xdr-engineer Sample Questions

xdr-engineer Sample Questions & Answers

Questions span three tied leaders: configuring endpoint prevention and extension profiles, onboarding data sources with automation rules, and detection rules with dashboards, plus deployment planning, access controls, and ongoing maintenance and troubleshooting.

Launch the full xdr-engineer simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Ingestion and Automation · Configure parsing rules

    A security engineer is designing a data ingestion pipeline using a Broker VM to collect logs from multiple on-premises sources. The sources include a custom application generating logs in a unique key-value format, a Cisco ASA firewall sending standard syslog, and a database server sending audit logs over TCP. The goal is to normalize all these logs into the Cortex XDR format before forwarding them to the Cortex Data Lake. Which sequence of components and actions within the Broker VM correctly represents the processing flow for the custom application logs?

    flowchart LR subgraph Broker_VM A[Collector Applet] --> B{Parsing Rule}; B --> C[Normalization]; C --> D[Forwarder]; end subgraph Custom_App E[Log Source] end subgraph CDL F[Cortex Data Lake] end E --> A; D --> F;

    Show answer & explanation

    Correct answer: A

    The correct flow for custom logs sent over TCP is to first receive them with a generic TCP Collector applet. Since the format is unique, a standard parser won't work. A custom Parsing Rule, typically using RegEx, must be applied to extract the fields. After parsing, the data is normalized to the XDR schema and then forwarded to the Cortex Data Lake. A Syslog Collector expects a specific syslog format, not a generic TCP stream. A Filebeat applet is used for collecting logs from files.

  2. Question 2Beginner

    Planning and Installation · Configure user roles, permissions, and access controls

    A Cortex XDR administrator is configuring user roles for a multi-tiered SOC. The requirements are to create a 'Tier 1 Analyst' role with view-only access to incidents and endpoint data, but no ability to perform response actions like isolating an endpoint. Which specific permission should be explicitly denied or not granted when creating this custom role?

    Show answer & explanation

    Correct answer: B

    The 'Endpoint Administration' permission grants the ability to perform response actions on endpoints, such as isolation, termination of processes, and file retrieval. To create a view-only role for a Tier 1 Analyst, this permission must be withheld. Permissions like 'View Incidents' and 'Run Queries' are necessary for their investigative duties.

  3. Question 3Intermediate

    Cortex XDR Agent Configuration · Configure endpoint extension profiles and policies

    An organization is using the Host Firewall module on Cortex XDR to enforce network policies on its endpoints. The security team needs to create a rule that blocks all inbound traffic to developer workstations from the corporate guest Wi-Fi network (172.16.32.0/20), but allows all other traffic. How should this rule be configured in the Host Firewall profile?

    Show answer & explanation

    Correct answer: A

    The requirement is to block inbound traffic from a specific subnet. Therefore, the rule must be configured with Action: Block, Direction: Inbound, and the Remote Address set to the guest Wi-Fi subnet 172.16.32.0/20. Since the default rule is typically 'Allow All', this specific block rule will take precedence for matching traffic, achieving the desired outcome.

  4. Question 4Intermediate

    Detection and Reporting · Create detection rules to align with requirements

    A SOC analyst is investigating an alert and needs to find all DNS queries made by a specific host (workstation-123.acme.corp) in the last 7 days that were not to the internal corporate DNS servers (10.1.1.10, 10.2.1.10). Which XQL query will retrieve this information most efficiently?

    Show answer & explanation

    Correct answer: D

    This query correctly filters the xdr_data dataset for DNS lookup events from the specified host. The key part is and not (action_device_ip_address = "10.1.1.10" or action_device_ip_address = "10.2.1.10"), which accurately excludes queries directed to the internal DNS servers. action_device_ip_address is the field that contains the IP address of the DNS server that received the query.

  5. Question 5Advanced

    Maintenance and Troubleshooting · Troubleshoot data management issues (e.g., data ingestion, parsing)

    An XDR engineer is troubleshooting a data ingestion issue where logs from a custom application are being received by the Broker VM but are not appearing in the XDR console. The engineer suspects a problem with the custom parsing rule. Which component or log file should be checked first to validate if the parsing rule is correctly extracting fields from the raw logs?

    Show answer & explanation

    Correct answer: A

    The Broker VM uses Fluentd for its logging pipeline. When a parsing rule is applied, the results, including successful field extractions and any errors, are logged in the fluentd.log file on the Broker VM's file system. This log is the most direct place to verify the behavior of a custom parsing rule and diagnose issues with field extraction or data normalization.

  6. Question 6Intermediate

    Ingestion and Automation · Onboard data sources (e.g., NGFW, network, cloud, identity)

    A company is migrating its infrastructure to a serverless architecture and needs to ensure that Cortex XDR can ingest logs from AWS Lambda functions. Which Cortex XDR component is specifically designed for this purpose?

    Show answer & explanation

    Correct answer: A

    The XDR Collector is the component designed to collect logs from cloud-native and SaaS sources where installing an agent is not possible. It can be configured to pull logs from services like AWS CloudWatch, which collects logs from AWS Lambda. The Broker VM is for on-premises collection, and the XDR agent cannot be installed directly into a serverless Lambda runtime environment.

  7. Question 7Intermediate

    Planning and Installation · Explain the deployment process, objectives, and resources (e.g., hardware, software, data sources, integrations)

    An organization is deploying Cortex XDR agents to a large number of endpoints using a golden image. To ensure agents register correctly and do not create duplicate entries, what step is crucial before the image is finalized?

    Show answer & explanation

    Correct answer: B

    When preparing a golden image for VDI or mass deployment, the Cortex XDR agent must be installed with the -vdi (or equivalent) flag. This action prevents the agent from registering with the console and generating a unique ID on the golden image itself. When a new endpoint is provisioned from this image, the agent will then perform its initial registration and receive a unique ID, preventing duplicate entries in the console.

  8. Question 8IntermediateSelect 2

    Cortex XDR Agent Configuration · Configure endpoint extension profiles and policies

    A security team wants to prevent users from connecting unauthorized USB storage devices to company laptops, while still allowing approved, company-issued encrypted USB drives. Which TWO components must be configured in Cortex XDR to enforce this policy? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    First, a general blocking rule is needed. A Device Control Profile must be configured to block the 'USB Storage' device class to act as the default deny policy for all such devices.

    After establishing the block rule, an exception is required. The Device Control Exceptions list allows administrators to specify unique identifiers (like serial numbers) of the company-issued USB drives that should be permitted, overriding the general block rule.

  9. Question 9Beginner

    Ingestion and Automation · Manage simple automation rules

    When configuring an automation rule in Cortex XDR, what is the primary purpose of the 'Execution Timeout' setting?

    Show answer & explanation

    Correct answer: B

    The 'Execution Timeout' is a safeguard mechanism. It sets the maximum amount of time that an automation rule is allowed to run after being triggered. This prevents a malfunctioning or long-running rule from consuming excessive system resources or getting stuck in a loop.

  10. Question 10Intermediate

    Detection and Reporting · Create custom dashboards and reporting templates

    An XDR engineer needs to create a custom dashboard for executive leadership that displays a high-level overview of the organization's security posture. The dashboard should include the number of critical incidents over the past 30 days, a breakdown of alerts by MITRE ATT&CK tactic, and a list of the top 10 most targeted endpoints. Which type of widget should be used to display the breakdown of alerts by MITRE ATT&CK tactic?

    Show answer & explanation

    Correct answer: C

    A Bar Chart Widget is the most suitable choice for visualizing categorical data like MITRE ATT&CK tactics. It can be configured to run an XQL query that groups alerts by tactic and displays the count for each tactic as a separate bar, providing an intuitive and easy-to-understand visual comparison for executives.

Ready for the real thing?

The full xdr-engineer simulator has every exam-style question, timed mode, and instant scoring.