Skip to content

xdr-engineer XDR Engineer Practice Questions

Prepare for xdr-engineer with more than an answer.

200 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 5
  1. Planning and Installation14%
  2. Cortex XDR Agent Configuration22%
  3. Ingestion and Automation22%
  4. Detection and Reporting22%
  5. Maintenance and Troubleshooting20%
  1. 1

    A Cortex XDR agent content update fails to install on a group of critical servers during a maintenance window. The administrator needs to revert the agents in that group to the previous stable content version as quickly as possible. What is the most efficient method to achieve this?

    Show answer details

    Correct answer: B

    Cortex XDR provides a centralized mechanism for managing agent and content versions. The most efficient way to roll back a content update for a specific group of endpoints is to edit the Agent Settings profile applied to that group and select the desired previous, stable content version. The agents will automatically revert upon their next check-in, without requiring manual intervention on each endpoint.

  2. 2

    True or False: Compute Units in Cortex XDR are consumed solely based on the volume of data (in GB) ingested into the Cortex Data Lake.

    Show answer details

    Correct answer: B

    False. Compute Unit consumption is based on a combination of factors, not just data volume. The main factors are the number of endpoints with the Pro agent enabled and the volume of third-party data ingested. The complexity of queries and analytics performed also contributes to compute usage, making it a more comprehensive metric than just raw data ingestion.

  3. 3

    What is the primary function of an endpoint group in Cortex XDR?

    Show answer details

    Correct answer: B

    The primary purpose of endpoint groups is to serve as a target for policy application. By grouping endpoints based on criteria like OS, IP range, or Active Directory OU, administrators can apply tailored security profiles (Malware, Agent Settings, etc.) to different sets of endpoints, rather than applying one monolithic policy to all.

  4. 4

    An XDR engineer is creating a parsing rule for a custom log format using a regular expression. The log entry is: Timestamp=2023-10-27T10:00:00Z Level=ERROR User=admin Action=LoginFailed SrcIP=192.168.1.100. The engineer needs to extract the value of SrcIP. Which regular expression will correctly capture the IP address?

    Show answer details

    Correct answer: D

    This regular expression SrcIP=([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+) specifically looks for the literal string SrcIP= followed by a capturing group (...). Inside the group, it matches one or more digits ([0-9]+) followed by a literal dot (\.) three times, and then a final set of one or more digits. This accurately and specifically captures an IPv4 address format. (.*) is too greedy and would capture the rest of the line, while (\d{1,3}) would only capture the first octet.

  5. 5

    A SOC has a high volume of alerts related to PowerShell execution, many of which are benign administrative scripts. To reduce noise, an analyst wants to create an exception for a specific, digitally signed script named Update-Inventory.ps1, which is always run from C:\ProgramData\AdminScripts\. What is the most precise and secure method to create this exception in Cortex XDR?

    Show answer details

    Correct answer: A

    The most secure and precise method is to combine multiple attributes. A signer-based exception ensures that only scripts signed by the trusted internal CA are allowed, preventing spoofed scripts with the same name. Combining this with a path-based exception (C:\ProgramData\AdminScripts\Update-Inventory.ps1) ensures that the trusted script can only be run from its authorized location. A broad process or path exception would create a significant security blind spot.

  6. 6

    A global financial institution is deploying Cortex XDR across a hybrid environment with 50,000 endpoints. The primary objective is to centralize log collection from legacy syslog devices, cloud flow logs, and Palo Alto Networks NGFWs, while minimizing latency for real-time threat hunting. The security architect must decide on the optimal Broker VM architecture. Given the requirements for high availability, geographic distribution, and performance, which Broker VM deployment strategy should the architect recommend?

    Show answer details

    Correct answer: C

    For a large, geographically dispersed hybrid environment, a distributed Broker VM cluster is the optimal design. This architecture provides high availability through failover, reduces latency by processing logs closer to the source, and offers horizontal scalability by adding more nodes. A single cluster creates a single point of failure and introduces significant latency. Independent instances lack the centralized management and automatic failover capabilities inherent in a cluster. A cloud-only deployment would create unnecessary latency and cost for forwarding on-premises logs to the cloud for processing.

  7. 7

    A security engineer is creating a new endpoint security profile for a group of developers who frequently work with unsigned binaries and custom scripts for testing purposes. The goal is to provide strong protection without impeding their development workflow. Which TWO settings within the Malware Protection profile should be configured to achieve this balance? (Select TWO)

    Show answer details

    Correct answer: B, E

    Enabling "Behavioral Threat Protection" is crucial as it analyzes process behavior rather than just static signatures, providing protection against malicious actions from legitimate-looking developer tools.

    Setting "Unsigned Executable Files" to "Report" allows developers to run their custom binaries while still giving the security team visibility into this activity without blocking them.

  8. 8

    True or False: The Cortex XDR Broker VM can be configured with a Syslog Collector applet to receive, parse, and forward logs from third-party devices to the Cortex Data Lake.

    Show answer details

    Correct answer: A

    True. The Broker VM is the primary component for collecting logs from on-premises third-party sources. It uses applets, such as the Syslog Collector applet, to ingest data from various sources like firewalls, proxies, and servers, then normalizes and forwards this data to the Cortex Data Lake for analysis.

  9. 9

    A healthcare organization has recently deployed Cortex XDR and is concerned about sophisticated lateral movement techniques. Their environment consists of Windows servers hosting electronic health record (EHR) systems and workstations used by clinical staff. The threat intelligence team has warned about adversaries using legitimate administrative tools like PsExec for lateral movement after gaining an initial foothold. The SOC manager wants to create a high-fidelity detection rule that specifically identifies anomalous PsExec usage targeting critical EHR servers.

    The EHR servers are all part of an Active Directory group named "EHR-Servers". Normal administrative activity originates from a dedicated set of bastion hosts within the 10.100.50.0/24 subnet. The SOC team has observed that attackers often launch PsExec from compromised user workstations, which are in different subnets. The goal is to generate an alert only when PsExec is used to connect to an EHR server from a source that is NOT one of the authorized bastion hosts.

    Which XQL query would be most effective for creating a Correlation Rule to detect this specific suspicious activity?

    Show answer details

    Correct answer: A

    This XQL query is the most accurate and effective. It correctly filters for process launch events (event_type = PROCESS_LAUNCH), specifically for psexec.exe, targets the critical servers by their endpoint group (agent_hostname in (group_name="EHR-Servers")), and critically, excludes legitimate traffic from the bastion host subnet (not actor_ip_address in("10.100.50.0/24")). The other options are flawed: one only counts usage, another incorrectly filters on pre-built stories and the wrong IP field, and the third checks for a causality ID without filtering by the crucial source IP.

  10. 10

    During a routine health check, a Cortex XDR administrator notices that several endpoints in a remote branch office have not checked in for over 24 hours. The administrator has confirmed network connectivity between the branch office and the corporate data center. The cytool command-line utility is available on one of the affected endpoints. Which cytool command should the administrator run first to diagnose the agent's communication status with the Cortex XDR console?

    Show answer details

    Correct answer: B

    The cytool checkin command forces the Cortex XDR agent to attempt an immediate check-in with the server. The output provides detailed information about the connection attempt, including TLS handshake errors, DNS resolution problems, or server connectivity issues. This makes it the most direct first step for diagnosing communication problems. cytool status provides general agent status but doesn't actively test connectivity. cytool runtime query is for querying agent processes, and cytool persist list shows the agent's database of persistent data.

Create an account to continue.