Sign In
Home/Palo Alto/Palo Alto Networks Certified XDR Engineer/Free questions

Palo Alto Networks Certified XDR Engineer — Free Practice Questions

10 free sample questions from a bank of 45, with the correct answers and explanations. No signup required — start practising right now.

1A threat hunter wants to prioritize investigations according to attacker objectives, techniques, and operational tactics. Which framework provides the best alignment?
  • CIS Asset Inventory
  • MITRE ATT&CK Mapping
  • CVSS Environmental Metrics
  • PCI DSS Controls
Answer: B

The short version

B — MITRE ATT&CK aligns hunts to adversary behavior. Tactics, techniques, and objectives map directly onto investigations.

Key concepts in this question

  • ATT&CK structure: tactics (why), techniques (how), procedures (what).
  • Prioritization: attacker objectives order the hunt queue.
  • Peer frameworks: inventory, scoring, and compliance serve other goals.

Why B is correct

MITRE ATT&CK Mapping is the framework built for aligning investigations to attacker objectives, techniques, and tactics.

Why the others are wrong

  • A. CIS Asset Inventory catalogs assets; it prioritizes no hunts.
  • C. CVSS Environmental Metrics score vulns; they map no adversary behavior.
  • D. PCI DSS Controls check compliance; they guide no threat hunt.

XDR Engineer exam tip

Hunt-priority wording always answers ATT&CK. Compliance and scoring never do.

2Which statement describes the functionality of fixed filters and dashboard drilldowns in enhancing a dashboard's interactivity and data insights?
  • Fixed filters allow users to select predefined data values, while dashboard drilldowns enable users to alter the scope of the data displayed by selecting filter values from the dashboard header
  • Fixed filters let users select predefined or dynamic values to adjust the scope, while dashboard drilldowns provide interactive insights or trigger contextual changes, like linking to XQL searches
  • Fixed filters limit the data visible in widgets, while dashboard drilldowns allow users to download data from the dashboard in various formats
  • Fixed filters allow users to adjust the layout, while dashboard drilldowns provide links to external reports and/or dashboards
Answer: B

The short version

B — fixed filters scope, drilldowns interact. Filters take preset or dynamic values; drilldowns open insights or fire console actions.

Key concepts in this question

  • Fixed filters: predefined or dynamic scoping controls.
  • Drilldowns: click-through to detail or triggered console behavior.
  • Non-roles: downloads, layouts, and external links are separate features.

Why B is correct

Fixed filters adjust scope via preset or dynamic values while drilldowns deliver interactive insights or trigger console actions.

Why the others are wrong

  • A. Filters are not predefined-only; dynamic values are supported.
  • C. Drilldowns do not download data in formats; they navigate and act.
  • D. Filters scope data, never layouts; drilldowns stay in-console.

XDR Engineer exam tip

Scope equals filter, click equals drilldown. Downloads live elsewhere.

3How can a Malware profile be configured to prevent a specific executable from being uploaded to the cloud?
  • Add the executable to the allow list for executions
  • Create an exclusion rule for the executable
  • Disable on-demand file examination for the executable
  • Set PE and DLL examination for the executable to report action mode
Answer: B

The short version

B — an exclusion rule stops the cloud upload path. Excluded executables skip the examination-and-upload flow.

Key concepts in this question

  • Cloud upload: agent sends samples for WildFire verdicts.
  • Exclusion effect: matching executables leave the pipeline.
  • Allow vs exclude: allow permits execution; exclusion removes from handling.

Why B is correct

Creating an exclusion rule for the executable keeps it from being uploaded to the cloud.

Why the others are wrong

  • A. Allow-listing permits execution; it does not govern uploads.
  • C. Disabling on-demand examination covers manual scans, not the upload path.
  • D. Report mode still examines and uploads; it only softens the action.

XDR Engineer exam tip

Stop-the-upload means exclusion. Execution permission means allow list.

4What happens when two or more values are specified for a disable prevention rule in Cortex XDR to allow file execution?
  • The rule is ignored if multiple values are specified for the target properties.
  • The exception is applied if the file satisfies all of the specified target properties.
  • The rule applies if the file satisfies any of the specified target properties.
  • The rule automatically applies to all files regardless of their properties.
Answer: B

The short version

B — multiple values AND together. The file must satisfy every specified target property for the exception to apply.

