Download Palo Alto Networks PCDRA Sample Questions [Mar-2024]
Real PCDRA Exam Questions and Answers FREE
The PCDRA exam is a comprehensive test that covers a range of topics related to network security, including threat detection, analysis, and remediation techniques. PCDRA exam is designed for security professionals who have experience working with Palo Alto Networks technologies, and who are looking to enhance their skills and knowledge in this area.
NEW QUESTION # 51
Which Exploit ProtectionModule (EPM) can be used to prevent attacks based on OS function?
- A. UASLR
- B. JIT Mitigation
- C. Memory Limit Heap Spray Check
- D. DLL Security
Answer: B
Explanation:
Explanation
JIT Mitigation is an Exploit Protection Module (EPM) that can be used to prevent attacks based on OS function. JIT Mitigation protects against exploits that use the Just-In-Time (JIT) compiler of the OS to execute malicious code. JIT Mitigation monitors the memory pages that are allocated by the JIT compiler and blocks any attempts to execute code from those pages. This prevents attackers from using the JIT compiler as a way to bypass other security mechanisms such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR). References:
* Palo Alto Networks. (2023). PCDRA Study Guide. PDF file. Retrieved from
https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcdra-study-g
* Palo Alto Networks. (2021). Exploit Protection Modules. Web page. Retrieved from
https://docs.paloaltonetworks.com/traps/6-0/traps-endpoint-security-manager-admin/traps-endpoint-securit
NEW QUESTION # 52
What is the standard installation disk space recommended to install a Broker VM?
- A. 512GB disk space
- B. 1GB disk space
- C. 2GB disk space
- D. 256GB disk space
Answer: A
NEW QUESTION # 53
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
- A. Click the three dots on the widget and then choose "Save" and this will link the query to the Widget Library.
- B. This isn't supported, you have to exit the dashboard and go into the Widget Library first to create it.
- C. Click on "Save to Widget Library" in the dashboard and you will be prompted to give the query a name and description.
- D. Click on "Save to Action Center" in the dashboard and you will be prompted to give the query a name and description.
Answer: C
Explanation:
Explanation
To save a custom XQL query to the Widget Library, you need to click on "Save to Widget Library" in the dashboard and you will be prompted to give the query a name and description. This will allow you to reuse the query in other dashboards or reports. You cannot save a query to the Widget Library by clicking the three dots on the widget, as this will only give you options to edit, delete, or clone the widget. You also cannot save a query to the Action Center, as this is a different feature that allows you to create alerts or remediation actions based on the query results. You do not have to exit the dashboard and go into the Widget Library first to create a query, as you can do it directly from the dashboard. References:
* Cortex XDR Pro Admin Guide: Save a Custom Query to the Widget Library
* Cortex XDR Pro Admin Guide: Create a Dashboard
NEW QUESTION # 54
Which statement is true based on the following Agent Auto Upgrade widget?
- A. There are more agents in Pending status than In Progress status.
- B. There are a total of 689 Up To Date agents.
- C. Agent Auto Upgrade was enabled but not on all endpoints.
- D. Agent Auto Upgrade has not been enabled.
Answer: C
NEW QUESTION # 55
Which of the following is NOT a precanned script provided by Palo Alto Networks?
- A. process_kill_name
- B. quarantine_file
- C. list_directories
- D. delete_file
Answer: B
NEW QUESTION # 56
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
- A. mark the incident as Resolved - False Positive
- B. mark the incident as Unresolved
- C. create a BIOC rule excluding this behavior
- D. create an exception to prevent future false positives
Answer: A
Explanation:
Explanation
If all alerts contained in a Cortex XDR incident have exclusions, the Cortex XDR console will automatically mark the incident as Resolved - False Positive. This means that the incident was not a real threat, but a benign or legitimate activity that triggered an alert. By marking the incident as Resolved- False Positive, the Cortex XDR console removes the incident from the list of unresolved incidents and does not count it towards the incident statistics. This helps the analyst to focus on the true positive incidents that require further investigation and response1.
