur during the execution of the file1.
References:
* Palo Alto Networks Cortex XDR Documentation, File Analysis and Protection Flow


NEW QUESTION # 27
Which of the following represents the correct relation of alerts to incidents?

  • A. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
  • B. Only alerts with the same host are grouped together into one Incident in a given time frame.
  • C. Every alert creates a new Incident.
  • D. Alerts that occur within athree-hourtime frame are grouped together into one Incident.

Answer: A


NEW QUESTION # 28
Which statement is true for Application Exploits and Kernel Exploits?

  • A. Kernel exploits are easier to prevent then application exploits.
  • B. The ultimate goal of any exploit is to reach the kernel.
  • C. The ultimate goal of any exploit is to reach the application.
  • D. Application exploits leverage kernel vulnerability.

Answer: B

Explanation:
Explanation
The ultimate goal of any exploit is to reach the kernel, which is the core component of the operating system that has the highest level of privileges and access to the hardware resources. Application exploits are attacks that target vulnerabilities in specific applications, such as web browsers, email clients, or office suites. Kernel exploits are attacks that target vulnerabilities in the kernel itself, such as memory corruption, privilege escalation, or code execution. Kernel exploits are more difficult to prevent and detect than application exploits, because they can bypass security mechanisms and hide their presence from the user and the system.
References:
* Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) Study Guide, page 8
* Palo Alto Networks Cortex XDR Documentation, Exploit Protection Overview


NEW QUESTION # 29
Which of the following policy exceptions applies to the following description?
'An exception allowing specific PHP files'

  • A. Behavioral threat protection rule exception
  • B. Support exception
  • C. Process exception
  • D. Local file threat examination exception

Answer: D

Explanation:
Explanation
The policy exception that applies to the following description is B, local file threat examination exception. A local file threat examination exception is an exception that allows you to exclude specific files or folders from being scanned by the Cortex XDR agent for malware or threats. You can use this exception to prevent false positives, performance issues, or compatibility problems with legitimate files or applications. You can define the local file threat examination exception by file name, file path, file hash, or digital signer. For example, you can create a local file threat examination exception for specific PHP files by entering their file names or paths in the exception configuration. References:
* Local File Threat Examination Exceptions
* Create a Local File Threat Examination Exception


NEW QUESTION # 30
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?

  • A. Create a custom XQL widget
  • B. Click the star in the widget
  • C. Create a custom report and filter on starred incidents
  • D. This is not currently supported

Answer: B

Explanation:
Reference:
%20you%20clear%20the%20star


NEW QUESTION # 31
How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?

  • A. by utilizing decoy Files.
  • B. by encrypting the disk first.
  • C. by patching vulnerable applications.
  • D. by retrieving the encryption key.

Answer: A


NEW QUESTION # 32
With a Cortex XDR Prevent license, which objects are considered to be sensors?

  • A. Cortex XDR agents
  • B. Palo Alto Networks Next-Generation Firewalls
  • C. Third-Party security devices
  • D. Syslog servers

Answer: A

Explanation:
Explanation
The objects that are considered to be sensors with a Cortex XDR Prevent license are Cortex XDR agents and Palo Alto Networks Next-Generation Firewalls. These are the two sources of data that Cortex XDR can collect and analyze for threat detection and response. Cortex XDR agents are software components that run on endpoints, such as Windows, Linux, and Mac devices, and provide protection against malware, exploits, and fileless attacks. Cortex XDR agents also collect and send endpoint data, such as process activity, network traffic, registry changes, and user actions, to the Cortex Data Lake for analysis and correlation. Palo Alto Networks Next-Generation Firewalls are network security devices that provide visibility and control over network traffic, and enforce security policies based on applications, users, and content. Next-Generation Firewalls also collect and send network data, such as firewall logs, DNS logs, HTTP headers, and WildFire verdicts, to the Cortex Data Lake for analysis and correlation. By integrating data from both Cortex XDR agents and Next-Generation Firewalls, Cortex XDR can provide a comprehensive view of the attack surface and detect threats across the network and endpoint layers. References:
* Cortex XDR Prevent License
* Cortex XDR Agent Features
* Next-Generation Firewall Features


NEW QUESTION # 33
The Cortex XDR console has triggered an incident, blocking a vitally important piece of software in your organization that is known to be benign. Which of the following options would prevent Cortex XDR from blocking this software in the future, for all endpoints in your organization?

  • A. Create a global exception.
  • B. Create a global inclusion.
  • C. Create an individual alert exclusion.
  • D. Create an endpoint-specific exception.

Answer: A

Explanation:
Explanation
A global exception is a rule that allows you to exclude specific files, processes, or behaviors from being blocked or detected by Cortex XDR. A global exception applies to all endpoints in your organization that are protected by Cortex XDR. Creating a global exception for a vitally important piece of software that is known to be benign would prevent Cortex XDR from blocking this software in the future, for all endpoints in your organization.
To create a global exception, you need to follow these steps:
* In the Cortex XDR management console, go to Policy Management > Exceptions and click Add Exception.
* Select the Global Exception option and click Next.
* Enter a name and description for the exception and click Next.
* Select the type of exception you want to create, such as file, process, or behavior, and click Next.
* Specify the criteria for the exception, such as file name, hash, path, process name, command line, or behavior name, and click Next.
* Review the summary of the exception and click Finish.
References:
* Create Global Exceptions: This document explains how to create global exceptions to exclude specific files, processes, or behaviors from being blocked or detected by Cortex XDR.
* Exceptions Overview: This document provides an overview of exceptions and how they can be used to
* fine-tune the Cortex XDR security policy.


NEW QUESTION # 34
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?

  • A. Create a new rule exception and use the singer as the characteristic.
  • B. Add the signer to the allow list in the malware profile.
  • C. Add the signer to the allow list under the action center page.
  • D. In the Restrictions Profile, add the file name and path to the Executable Files allow list.

Answer: B

Explanation:
Explanation
To prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer in Windows and macOS, one way to add an exception for the signer is to add the signer to the allow list in the malware profile. A malware profile is a profile that defines the settings and actions for malware prevention and detection on the endpoints. A malware profile allows you to specify a list of files, folders, or signers that you want to exclude from malware scanning and blocking. By adding the signer to the allow list in the malware profile, you can prevent the Cortex XDR Agent from blocking any file that is signed by that signer1.
Let's briefly discuss the other options to provide a comprehensive explanation:
A: In the Restrictions Profile, add the file name and path to the Executable Files allow list: This is not the correct answer. Adding the file name and path to the Executable Files allow list in the Restrictions Profile will not prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. A Restrictions Profile is a profile that defines the settings and actions for restricting the execution of files or processes on the endpoints. A Restrictions Profile allows you to specify a list of executable files that you want to allow or block based on the file name and path. However, this method does not take into account the digital signer of the file, and it may not be effective if the file name or path changes2.
B: Create a new rule exception and use the signer as the characteristic: This is not the correct answer. Creating a new rule exception and using the signer as the characteristic will not prevent theCortex XDR Agent from blocking execution of a file based on the digital signer. A rule exception is an exception that you can create to modify the behavior of a specific prevention rule or BIOC rule. A rule exception allows you to specify the characteristics and the actions that you want to apply to the exception, such as file hash, process name, IP address, or domain name. However, this method does not support using the signer as a characteristic, and it may not be applicable to all prevention rules or BIOC rules3.
D: Add the signer to the allow list under the action center page: This is not the correct answer. Adding the signer to the allow list under the action center page will not prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. The action center page is a page that allows you to create and manage actions that you can perform on your endpoints, such as isolating, scanning, collecting files, or executing scripts. The action center page does not have an option to add a signer to the allow list, and it is not related to the malware prevention or detection functionality4.
In conclusion, to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer in Windows and macOS, one way to add an exception for the signer is to add the signer to the allow list in the malware profile. By using this method, you can exclude the files that are signed by the trusted signer from the malware scanning and blocking.
References:
* Add a New Malware Security Profile
* Add a New Restrictions Security Profile
* Create a Rule Exception
* Action Center


NEW QUESTION # 35
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?

  • A. Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.
  • B. Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.
  • C. Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.
  • D. Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.

Answer: A

Explanation:
Explanation
Cortex XDR Analytics is a cloud-based service that uses machine learning and artificial intelligence to detect and prevent network attacks. Cortex XDR Analytics can interfere with the attack pattern as soon as it is observed on the endpoint by applying protection policies that block malicious processes, files, or network connections. This way, Cortex XDR Analytics can stop the attack before it causes any damage or compromises the system. References:
* [Cortex XDR Analytics Overview]
* [Cortex XDR Analytics Protection Policies]


NEW QUESTION # 36
What are two purposes of "Respond to Malicious Causality Chains" in a Cortex XDR Windows Malware profile? (Choose two.)

  • A. Automatically kill the processes involved in malicious activity.
  • B. Automatically block the IP addresses involved in malicious traffic.
  • C. Automatically terminate the threads involved in malicious activity.
  • D. Automatically close the connections involved in malicious traffic.

Answer: B,D

Explanation:
Reference:
%20threat%20protection%2C%20the,appear%20legitimate%20if%20inspected%20individually


NEW QUESTION # 37
Which module provides the best visibility to view vulnerabilities?

  • A. Live Terminal module
  • B. Host Insights module
  • C. Forensics module
  • D. Device Control Violations module

Answer: B


NEW QUESTION # 38
Which function describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed?

  • A. Isolation
  • B. Quarantine
  • C. Search & destroy
  • D. Flag for removal

Answer: B

Explanation:
Explanation
The function that describes the removal of a specific file from its location on a local or removable drive to a protected folder to prevent the file from being executed is quarantine. Quarantine is a feature of Cortex XDR that allows you to isolate malicious or suspicious files from the endpoint and prevent them from running or spreading. You can quarantine files manually from the Cortex XDR console, or automatically based on the malware analysis profile or the remediation suggestions. When you quarantine a file, the Cortex XDR agent encrypts the file and moves it to a hidden folder under the agent installation directory. The file is also renamed with a random string and a .quarantine extension. You can view, restore, or delete the quarantined files from the Cortex XDR console. References:
* Quarantine Files
* Manage Quarantined Files


NEW QUESTION # 39
......

Use Free PCDRA Exam Questions that Stimulates Actual EXAM : https://examtorrent.braindumpsit.com/PCDRA-latest-dumps.html