Exam Details

  • Exam Code
    :PCDRA
  • Exam Name
    :Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA)
  • Certification
    :Palo Alto Networks Certifications
  • Vendor
    :Palo Alto Networks
  • Total Questions
    :91 Q&As
  • Last Updated
    :May 03, 2025

Palo Alto Networks Palo Alto Networks Certifications PCDRA Questions & Answers

  • Question 1:

    When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?

    A. Click the three dots on the widget and then choose "Save" and this will link the query to the Widget Library.

    B. This isn't supported, you have to exit the dashboard and go into the Widget Library first to create it.

    C. Click on "Save to Action Center" in the dashboard and you will be prompted to give the query a name and description.

    D. Click on "Save to Widget Library" in the dashboard and you will be prompted to give the query a name and description.

  • Question 2:

    After scan, how does file quarantine function work on an endpoint?

    A. Quarantine takes ownership of the files and folders and prevents execution through access control.

    B. Quarantine disables the network adapters and locks down access preventing any communications with the endpoint.

    C. Quarantine removes a specific file from its location on a local or removable drive to a protected folder and prevents it from being executed.

    D. Quarantine prevents an endpoint from communicating with anything besides the listed exceptions in the agent profile and Cortex XDR.

  • Question 3:

    In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?

    A. Agent Proxy

    B. Agent Installer and Content Caching

    C. Syslog Collector

    D. CSV Collector

  • Question 4:

    What kind of malware uses encryption, data theft, denial of service, and possibly harassment to take advantage of a victim?

    A. Ransomware

    B. