
PDF Download Free of PCDRA Valid Practice Test Questions
PCDRA Test Engine files, PCDRA Dumps PDF
The PCDRA exam is a comprehensive test that covers a range of topics related to network security, including threat detection, analysis, and remediation techniques. PCDRA exam is designed for security professionals who have experience working with Palo Alto Networks technologies, and who are looking to enhance their skills and knowledge in this area.
NEW QUESTION # 18
Which minimum Cortex XDR agent version is required for Kubernetes Cluster?
- A. Cortex XDR 7.5
- B. Cortex XDR 7.4
- C. Cortex XDR 5.0
- D. Cortex XDR 6.1
Answer: A
Explanation:
Explanation
The minimum Cortex XDR agent version required for Kubernetes Cluster is Cortex XDR 7.5. This version introduces the Cortex XDR agent for Kubernetes hosts, which provides protection and visibility for Linux hosts that run on Kubernetes clusters. The Cortex XDR agent for Kubernetes hosts supports the following features:
* Anti-malware protection
* Behavioral threat protection
* Exploit protection
* File integrity monitoring
* Network security
* Audit and remediation
* Live terminal
To install the Cortex XDR agent for Kubernetes hosts, you need to deploy the Cortex XDR agent as a DaemonSet on your Kubernetes cluster. You also need to configure the agent settings profile and the agent installer in the Cortex XDR management console. References:
* Cortex XDR Agent Release Notes: This document provides the release notes for Cortex XDR agent versions, including the new features, enhancements, and resolved issues.
* Install the Cortex XDR Agent for Kubernetes Hosts: This document explains how to install and configure the Cortex XDR agent for Kubernetes hosts using the Cortex XDR management console and the Kubernetes command-line tool.
NEW QUESTION # 19
Which of the following represents the correct relation of alerts to incidents?
- A. Alerts that occur within a three hour time frame are grouped together into one Incident.
- B. Only alerts with the same host are grouped together into one Incident in a given time frame.
- C. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- D. Every alert creates a new Incident.
Answer: B
NEW QUESTION # 20
To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
- A. endpoint_name
- B. event_type
- C. threat_event
- D. causality_chain
Answer: B
NEW QUESTION # 21
Which license is required when deploying Cortex XDR agent on Kubernetes Clusters as a DaemonSet?
- A. Host Insights
- B. Cortex XDR Pro per Endpoint
- C. Cortex XDR Cloud per Host
- D. Cortex XDR Pro per TB
Answer: C
NEW QUESTION # 22
Which statement regarding scripts in Cortex XDR is true?
- A. Any version of Python script can be run.
- B. The script is run on the machine uploading the script to ensure that it is operational.
- C. Any script can be imported including Visual Basic (VB) scripts.
- D. The level of risk is assigned to the script upon import.
Answer: D
Explanation:
Explanation
The correct answer is B, the level of risk is assigned to the script upon import. When you import a script to the Agent Script Library in Cortex XDR, you need to specify the level of risk associated with the script. The level of risk determines the permissions and restrictions for running the script on endpoints. The levels of risk are:
* Low: The script can be run on any endpoint without requiring approval from the Cortex XDR administrator. The script can also be used in remediation suggestions or automation actions.
* Medium: The script can be run on any endpoint, but requires approval from the Cortex XDR administrator. The script can also be used in remediation suggestions or automation actions.
* High: The script can only be run on isolated endpoints, and requires approval from the Cortex XDR administrator. The script cannot be used in remediation suggestions or automation actions.
The other options are incorrect for the following reasons:
* A is incorrect because not any version of Python script can be run in Cortex XDR. The scripts must be written in Python 2.7, and must follow the guidelines and limitations described in the Cortex XDR documentation. For example, the scripts must not exceed 64 KB in size, must not use external libraries
* or modules, and must not contain malicious or harmful code.
* C is incorrect because not any script can be imported to Cortex XDR, including Visual Basic (VB) scripts. The scripts must be written in Python 2.7, and must follow the guidelines and limitations described in the Cortex XDR documentation. VB scripts are not supported by Cortex XDR, and will not run on the endpoints.
* D is incorrect because the script is not run on the machine uploading the script to ensure that it is operational. The script is only validated for syntax errors and size limitations when it is imported to the Agent Script Library. The script is not executed or tested on the machine uploading the script, and the script may still fail or cause errors when it is run on the endpoints.