An exclusion is a rule that hides an alert from the Cortex XDR console, based on certain criteria, such as the alert source, type, severity, or description. An exclusion does not change the security policy or prevent the alert from firing, it only suppresses the alert from the console. An exclusion is useful when the analyst wants to reduce the noise of false positive alerts that are not relevant or important2.
An exception, on the other hand, is a rule that overrides the security policy and allows or blocks a process or file from running on an endpoint, based on certain attributes, such as the file hash, path, name, or signer. An exception is useful when the analyst wants to prevent false negative alerts that are caused by malicious or unwanted files or processes that are not detected by the security policy3.
A BIOC rule is a rule that creates an alert based on a custom XQL query that defines a specific behavior of interest or concern. A BIOC rule is useful when the analyst wants to detect and alert on anomalous or suspicious activities that are not covered by the default Cortex XDR rules4.
References:
* Palo Alto Networks Cortex XDR Documentation, Resolve an Incident1
* Palo Alto Networks Cortex XDR Documentation, Alert Exclusions2
* Palo Alto Networks Cortex XDR Documentation, Exceptions3
* Palo Alto Networks Cortex XDR Documentation, BIOC Rules4
NEW QUESTION # 57
What is the purpose of the Cortex Data Lake?
- A. the interface between firewalls and the Cortex XDR agents
- B. the workspace for your Cortex XDR agents to detonate potential malware files
- C. a local storage facility where your logs and alert data can be aggregated
- D. a cloud-based storage facility where your firewall logs are stored
Answer: D
Explanation:
Explanation
The purpose of the Cortex Data Lake is to provide a cloud-based storage facility where your firewall logs are stored. Cortex Data Lake is a service that collects, transforms, and integrates your enterprise's security data to enable Palo Alto Networks solutions. It powers AI and machine learning, detection accuracy, and app and service innovation. Cortex Data Lake automatically collects, integrates, and normalizes data across your security infrastructure, including your next-generation firewalls, Prisma Access, and Cortex XDR. With unified data, you can run advanced AI and machine learning to radically simplify security operations with apps built on Cortex. Cortex Data Lake is available in multiple regions and supports data residency and privacy requirements. References:
* Cortex Data Lake - Palo Alto Networks
* Cortex Data Lake - Palo Alto Networks
* Cortex Data Lake, the technology behind Cortex XDR - Palo Alto Networks
* CORTEX DATA LAKE - Palo Alto Networks
* Sizing for Cortex Data Lake Storage - Palo Alto Networks
NEW QUESTION # 58
What is the action taken out by Managed Threat Hunting team for Zero Day Exploits?
- A. MTH researches for threats in the logs and reports to engineering.
- B. MTH runs queries and investigative actions and no further action is taken.
- C. MTH pushes content updates to prevent against thezero-dayexploits.
- D. MTH researches for threats in the tenant and generates a report with the findings.
Answer: D
Explanation:
Explanation
The Managed Threat Hunting (MTH) team is a group of security experts who proactively hunt for threats in the Cortex XDR tenant and generate a report with the findings. The MTH team uses advanced queries and investigative actions to identify and analyze potential threats, such as zero-day exploits, that may have bypassed the prevention and detection capabilities of Cortex XDR. The MTH team also provides recommendations and best practices to help customers remediate the threats and improve their security posture. References:
* Managed Threat Hunting Service
* Managed Threat Hunting Report
NEW QUESTION # 59
Which profiles can the user use to configure malware protection in the Cortex XDR console?
- A. Malware Protection profile
- B. Malware Detection profile
- C. Anti-Malware profile
- D. Malware profile
Answer: A
Explanation:
Explanation
The user can use the Malware Protection profile to configure malware protection in the Cortex XDR console. The Malware Protection profile defines the actions that Cortex XDR takes when it detects malware on your endpoints. You can configure different actions for different types of malware, such as ransomware, password theft, or child process. You can also configure the scan frequency and scope for periodic malware scans. The Malware Protection profile is part of the Endpoint Security policy that you assign to your endpoints. References:
* Malware Protection Profile
* Endpoint Security Policy
NEW QUESTION # 60
A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?
- A. It is false positive.
- B. It is true negative.