Key concepts in this question

  • Disable prevention rule: exception allowing file execution.
  • Multi-value logic: conjunctive matching across properties.
  • Precision payoff: narrower exceptions, safer allows.

Why B is correct

When two or more values are specified, the exception applies only if the file satisfies all of the target properties.

Why the others are wrong

  • A. Multiple values never void the rule.
  • C. Any-match (OR) logic would over-allow; the rule requires all.
  • D. Unconditional application contradicts property matching entirely.

XDR Engineer exam tip

Stacked exception values narrow, never widen. All must hit.

5Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?
  • dataset = xdr_data| filter event_type = FILE and (event_sub_type = FILE_CREATE_NEW or event_sub_type = FILE_WRITE or event_sub_type = FILE_REMOVE or event_sub_type = FILE_RENAME) and agent_hostname = "hostname"| filter lowercase(action_file_path) in ("/etc/","/usr/local/share/", "/usr/share/*") and action_file_extension in ("conf", "txt")| fields action_file_name, action_file_path, action_file_type, agent_ip_addresses, agent_hostname, action_file_path
  • dataset = xdr_data| filter event_type = ENUM.DEVICE and action_process_image_name ="**"and action_process_image_command_line = "-e cmd"andaction_process_image_command_line != "cmd.exe -a /c*"
  • dataset = xdr_data| filter event_type = ENUM.PROCESS and event_type = ENUM.DEVICE and action_process_image_name = "**"and action_process_image_command_line = "-e cmd"and action_process_image_command_line != "cmd.exe -a /c*"
  • dataset = xdr_data| filter event_type = ENUM.PROCESS and action_process_image_name ="**"and action_process_image_command_line = "-e cmd"andaction_process_image_command_line != "cmd.exe -a /c*"
Answer: D

The short version

D — only the clean PROCESS query converts. A well-formed process-behavior filter becomes a BIOC and then a prevention rule.

Key concepts in this question

  • BIOC requirement: valid behavioral filter, here on process execution.
  • Conversion path: BIOC first, custom prevention second.
  • Malformed queries: wrong enums and doubled fields never validate.

Why D is correct

The ENUM.PROCESS query with process-image and command-line filters is the valid behavioral indicator convertible to custom prevention.

Why the others are wrong

  • A. FILE-event queries are file indicators, not the convertible process behavior here.
  • B. ENUM.DEVICE mistypes the behavior class; the query is invalid.
  • C. Doubled event_type filters (PROCESS and DEVICE) invalidate the query.

XDR Engineer exam tip

Convertible means valid first: single correct enum, sane fields, then promote.

6What is the earliest time frame an alert could be automatically generated once the conditions of a new correlation rule are met?
  • Immediately
  • Between 30 and 45 minutes
  • Between 10 and 20 minutes
  • 5 minutes or less
Answer: C

The short version

C — correlation alerts land in 10 to 20 minutes. The engine evaluates on its cycle, not instantly.

Key concepts in this question

  • Correlation cadence: scheduled evaluation windows.
  • Earliest generation: first cycle after conditions fill.
  • Instant myth: no zero-delay auto-generation exists.

Why C is correct

Once a new correlation rule conditions are met, the earliest automatic alert falls in the 10-to-20-minute window.

Why the others are wrong

  • A. Immediate generation skips the evaluation cycle that must run.
  • B. 30 to 45 minutes overshoots the documented earliest window.
  • D. Sub-5-minute generation is faster than the engine cycle allows.

XDR Engineer exam tip

Correlation timing is cycle timing: 10-20 minutes, never instant.

7Which configuration profile option with an available built-in template can be applied to both Windows and Linux systems by using XDR Collector?
  • Filebeat
  • HTTP Collector template
  • XDR Collector settings
  • Winlogbeat
Answer: A

The short version

A — Filebeat ships cross-platform via XDR Collector. Its built-in template covers Windows and Linux alike.

Key concepts in this question

  • Filebeat: lightweight log shipper for files.
  • Built-in template: ready-made collector configuration.
  • Platform split: Winlogbeat is Windows-only by contrast.

Why A is correct

The Filebeat built-in template applies to both Windows and Linux systems through XDR Collector.

