xdr-engineer Sample Questions & Answers
Questions span three tied leaders: configuring endpoint prevention and extension profiles, onboarding data sources with automation rules, and detection rules with dashboards, plus deployment planning, access controls, and ongoing maintenance and troubleshooting.
Launch the full xdr-engineer simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Ingestion and Automation · Configure parsing rules
A security engineer is designing a data ingestion pipeline using a Broker VM to collect logs from multiple on-premises sources. The sources include a custom application generating logs in a unique key-value format, a Cisco ASA firewall sending standard syslog, and a database server sending audit logs over TCP. The goal is to normalize all these logs into the Cortex XDR format before forwarding them to the Cortex Data Lake. Which sequence of components and actions within the Broker VM correctly represents the processing flow for the custom application logs?
flowchart LR subgraph Broker_VM A[Collector Applet] --> B{Parsing Rule}; B --> C[Normalization]; C --> D[Forwarder]; end subgraph Custom_App E[Log Source] end subgraph CDL F[Cortex Data Lake] end E --> A; D --> F;Show answer & explanation
Correct answer: A
The correct flow for custom logs sent over TCP is to first receive them with a generic TCP Collector applet. Since the format is unique, a standard parser won't work. A custom Parsing Rule, typically using RegEx, must be applied to extract the fields. After parsing, the data is normalized to the XDR schema and then forwarded to the Cortex Data Lake. A Syslog Collector expects a specific syslog format, not a generic TCP stream. A Filebeat applet is used for collecting logs from files.
- Question 2Beginner
Planning and Installation · Configure user roles, permissions, and access controls
A Cortex XDR administrator is configuring user roles for a multi-tiered SOC. The requirements are to create a 'Tier 1 Analyst' role with view-only access to incidents and endpoint data, but no ability to perform response actions like isolating an endpoint. Which specific permission should be explicitly denied or not granted when creating this custom role?
Show answer & explanation
Correct answer: B
The 'Endpoint Administration' permission grants the ability to perform response actions on endpoints, such as isolation, termination of processes, and file retrieval. To create a view-only role for a Tier 1 Analyst, this permission must be withheld. Permissions like 'View Incidents' and 'Run Queries' are necessary for their investigative duties.
- Question 3Intermediate
Cortex XDR Agent Configuration · Configure endpoint extension profiles and policies
An organization is using the Host Firewall module on Cortex XDR to enforce network policies on its endpoints. The security team needs to create a rule that blocks all inbound traffic to developer workstations from the corporate guest Wi-Fi network (
172.16.32.0/20), but allows all other traffic. How should this rule be configured in the Host Firewall profile?Show answer & explanation
Correct answer: A
The requirement is to block inbound traffic from a specific subnet. Therefore, the rule must be configured with Action: Block, Direction: Inbound, and the Remote Address set to the guest Wi-Fi subnet
172.16.32.0/20. Since the default rule is typically 'Allow All', this specific block rule will take precedence for matching traffic, achieving the desired outcome. - Question 4Intermediate
Detection and Reporting · Create detection rules to align with requirements
A SOC analyst is investigating an alert and needs to find all DNS queries made by a specific host (
workstation-123.acme.corp) in the last 7 days that were not to the internal corporate DNS servers (10.1.1.10,10.2.1.10). Which XQL query will retrieve this information most efficiently?Show answer & explanation
Correct answer: D
This query correctly filters the
xdr_datadataset for DNS lookup events from the specified host. The key part isand not (action_device_ip_address = "10.1.1.10" or action_device_ip_address = "10.2.1.10"), which accurately excludes queries directed to the internal DNS servers.action_device_ip_addressis the field that contains the IP address of the DNS server that received the query. - Question 5Advanced
Maintenance and Troubleshooting · Troubleshoot data management issues (e.g., data ingestion, parsing)
An XDR engineer is troubleshooting a data ingestion issue where logs from a custom application are being received by the Broker VM but are not appearing in the XDR console. The engineer suspects a problem with the custom parsing rule. Which component or log file should be checked first to validate if the parsing rule is correctly extracting fields from the raw logs?