- C. It is true positive.
- D. It is a false negative.
Answer: A
NEW QUESTION # 61
Where would you go to add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint?
- A. In the Action Center, choose Allow list, select new action, select add to allow list, add your hash to the list, and apply it.
- B. From the rules menu select new exception, fill out the criteria, choose the scope to apply it to, hit save.
- C. Find the exceptions profile attached to the endpoint, under process exceptions select local analysis, paste the hash and save.
- D. Find the Malware profile attached to the endpoint, Under Portable Executable and DLL Examination add the hash to the allow list.
Answer: A
Explanation:
Explanation
To add an exception to exclude a specific file hash from examination by the Malware profile for a Windows endpoint, you need to use the Action Center in Cortex XDR. The Action Center allows you to create and manage actions that apply to endpoints, such as adding files or processes to the allow list or block list, isolating or unisolating endpoints, or initiating live terminal sessions. To add a file hash to the allow list, you need to choose Allow list, select new action, select add to allow list, add your hash to the list, and apply it. This will prevent the Malware profile from scanning or blocking the file on the endpoints that match the scope of the action. References: Cortex XDR 3: Responding to Attacks1, Action Center2
NEW QUESTION # 62
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
- A. Click the three dots on the widget and then choose "Save" and this will link the query to the Widget Library.
- B. This isn't supported, you have to exit the dashboard and go into the Widget Library first to create it.
- C. Click on "Save to Widget Library" in the dashboard and you will be prompted to give the query a name and description.
- D. Click on "Save to Action Center" in the dashboard and you will be prompted to give the query a name and description.
Answer: C
NEW QUESTION # 63
Which of the following represents the correct relation of alerts to incidents?
- A. Every alert creates a new Incident.
- B. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- C. Alerts that occur within athree-hourtime frame are grouped together into one Incident.
- D. Only alerts with the same host are grouped together into one Incident in a given time frame.
Answer: B
NEW QUESTION # 64
What is the difference between presets and datasets in XQL?
- A. A dataset is a third-party data source; presets are built-in data source.
- B. A dataset is a database; presets is a field.
- C. A dataset is a Cortex data lake data source only; presets are built-in data source.
- D. A dataset is a built-in orthird-partysource; presets group XDR data fields.
Answer: D
Explanation:
Explanation
The difference between presets and datasets in XQL is that a dataset is a built-in or third-party data source, while a preset is a group of XDR data fields. A dataset is a collection of data that you can query and analyze using XQL. A dataset can be a Cortex data lake data source, such as endpoints, alerts, incidents, or network flows, or a third-party data source, such as AWS CloudTrail, Azure Activity Logs, or Google Cloud Audit Logs. A preset is a predefined set of XDR data fields that are relevant for a specific use case, such as process execution, file operations, or network activity. A preset can help you simplify and standardize your XQL queries by selecting the most important fields for youranalysis. You can use presets with any Cortex data lake data source, but not with third-party data sources. References:
* Datasets and Presets
* XQL Language Reference
NEW QUESTION # 65
What contains a logical schema in an XQL query?
- A. Field
- B. Array expand
- C. Bin
- D. Dataset
Answer: A
Explanation:
Explanation
A logical schema in an XQL query is a field, which is a named attribute of a dataset. A field can have a data type, such as string, integer, boolean, or array. A field can also have a modifier, such as bin or expand, that transforms the field value in the query output. A field can be used in the select, where, group by, order by, or having clauses of an XQL query. References:
* XQL Syntax
* XQL Data Types
* XQL Field Modifiers
NEW QUESTION # 66
When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)
- A. Change the status of multiple incidents.
- B. Investigate several Incidents at once.
- C. Assign incidents to an analyst in bulk.
- D. Delete the selected Incidents.
Answer: A,C
NEW QUESTION # 67
What is the function of WildFire for Cortex XDR?
- A. WildFire runs in the cloud and analyses alert data from the XDR agent to check for behavioural threats.
- B. WildFire accepts and analyses a sample to provide a verdict.
- C. WildFire runs entirely on the agent to quickly analyse samples and provide a verdict.
