exam questions

Exam PCDRA All Questions

View all questions & answers for the PCDRA exam

Exam PCDRA topic 1 question 42 discussion

Actual exam question from Palo Alto Networks's PCDRA
Question #: 42
Topic #: 1
[All PCDRA Questions]

Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack will be neutralized. Which of the following statements is correct?

  • A. Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.
  • B. Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.
  • C. Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.
  • D. Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sharkk43
Highly Voted 8 months, 3 weeks ago
If you go here: https://www.paloaltonetworks.com/services/education/palo-alto-networks-certified-detection-and-remediation-analyst And then go to Sample questions (specifically here: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcdra-sample-questions.pdf), there's 7 questions, one of them being: Which statement is valid regarding the Cortex XDR Analytics module? A. It interferes with an attack pattern as soon as it is observed on the endpoint. B. It does not interfere with any portion of the attack pattern on the endpoint. C. It does not need to interfere with any portion of the pattern to prevent the attack. D. It interferes with the attack pattern as soon as it is observed on the firewall. Palo Alto says the answer here is B. Therefore, for this question on ExamTopics I'd say the answer is B as well.
upvoted 8 times
deyabeel22
8 months, 3 weeks ago
In which module?
upvoted 1 times
...
...
Chiquitabandita
Most Recent 4 months ago
Selected Answer: B
looking at the links below I think it is B
upvoted 1 times
...
SpTester
6 months, 2 weeks ago
Selected Answer: B
Coverage of MITRE Attack Tactics: Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack is neutralized. The Cortex XDR Analytics Engine retrieves logs from the Cortex XDR tenant to create a baseline so that it can raise alerts when abnormal activity occurs. This analysis is highly sophisticated and performed on more than a thousand dimensions of data. Internally, Cortex XDR organizes its analytics activity into algorithms called detectors. Each detector is responsible for raising an alert when suspicious behavior is detected. https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts So I vote B. It enables the possibility but not to do anything on the Firewall itself or Endpoint itself. So it cannot act as soon as pattern is detected.
upvoted 2 times
...
SpTester
6 months, 2 weeks ago
Selected Answer: D
Coverage of MITRE Attack Tactics: Network attacks follow predictable patterns. If you interfere with any portion of this pattern, the attack is neutralized. The Cortex XDR Analytics Engine retrieves logs from the Cortex XDR tenant to create a baseline so that it can raise alerts when abnormal activity occurs. This analysis is highly sophisticated and performed on more than a thousand dimensions of data. Internally, Cortex XDR organizes its analytics activity into algorithms called detectors. Each detector is responsible for raising an alert when suspicious behavior is detected. https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts So I vote D. It enables the possibility but not to do anything on the Firewall itself.
upvoted 2 times
...
darylmaeb24
8 months, 1 week ago
BIOC Analytics is just a detection alert. Unless you have set a custom BIOC Prevention rules. My answer would be B.
upvoted 2 times
...
_tips
10 months, 1 week ago
The question is talking about Network Attacks, so I think, it is talking about Firewalls, https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts The Cortex XDR app uses its Analytics Engine to examine logs and data retrieved from your sensors on the Cortex XDR tenants to build an activity baseline, and recognize abnormal activity when it occurs. The Analytics Engine accesses your logs as they are streamed to the Cortex XDR tenant, including any Firewall data, and analyzes the data as soon as it arrives. Cortex XDR raises an Analytics alert when the Analytics Engine determines an anomaly. I guess the answer is A.
upvoted 2 times
...
Davina07
1 year, 1 month ago
Selected Answer: D
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago