Palo Alto Networks PCDRA Exam Practice Questions (P. 1)
- Full Access (96 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Phishing belongs which of the following MITRE ATT&CK tactics?
- AInitial Access, Persistence
- BPersistence, Command and Control
- CReconnaissance, Persistence
- DReconnaissance, Initial AccessMost Voted
Correct Answer:
D
D
send
light_mode
delete
Question #2
When creating a BIOC rule, which XQL query can be used?
- Adataset = xdr_data
| filter event_sub_type = PROCESS_START and
action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe" - Bdataset = xdr_data
| filter event_type = PROCESS and
event_sub_type = PROCESS_START and
action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"Most Voted - Cdataset = xdr_data
| filter action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"
| fields action_process_image - Ddataset = xdr_data
| filter event_behavior = true
event_sub_type = PROCESS_START and
action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"
Correct Answer:
B
B
send
light_mode
delete
Question #3
Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
- ASecurity Manager Dashboard
- BData Ingestion Dashboard
- CSecurity Admin Dashboard
- DIncident Management Dashboard
Correct Answer:
A
A
send
light_mode
delete
Question #4
What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)
- AAutomatically close the connections involved in malicious traffic.Most Voted
- BAutomatically kill the processes involved in malicious activity.
- CAutomatically terminate the threads involved in malicious activity.
- DAutomatically block the IP addresses involved in malicious traffic.Most Voted
Correct Answer:
AD
AD
send
light_mode
delete
Question #5
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
- AClick the three dots on the widget and then choose “Save” and this will link the query to the Widget Library.
- BThis isn’t supported, you have to exit the dashboard and go into the Widget Library first to create it.
- CClick on “Save to Action Center” in the dashboard and you will be prompted to give the query a name and description.
- DClick on “Save to Widget Library” in the dashboard and you will be prompted to give the query a name and description.
Correct Answer:
D
D
send
light_mode
delete
All Pages