- D. WildFire is the engine that runs on the local agent and determines whether behavioural threats are occurring on the endpoint.
Answer: B
NEW QUESTION # 68
Which of the following represents the correct relation of alerts to incidents?
- A. Every alert creates a new Incident.
- B. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- C. Alerts that occur within athree-hourtime frame are grouped together into one Incident.
- D. Only alerts with the same host are grouped together into one Incident in a given time frame.
Answer: B
Explanation:
Explanation
The correct relation of alerts to incidents is that alerts with same causality chains that occur within a given time frame are grouped together into an incident. A causality chain is a sequence of events that are related to the same malicious activity, such as a malware infection, a lateral movement, or a data exfiltration. Cortex XDR uses a set of rules that take into account different attributes of the alerts, such as the alert source, type, and time period, to determine if they belong to the same causality chain. By grouping related alerts into incidents, Cortex XDR reduces the number of individual events to review and provides a complete picture of the attack with rich investigative details1.
Option A is incorrect, because alerts with the same host are not necessarily grouped together into one incident in a given time frame. Alerts with the same host may belong to different causality chains, or may be unrelated to any malicious activity. For example, if a host has a malware infection and a network anomaly, these alerts may not be grouped into the same incident, unless they are part of the same attack.
Option B is incorrect, because alerts that occur within a three hour time frame are not always grouped together into one incident. The time frame is not the only criterion for grouping alerts into incidents. Alerts that occur within a three hour time frame may belong to different causality chains, or may be unrelated to any malicious activity. For example, if a host has a file download and a registry modification within a three hour time frame, these alerts may not be grouped into the same incident, unless they are part of the same attack.
Option D is incorrect, because every alert does not create a new incident. Creating a new incident for every alert would result in alert fatigue and inefficient investigations. Cortex XDR aims to reduce the number of incidents by grouping related alerts into one incident, based on their causality chains and other attributes.
References:
* Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) Study Guide, page 9
* Palo Alto Networks Cortex XDR Documentation, Incident Management Overview2
* Cortex XDR: Stop Breaches with AI-Powered Cybersecurity1
NEW QUESTION # 69
What is the purpose of targeting software vendors in a supply-chain attack?
- A. to steal users' login credentials.
- B. to access source code.
- C. to report Zero-day vulnerabilities.
- D. to take advantage of a trusted software delivery method.
Answer: D
Explanation:
Explanation
A supply chain attack is a type of cyberattack that targets a trusted third-party vendor who offers services or software vital to the supply chain. Software supply chain attacks inject malicious code into an application in order to infect all users of an app. The purpose of targeting software vendors in a supply-chain attack is to take advantage of a trusted software delivery method, such as an update or a download, that can reach a large number of potential victims. By compromising a software vendor, an attacker can bypass the security measures of the downstream organizations and gain access to their systems, data, or networks. References:
* What Is a Supply Chain Attack? - Definition, Examples & More | Proofpoint US
* What Is a Supply Chain Attack? - CrowdStrike
* What Is a Supply Chain Attack? | Zscaler
* What Is a Supply Chain Attack? Definition, Examples & Prevention
NEW QUESTION # 70
Which of the following represents the correct relation of alerts to incidents?
- A. Every alert creates a new Incident.
- B. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- C. Only alerts with the same host are grouped together into one Incident in a given time frame.
- D. Alerts that occur within a three hour time frame are grouped together into one Incident.
Answer: C
NEW QUESTION # 71
......
Palo Alto Networks PCDRA (Palo Alto Networks Certified Detection and Remediation Analyst) exam is a certification exam designed for individuals who want to demonstrate their expertise in detecting and remediating cyber threats. PCDRA exam is designed to test the skills and knowledge of network security professionals in identifying and analyzing threats, as well as implementing effective remediation strategies.
Truly Beneficial For Your Palo Alto Networks Exam: https://www.examsreviews.com/PCDRA-pass4sure-exam-review.html
View All PCDRA Actual Exam Questions, Answers and Explanations for Free: https://drive.google.com/open?id=1UFZrb9CP-4fuoWOHTtmHm8VMihaeW6Oo