References:
* Agent Script Library
* Import a Script
* Run Scripts on an Endpoint
NEW QUESTION # 23
When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)
- A. Investigate several Incidents at once.
- B. Change the status of multiple incidents.
- C. Assign incidents to an analyst in bulk.
- D. Delete the selected Incidents.
Answer: B,C
NEW QUESTION # 24
When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)
- A. Investigate several Incidents at once.
- B. Change the status of multiple incidents.
- C. Assign incidents to an analyst in bulk.
- D. Delete the selected Incidents.
Answer: B,C
Explanation:
Explanation
When selecting multiple incidents at a time, the options that are available from the menu when a user right-clicks the incidents are: Assign incidents to an analyst in bulk and Change the status of multiple incidents. These options allow the user to perform bulk actions on the selected incidents, such as assigning them to a specific analyst or changing their status to open, in progress, resolved, or closed. These options can help the user to manage and prioritize the incidents more efficiently and effectively. To use these options, the user needs to select the incidents from the incident table, right-click on them, and choose the desired option from the menu. The user can also use keyboard shortcuts to perform these actions, such as Ctrl+A to select all incidents, Ctrl+Shift+A to assign incidents to an analyst, and Ctrl+Shift+S to change the status of incidents12 References:
* Assign Incidents to an Analyst in Bulk
* Change the Status of Multiple Incidents
NEW QUESTION # 25
Phishing belongstowhich of the following MITRE ATT&CK tactics?
- A. Reconnaissance, Initial Access
- B. Reconnaissance, Persistence
- C. Persistence, Command and Control
- D. Initial Access, Persistence
Answer: A
Explanation:
Explanation
Phishing is a technique that belongs to two MITRE ATT&CK tactics: Reconnaissance and Initial Access.
Reconnaissance is the process of gathering information about a target before launching an attack. Phishing for information is a sub-technique of Reconnaissance that involves sending phishing messages to elicit sensitive information that can be used during targeting. Initial Access is the process of gaining a foothold in a network or system. Phishing is a sub-technique of Initial Access that involves sending phishing messages to execute malicious code on victim systems. Phishing can be used for both Reconnaissance and Initial Access depending on the objective and content of the phishing message. References:
* Phishing, Technique T1566 - Enterprise | MITRE ATT&CK 1
* Phishing for Information, Technique T1598 - Enterprise | MITRE ATT&CK 2
* Phishing for information, Part 2: Tactics and techniques 3
* PHISHING AND THE MITREATT&CK FRAMEWORK - EnterpriseTalk 4
* Initial Access, Tactic TA0001 - Enterprise | MITRE ATT&CK 5
NEW QUESTION # 26
In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?
- A. Syslog Collector
- B. Agent Installer and Content Caching
- C. CSV Collector
- D. Agent Proxy
Answer: B
Explanation:
Explanation
The Agent Installer and Content Caching applet of the Broker VM is used to download and cache the Cortex XDR agent installation packages and content updates from Palo Alto Networks servers. This applet also acts as a proxy server for the Cortex XDR agents to communicate with the Cortex Data Lake and the Cortex XDR management console. To ensure secure communication between the Broker VM and the Cortex XDR agents, you are required to install a strong cipher SHA256-based SSL certificate on the Broker VM. The SSL certificate must have a common name or subject alternative name that matches the Broker VM FQDN or IP address. The SSL certificate must also be trusted by the Cortex XDR agents, either by using a certificate signed by a public CA or by manually installing the certificate on the endpoints. References:
* Agent Installer and Content Caching
* Install an SSL Certificate on the Broker VM
NEW QUESTION # 27
Which of the following best defines the Windows Registry as used by the Cortex XDR agent?
- A. a system of files used by the operating system to commit memory that exceeds the available hardware resources. Also known as the "swap"
- B. a hierarchical database that stores settings for the operating system and for applications
- C. a ledger for maintaining accurate and up-to-date information on total disk usage and disk space remaining available to the operating system
- D. a central system, available via the internet, for registering officially licensed versions of software to prove ownership
Answer: B
NEW QUESTION # 28
You can star security events in which two ways? (Choose two.)
- A. Create an alert-starring configuration.
- B. Create an Incident-starring configuration.
