Forwarding target: the configured collaboration sink, here Slack.
Ticketing contrast: ITSM tools serve incidents, not report delivery.
Why A is correct
Slack is the supported forwarding application for scheduled Cortex XDR reports.
Why the others are wrong
B. ServiceNow consumes incidents and tickets, not scheduled report pushes.
C. Salesforce is a CRM, not a report sink.
D. Jira tracks issues; it does not receive scheduled XDR reports.
XDR Analyst exam tip
Reports go to collaboration (Slack); incidents go to ticketing (ServiceNow/Jira).
5In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
In the Restrictions Profile, add the file name and path to the Executable Files allow list.
Add the signer to the allow list in the malware profile.
Create a new rule exception and use the singer as the characteristic.
Add the signer to the allow list under the action center page.
Answer: B
The short version
B — signer trust lives in the malware profile allow list. Adding the digital signer there stops signer-based blocking on Windows and macOS.
Key concepts in this question
Signer-based blocking: agent blocks execution by certificate signer.
Malware profile allow list: the trust override for signers.
Restrictions vs malware: file-path rules differ from signer trust.
Why B is correct
The documented exception for a blocked digital signer is adding that signer to the allow list in the malware profile.
Why the others are wrong
A. Executable-file path lists gate paths, not signers.
C. Rule exceptions with characteristics serve other rule types, not signer trust.
D. The action center manages response actions, not profile trust lists.
XDR Analyst exam tip
Signer problem means malware profile; path problem means restrictions profile.
6Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
Causality Analysis Engine
Sensor Engine
Causality Chain Engine
Log Stitching Engine
Answer: A
The short version
A — the Causality Analysis Engine builds incidents. It picks each alert key artifacts and fuses related alerts into one incident.
Key concepts in this question
Artifact selection: the most relevant entities per alert.
Aggregation: alerts sharing an event stitch into an incident.
Determining relevant artifacts per alert and aggregating event-related alerts into incidents is the Causality Analysis Engine role.
Why the others are wrong
B. The Sensor Engine collects endpoint data; it aggregates nothing.
C. Causality Chain Engine is not the named aggregation engine here.
D. The Log Stitching Engine joins raw logs; incident assembly sits above it.
XDR Analyst exam tip
Alerts-to-incident assembly always names Causality Analysis. Stitching is just log joining.
7Which statement is true based on the following Agent Auto Upgrade widget?
Agent Auto Upgrade has not been enabled.
There are a total of 689 Up To Date agents.
There are more agents in Pending status than In Progress status.
Agent Auto Upgrade was enabled but not on all endpoints.
Answer: D
The short version
D — enabled but not on all endpoints. The widget shows live upgrade statuses plus a 128-agent Not Configured slice, so auto-upgrade is on yet not universal.
Key concepts in this question
Agent Auto Update Status widget: donut of Pending (15), In Progress (78), Up To Date (450), Failed (18), Not Configured (128) over 689 agents.
Not Configured: endpoints outside auto-upgrade scope, proving coverage is partial.
Total vs Up To Date: 689 is the fleet total, not the Up To Date count (450).
Why D is correct
The exhibit shows active Pending and In Progress upgrades, so auto-upgrade is enabled, alongside 128 Not Configured agents, so it is not applied to every endpoint. 689 is the center total while Up To Date reads 450.
Why the others are wrong
A. Pending (15) and In Progress (78) activity proves the feature is enabled.
B. 689 is the total fleet; the Up To Date slice is 450.
C. Pending (15) is smaller than In Progress (78), so the comparison is reversed.
XDR-Analyst exam tip
Center number equals fleet total; always read each legend slice before picking a count-based option.
8To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?
It does not interfere with any portion of the pattern on the endpoint.
It interferes with the pattern as soon as it is observed on the endpoint.
It does not need to interfere with the any portion of the pattern to prevent the attack.
It interferes with the pattern as soon as it is observed by the firewall.
Answer: B
The short version
B — Analytics breaks the pattern on-endpoint at first sight. Any interference with part of the attack pattern stops a network-based attack.
Key concepts in this question
Pattern interference: disrupting any stage collapses the chain.
On-endpoint timing: action triggers when observed locally.
Firewall contrast: the analytics verdict fires at the endpoint, not the firewall.
Why B is correct
The Analytics module interferes with the pattern as soon as it is observed on the endpoint, which suffices to prevent the attack.
Why the others are wrong
A. No interference would let the pattern complete; prevention requires action.
C. Prevention needs interference; observation alone stops nothing.
D. The endpoint module acts on the endpoint, not via firewall observation.
XDR Analyst exam tip
Break any link, break the chain. Timing answers always say on-endpoint at observation.
9Which of the following Live Terminal options are available for Android systems?
Live Terminal is not supported.
Stop an app.
Run Android commands.
Run APK scripts.
Answer: C
The short version
C — Android Live Terminal runs Android commands. The mobile shell exposes device command execution.
Key concepts in this question
Platform scoping: terminal options differ per OS agent.
Android capability: command execution on the device.
Unsupported claims: the feature exists, so absence answers fail.
Why C is correct
Running Android commands is the available Live Terminal option on Android systems.
Why the others are wrong
A. Live Terminal support exists for Android; the absence claim is false.
B. Stopping an app is not the listed terminal option.
D. Running APK scripts is not the listed terminal option.
XDR Analyst exam tip
Mobile terminal questions answer device commands; desktop answers span wider.
10Which statement is true for Application Exploits and Kernel Exploits?
The ultimate goal of any exploit is to reach the application.
Kernel exploits are easier to prevent then application exploits.