Palo-alto-networks

PCDRA practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 85-question bank.

Provider
Palo-alto-networks
Question bank
85
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for PCDRA, a certification listed under Palo-alto-networks. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Palo-alto-networks. The certification credential is issued by Palo-alto-networks, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Phishing belongs which of the following MITRE ATT&CK tactics?

    Choose one answer.

    • Initial Access, Persistence
    • Persistence, Command and Control
    • Reconnaissance, Persistence
    • Reconnaissance, Initial Access
  2. Question 2 · 1

    When viewing the incident directly, what is the “assigned to” field value of a new Incident that was just reported to Cortex?

    Choose one answer.

    • Pending
    • It is blank
    • Unassigned
    • New
  3. Question 3 · 1

    In incident-related widgets, how would you filter the display to only show incidents that were “starred”?

    Choose one answer.

    • Create a custom XQL widget
    • This is not currently supported
    • Create a custom report and filter on starred incidents
    • Click the star in the widget
  4. Question 4 · 1

    Where would you view the WildFire report in an incident?

    Choose one answer.

    • next to relevant Key Artifacts in the incidents details page
    • under Response --> Action Center
    • under the gear icon --> Agent Audit Logs
    • on the HUB page at apps.paloaltonetworks.com
  5. Question 5 · 1

    What does the following output tell us?

    Choose one answer.

    Question illustration 1
    • There is one low severity incident.
    • Host shpapy_win10 had the most vulnerabilities.
    • There is one informational severity alert.
    • This is an actual output of the Top 10 hosts with the most malware.
  6. Question 6 · 1

    Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?

    Choose one answer.

    • Sensor Engine
    • Causality Analysis Engine
    • Log Stitching Engine
    • Causality Chain Engine
  7. Question 7 · 1

    Which type of BIOC rule is currently available in Cortex XDR?

    Choose one answer.

    • Threat Actor
    • Discovery
    • Network
    • Dropper
  8. Question 8 · 1

    In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?

    Choose one answer.

    • In the Restrictions Profile, add the file name and path to the Executable Files allow list.
    • Create a new rule exception and use the singer as the characteristic.
    • Add the signer to the allow list in the malware profile.
    • Add the signer to the allow list under the action center page.
  9. Question 9 · 1

    As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?

    Choose one answer.

    • Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.
    • Enable DLL Protection on all servers but there might be some false positives.
    • Create IOCs of the malicious files you have found to prevent their execution.
    • Enable Behavioral Threat Protection (BTP) with cytool to prevent the attack from spreading.
  10. Question 10 · 1

    Which statement is true based on the following Agent Auto Upgrade widget?

    Choose one answer.

    Question illustration 1
    • There are a total of 689 Up To Date agents.
    • Agent Auto Upgrade was enabled but not on all endpoints.
    • Agent Auto Upgrade has not been enabled.
    • There are more agents in Pending status than In Progress status.
  11. Question 11 · 1

    What is the purpose of targeting software vendors in a supply-chain attack?

    Choose one answer.

    • to take advantage of a trusted software delivery method.
    • to steal users’ login credentials.
    • to access source code.
    • to report Zero-day vulnerabilities.
  12. Question 12 · 1

    What is the standard installation disk space recommended to install a Broker VM?

    Choose one answer.

    • 1GB disk space
    • 2GB disk space
    • 512GB disk space
    • 256GB disk space
  13. Question 13 · 1

    How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?

    Choose one answer.

    • by encrypting the disk first.
    • by utilizing decoy Files.
    • by retrieving the encryption key.
    • by patching vulnerable applications.
  14. Question 14 · 1

    What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?

    Choose one answer.

    • Netflow Collector
    • Syslog Collector
    • DB Collector
    • Pathfinder
  15. Question 15 · 1

    When is the wss (WebSocket Secure) protocol used?

    Choose one answer.

    • when the Cortex XDR agent downloads new security content
    • when the Cortex XDR agent uploads alert data
    • when the Cortex XDR agent connects to WildFire to upload files for analysis
    • when the Cortex XDR agent establishes a bidirectional communication channel

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free