Show answer & explanation
Correct answer: A
The Broker VM uses Fluentd for its logging pipeline. When a parsing rule is applied, the results, including successful field extractions and any errors, are logged in the
fluentd.logfile on the Broker VM's file system. This log is the most direct place to verify the behavior of a custom parsing rule and diagnose issues with field extraction or data normalization. - Question 6Intermediate
Ingestion and Automation · Onboard data sources (e.g., NGFW, network, cloud, identity)
A company is migrating its infrastructure to a serverless architecture and needs to ensure that Cortex XDR can ingest logs from AWS Lambda functions. Which Cortex XDR component is specifically designed for this purpose?
Show answer & explanation
Correct answer: A
The XDR Collector is the component designed to collect logs from cloud-native and SaaS sources where installing an agent is not possible. It can be configured to pull logs from services like AWS CloudWatch, which collects logs from AWS Lambda. The Broker VM is for on-premises collection, and the XDR agent cannot be installed directly into a serverless Lambda runtime environment.
- Question 7Intermediate
Planning and Installation · Explain the deployment process, objectives, and resources (e.g., hardware, software, data sources, integrations)
An organization is deploying Cortex XDR agents to a large number of endpoints using a golden image. To ensure agents register correctly and do not create duplicate entries, what step is crucial before the image is finalized?
Show answer & explanation
Correct answer: B
When preparing a golden image for VDI or mass deployment, the Cortex XDR agent must be installed with the
-vdi(or equivalent) flag. This action prevents the agent from registering with the console and generating a unique ID on the golden image itself. When a new endpoint is provisioned from this image, the agent will then perform its initial registration and receive a unique ID, preventing duplicate entries in the console. - Question 8IntermediateSelect 2
Cortex XDR Agent Configuration · Configure endpoint extension profiles and policies
A security team wants to prevent users from connecting unauthorized USB storage devices to company laptops, while still allowing approved, company-issued encrypted USB drives. Which TWO components must be configured in Cortex XDR to enforce this policy? (Select TWO)
Show answer & explanation
Correct answers: A, B
First, a general blocking rule is needed. A Device Control Profile must be configured to block the 'USB Storage' device class to act as the default deny policy for all such devices.
After establishing the block rule, an exception is required. The Device Control Exceptions list allows administrators to specify unique identifiers (like serial numbers) of the company-issued USB drives that should be permitted, overriding the general block rule.
- Question 9Beginner
Ingestion and Automation · Manage simple automation rules
When configuring an automation rule in Cortex XDR, what is the primary purpose of the 'Execution Timeout' setting?
Show answer & explanation
Correct answer: B
The 'Execution Timeout' is a safeguard mechanism. It sets the maximum amount of time that an automation rule is allowed to run after being triggered. This prevents a malfunctioning or long-running rule from consuming excessive system resources or getting stuck in a loop.
- Question 10Intermediate
Detection and Reporting · Create custom dashboards and reporting templates
An XDR engineer needs to create a custom dashboard for executive leadership that displays a high-level overview of the organization's security posture. The dashboard should include the number of critical incidents over the past 30 days, a breakdown of alerts by MITRE ATT&CK tactic, and a list of the top 10 most targeted endpoints. Which type of widget should be used to display the breakdown of alerts by MITRE ATT&CK tactic?
Show answer & explanation
Correct answer: C
A Bar Chart Widget is the most suitable choice for visualizing categorical data like MITRE ATT&CK tactics. It can be configured to run an XQL query that groups alerts by tactic and displays the count for each tactic as a separate bar, providing an intuitive and easy-to-understand visual comparison for executives.
Ready for the real thing?
The full xdr-engineer simulator has every exam-style question, timed mode, and instant scoring.