- C. Manually star an Incident.
- D. Manually star an alert.
Answer: B,C
NEW QUESTION # 29
How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?
- A. by patching vulnerable applications.
- B. by encrypting the disk first.
- C. by utilizing decoy Files.
- D. by retrieving the encryption key.
Answer: C
Explanation:
Explanation
Cortex XDR agent for Windows prevents ransomware attacks from compromising the file system by utilizing decoy files. Decoy files are randomly generated files that are placed in strategic locations on the endpoint, such as the user's desktop, documents, and pictures folders. These files are designed to look like valuable data that ransomware would target for encryption. When Cortex XDR agent detects that a process is attempting to access or modify a decoy file, it immediately blocks the process and alerts the administrator. This way, Cortex XDR agent can stop ransomware attacks before they can cause any damage to the real files on the endpoint.
References:
* Anti-Ransomware Protection
* PCDRA Study Guide
NEW QUESTION # 30
Which search methods is supported by File Search and Destroy?
- A. File Search and Repair
- B. File Seek and Repair
- C. File Search and Destroy
- D. File Seek and Destroy
Answer: C
Explanation:
Explanation
File Search and Destroy is a feature of Cortex XDR that allows you to search for and remove malicious files from endpoints. You can use this feature to find files by their hash, full path, or partial path using regex parameters. You can then select the files from the search results and destroy them by hash or by path. When you destroy a file by hash, all the file instances on the endpoint are removed. File Search and Destroy is useful for quickly responding to threats and preventing further damage. References:
* Search and Destroy Malicious Files
* Cortex XDR Pro Administrator Guide
NEW QUESTION # 31
When investigating security events, which feature in Cortex XDR is useful for reverting the changes on the endpoint?
- A. Remediation Automation
- B. Remediation Suggestions
- C. Automatic Remediation
- D. Machine Remediation
Answer: B
NEW QUESTION # 32
Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?
- A. Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.
- B. Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.
- C. Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.
- D. Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.
Answer: C
Explanation:
Explanation
Cortex XDR Analytics is a cloud-based service that uses machine learning and artificial intelligence to detect and prevent network attacks. Cortex XDR Analytics can interfere with the attack pattern as soon as it is observed on the endpoint by applying protection policies that block malicious processes, files, or network connections. This way, Cortex XDR Analytics can stop the attack before it causes any damage or compromises the system. References:
* [Cortex XDR Analytics Overview]
* [Cortex XDR Analytics Protection Policies]
NEW QUESTION # 33
What is the difference between presets and datasets in XQL?
- A. A dataset is a database; presets is a field.
- B. A dataset is a built-in orthird-partysource; presets group XDR data fields.
- C. A dataset is a Cortex data lake data source only; presets are built-in data source.
- D. A dataset is a third-party data source; presets are built-in data source.
Answer: B
Explanation:
Explanation
The difference between presets and datasets in XQL is that a dataset is a built-in or third-party data source, while a preset is a group of XDR data fields. A dataset is a collection of data that you can query and analyze using XQL. A dataset can be a Cortex data lake data source, such as endpoints, alerts, incidents, or network flows, or a third-party data source, such as AWS CloudTrail, Azure Activity Logs, or Google Cloud Audit Logs. A preset is a predefined set of XDR data fields that are relevant for a specific use case, such as process execution, file operations, or network activity. A preset can help you simplify and standardize your XQL queries by selecting the most important fields for youranalysis. You can use presets with any Cortex data lake data source, but not with third-party data sources. References:
* Datasets and Presets
* XQL Language Reference
NEW QUESTION # 34
While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
- A. mark the incident as Resolved - False Positive
- B. create a BIOC rule excluding this behavior
- C. create an exception to prevent future false positives
- D. mark the incident as Unresolved
Answer: A
NEW QUESTION # 35
Which of the following represents the correct relation of alerts to incidents?
- A. Only alerts with the same host are grouped together into one Incident in a given time frame.
- B. Alerts that occur within athree-hourtime frame are grouped together into one Incident.
- C. Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
- D. Every alert creates a new Incident.
Answer: C
Explanation:
Explanation
The correct relation of alerts to incidents is that alerts with same causality chains that occur within a given time frame are grouped together into an incident. A causality chain is a sequence of events that are related to the same malicious activity, such as a malware infection, a lateral movement, or a data exfiltration. Cortex XDR uses a set of rules that take into account different attributes of the alerts, such as the alert source, type, and time period, to determine if they belong to the same causality chain. By grouping related alerts into incidents, Cortex XDR reduces the number of individual events to review and provides a complete picture of the attack with rich investigative details1.
Option A is incorrect, because alerts with the same host are not necessarily grouped together into one incident in a given time frame. Alerts with the same host may belong to different causality chains, or may be unrelated to any malicious activity. For example, if a host has a malware infection and a network anomaly, these alerts may not be grouped into the same incident, unless they are part of the same attack.
Option B is incorrect, because alerts that occur within a three hour time frame are not always grouped together into one incident. The time frame is not the only criterion for grouping alerts into incidents. Alerts that occur within a three hour time frame may belong to different causality chains, or may be unrelated to any malicious activity. For example, if a host has a file download and a registry modification within a three hour time frame, these alerts may not be grouped into the same incident, unless they are part of the same attack.
Option D is incorrect, because every alert does not create a new incident. Creating a new incident for every alert would result in alert fatigue and inefficient investigations. Cortex XDR aims to reduce the number of incidents by grouping related alerts into one incident, based on their causality chains and other attributes.
References:
* Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) Study Guide, page 9
* Palo Alto Networks Cortex XDR Documentation, Incident Management Overview2
* Cortex XDR: Stop Breaches with AI-Powered Cybersecurity1
NEW QUESTION # 36
Which type of BIOC rule is currently available in Cortex XDR?
- A. Network
- B. Threat Actor
- C. Dropper
- D. Discovery
Answer: D
Explanation:
Explanation
The type of BIOC rule that is currently available in Cortex XDR is Discovery. A Discovery BIOC rule is a rule that detects suspicious or malicious behavior on endpoints based on the Cortex XDR data. A Discovery BIOC rule can use various event types, such as file, injection, load image, network, process, registry, or user, to define the criteria for the rule. A Discovery BIOC rule can also use operators, functions, and variables to create complex logic and conditions for the rule. A Discovery BIOC rule can generate alerts when the rule is triggered, and these alerts can be grouped into incidents for further investigation and response12.
Let's briefly discuss the other options to provide a comprehensive explanation:
A: Threat Actor: This is not the correct answer. Threat Actor is not a type of BIOC rule that is currently available in Cortex XDR. Threat Actor is a term that refers to an individual or a group that is responsible for a cyberattack or a threat campaign. Cortex XDR does not support creating BIOC rules based on threat actors, but it can provide threat intelligence and context from various sources, such as Unit 42, AutoFocus, or Cortex XSOAR3.
C: Network: This is not the correct answer. Network is not a type of BIOC rule that is currently available in Cortex XDR. Network is an event type that can be used in a Discovery BIOC rule to define the criteria based on network attributes, such as source IP, destination IP, source port, destination port, protocol, or domain. Network is not a standalone type of BIOC rule, but a part of the Discovery BIOC rule2.
D: Dropper: This is not the correct answer. Dropper is not a type of BIOC rule that is currently available in Cortex XDR. Dropper is a term that refers to a type of malware that is designed to download and install other malicious files or programs on a compromised system. Cortex XDR does not support creating BIOC rules based on droppers, but it can detect and prevent droppers using various methods, such as behavioral threat protection, exploit prevention, or WildFire analysis4.
In conclusion, the type of BIOC rule that is currently available in Cortex XDR is Discovery. By using Discovery BIOC rules, you can create custom detection rules that match your specific use cases and scenarios.
References:
* Create a BIOC Rule
* BIOC Rule Event Types
* Threat Intelligence and Context
* Malware Prevention
NEW QUESTION # 37
Which of the following policy exceptions applies to the following description?
'An exception allowing specific PHP files'
- A. Behavioral threat protection rule exception
- B. Support exception
- C. Process exception
- D. Local file threat examination exception
Answer: D
NEW QUESTION # 38
What is by far the most common tactic used by ransomware to shut down a victim's operation?
- A. denying traffic out of the victims network until payment is received
- B. restricting access to administrative accounts to the victim
- C. encrypting certain files to prevent access by the victim
- D. preventing the victim from being able to access APIs to cripple infrastructure
Answer: C
NEW QUESTION # 39
Why would one threaten to encrypt a hypervisor or, potentially, a multiple number of virtual machines running on a server?
- A. To extort a payment from a victim or potentially embarrass the owners.
- B. To gain notoriety and potentially a consulting position.
- C. To better understand the underlying virtual infrastructure.
- D. To potentially perform a Distributed Denial of Attack.
Answer: A
Explanation:
Explanation
Encrypting a hypervisor or a multiple number of virtual machines running on a server is a form of ransomware attack, which is a type of cyberattack that involves locking or encrypting the victim's data or system and demanding a ransom for its release. The attacker may threaten to encrypt the hypervisor or the virtual machines to extort a payment from the victim or potentially embarrass the owners by exposing their sensitive or confidential information. Encrypting a hypervisor or a multiple number of virtual machines can have a severe impact on the victim's business operations, as it can affect the availability, integrity, and confidentiality of their data and applications. The attacker may also use the encryption as a leverage to negotiate a higher ransom or to coerce the victim into complying with their demands. References:
* Encrypt an Existing Virtual Machine or Virtual Disk: This document explains how to encrypt an existing virtual machine or virtual disk using the vSphere Client.
* How to Encrypt an Existing or New Virtual Machine: This article provides a guide on how to encrypt an existing or new virtual machine using AOMEI Backupper.
* Ransomware: This document provides an overview of ransomware, its types, impacts, and prevention methods.
NEW QUESTION # 40
After scan, how does file quarantine function work on an endpoint?
- A. Quarantine takes ownership of the files and folders and prevents execution through access control.
- B. Quarantine prevents an endpoint from communicating with anything besides the listed exceptions in the agent profile and Cortex XDR.
- C. Quarantine removes a specific file from its location on a local or removable drive to a protected folder and prevents it from being executed.
- D. Quarantine disables the network adapters and locks down access preventing any communications with the endpoint.
Answer: C
Explanation:
Explanation
Quarantine is a feature of Cortex XDR that allows you to isolate a malicious file from its original location and prevent it from being executed. Quarantine works by moving the file to a protected folder on the endpoint and changing its permissions and attributes. Quarantine can be applied to files detected by periodic scans or by behavioral threat protection (BTP) rules. Quarantine is only supported for portable executable (PE) and dynamic link library (DLL) files. Quarantine does not affect the network connectivity or the communication of the endpoint with Cortex XDR. References:
* Quarantine Malicious Files
* Manage Quarantined Files
NEW QUESTION # 41
What is the Wildfire analysis file size limit for Windows PE files?
- A. 500MB
- B. 100MB
- C. 1GB
- D. No Limit
Answer: B
Explanation:
Explanation
The Wildfire analysis file size limit for Windows PE files is 100MB. Windows PE files are executable files that run on the Windows operating system, such as .exe, .dll, .sys, or .scr files. Wildfire is a cloud-based service that analyzes files and URLs for malicious behavior and generates signatures and protections for them.
Wildfire can analyze various file types, such as PE, APK, PDF, MS Office, and others, but each file type has a different file size limit. The file size limit determines the maximum size of the file that can be uploaded or forwarded to Wildfire for analysis. If the file size exceeds the limit, Wildfire will not analyze the file and will return an error message.
According to the Wildfire documentation1, the file size limit for Windows PE files is 100MB. This means that any PE file that is larger than 100MB will not be analyzed by Wildfire. However, the firewall can still apply other security features, such as antivirus, anti-spyware, vulnerability protection, and file blocking, to the PE file based on the security policy settings. The firewall can also perform local analysis on the PE file using the Cortex XDR agent, which uses machine learning models to assess the file and assign it a verdict2.
References:
* WildFire File Size Limits: This document provides the file size limits for different file types that can be analyzed by Wildfire.
* Local Analysis: This document explains how the Cortex XDR agent performs local analysis on files that cannot be sent to Wildfire for analysis.
NEW QUESTION # 42
......
Pass Your Palo Alto Certifications and Accreditations PCDRA Exam on Apr 21, 2024 with 93 Questions: https://www.topexamcollection.com/PCDRA-vce-collection.html
Latest Palo Alto Networks PCDRA PDF and Dumps (2024) Free Exam Questions Answers: https://drive.google.com/open?id=1AdzWyVi8i1PotR_uwzq57OaZwuLXN4_G