Why the others are wrong

  • B. The HTTP Collector template serves HTTP ingestion, not the cross-platform case.
  • C. Collector settings is the generic menu, not the named template.
  • D. Winlogbeat is Windows-only and fails the both-systems condition.

XDR Engineer exam tip

Both-OS collection says Filebeat; Windows-only says Winlogbeat.

8An engineer is building a dashboard to visualize the number of alerts from various sources. One of the widgets from the dashboard is shown in the image below:The engineer wants to configure a drilldown on this widget to allow dashboard users to select any of the alert names and view those alerts with additional relevant details. The engineer has configured the following XQL query to meet the requirement:dataset = alerts| fields alert_name, description, alert_source, severity,original_tags, alert_id, incident_id| filter alert_name =| sort desc _timeHow will the engineer complete the third line of the query (filter alert_name =) to allow dynamic filtering on a selected alert name?
Palo Alto Networks Certified XDR Engineer question 8
  • $y_axis.value
  • $x_axis.value
  • $y_axis.name
  • $x_axis.name
Answer: B

The short version

B — Filter on $x_axis.value to capture the clicked alert name. The donut lists alert names as the x-axis categories, so the clicked slice value is the alert name the drilldown must pass.

Key concepts in this question

  • Chart axes: the alert-name field is the string x-axis category while the count is the numeric y-axis.
  • Drilldown variables: $x_axis.value selects the x-axis value for the clicked element.
  • Parameterized filter: filter alert_name = <clicked value> makes the target query dynamic per click.

Why B is correct

The widget "Top XDR Analytics Alerts" breaks 148 alerts down by name (Large Upload, HTTP with suspicious characteristics, port scan). Clicking a segment must feed that segment's name into filter alert_name =, and Cortex drilldown variables define $x_axis.value as the x-axis value for the clicked value on chart widgets including pie views. Hence filter alert_name = $x_axis.value completes the requirement.

Why the others are wrong

  • A. $y_axis.value would pass the numeric count (113, 16, 12, 7), not an alert name, so the filter would match nothing.
  • C. $y_axis.name passes the y-axis field name (the count field), not the selected alert.
  • D. $x_axis.name passes the x-axis field name (alert_name itself), a constant string rather than the clicked alert.

XDR-Engineer exam tip

Drilldown wants a value, not a name: x holds categories so $x_axis.value carries the click; .name only carries the field label.

9An attacker uses a malicious Microsoft Word document to launch PowerShell, download malware, and establish persistence. Which Cortex XDR feature best visualizes this sequence?
  • Live Terminal
  • Endpoint Administration
  • Device Control Policy
  • Causality Chain Analysis
Answer: D

The short version

D — the Word-to-PowerShell-to-persistence chain is Causality. Only the causality view links the sequence end to end.

Key concepts in this question

  • Causality chain: parent-child process story across the attack.
  • Document-to-shell pattern: classic initial-access-to-persistence flow.
  • Tool split: terminals act, admin pages manage, policies constrain.

Why D is correct

Causality Chain Analysis visualizes the malicious document launching PowerShell, dropping malware, and persisting as one linked sequence.

Why the others are wrong

  • A. Live Terminal gives a shell; it draws no attack sequence.
  • B. Endpoint Administration manages agents; it visualizes no chain.
  • C. Device Control Policy governs media; it shows no execution story.

XDR Engineer exam tip

Sequence questions answer Causality. Single-point tools never tell stories.

10An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?
  • RULE
  • INGEST
  • FILTER
  • CONST
Answer: A

The short version

A — reusable extraction lives in RULE. Define once there, reference across sources.

Key concepts in this question

  • RULE section: shared reusable parsing logic.
  • INGEST/FILTER: intake and selection stages, not libraries.
  • CONST: fixed values, not reusable rules.

Why A is correct

The RULE section is where administrators define reusable rules for consistent field extraction.

Why the others are wrong

  • B. INGEST handles intake plumbing, not reusable logic.
  • C. FILTER selects logs; it stores no reusable rules.
  • D. CONST holds constants, not rule definitions.

XDR Engineer exam tip

Reuse equals RULE. Intake, filter, and constants never host libraries.

Want the full bank of 45 questions for Palo Alto Networks Certified XDR Engineer? See all practice exams.