A query is created that will run weekly via API. After it is tested and ready, it is reviewed in the Query Center. Which available column should be checked to determine how many compute units will be used when the query is run?
Correct Answer: B
In Cortex XDR, theQuery Centerallows administrators to manage and reviewXQL (XDR Query Language) queries, including those scheduled to run via API. Each query consumescompute units, a measure of the computational resources required to execute the query. To determine how many compute units a query will use, theCompute Unit Usagecolumn in the Query Center provides the actual or estimated resource consumption based on the query's execution history or configuration. * Correct Answer Analysis (B):TheCompute Unit Usagecolumn in the Query Center displays the number of compute units consumed by a query when it runs. For a tested and ready query, this column provides the most accurate information on resource usage, helping administrators plan for API-based executions. * Why not the other options? * A. Query Status: The Query Status column indicates whether the query ran successfully, failed, or is pending, but it does not provide information on compute unit consumption. * C. Simulated Compute Units: While some systems may offer simulated estimates, Cortex XDR' s Query Center does not have a "Simulated Compute Units" column. The actual usage is tracked in Compute Unit Usage. * D. Compute Unit Quota: The Compute Unit Quota refers to the total available compute units for the tenant, not the specific usage of an individual query. Exact Extract or Reference: TheCortex XDR Documentation Portalexplains Query Center functionality: "The Compute Unit Usage column in the Query Center shows the compute units consumed by a query, enabling administrators to assess resource usage for scheduled or API-based queries" (paraphrased from the Query Center section). TheEDU- 262: Cortex XDR Investigation and Responsecourse covers query management, stating that "Compute Unit Usage provides details on the resources used by each query in the Query Center" (paraphrased from course materials). ThePalo Alto Networks Certified XDR Engineer datasheetincludes "maintenance and troubleshooting" as a key exam topic, encompassing query resource management. References: Palo Alto Networks Cortex XDR Documentation Portal:https://docs-cortex.paloaltonetworks.com/ EDU-262: Cortex XDR Investigation and Response Course Objectives Palo Alto Networks Certified XDR Engineer Datasheet:https://www.paloaltonetworks.com/services/education /certification#xdr-engineer
Question 17
An analyst uploads custom file hashes associated with a newly discovered threat actor campaign. What occurs after the IOC is activated?
Correct Answer: B
IOC matching evaluates historical telemetry for previous compromises while continuously monitoring future events. This dual capability allows organizations to identify both existing infections and newly emerging threat activity.
Question 18
When configuring a new custom parsing rule in Cortex XDR, which section of the rule is mandatory?
Correct Answer: A
The INGEST section is mandatory in a custom parsing rule because it defines the vendor, product, target dataset, and ingestion behavior for the logs that the rule will parse.
Question 19
Some company employees are able to print documents when working from home, but not on network-attached printers, while others are able to print only to file. What can be inferred about the affected users' inability to print?
Correct Answer: D
The scenario describes two distinct groups with different printing behaviors: Group 1: can print from home but not to network-attached printers Group 2: can only print to file This pattern of differentiated printing restrictions across users is consistent with different device control/extensions profiles being applied, where each profile has different rules blocking specific types of print destinations (network printers vs. all physical printing).
Question 20
How are dynamic endpoint groups created and managed in Cortex XDR?
Correct Answer: D
In Cortex XDR, Dynamic Endpoint Groups allow you to automatically categorize endpoints based on real-time operational characteristics without manual management. When you configure a dynamic endpoint group, you establish filtering rules based on specific host attributes. These attributes include OS Type, OS Version, Hostname/String patterns, Domain, and IP address ranges/Network segments. Any endpoint matching these criteria automatically joins the group.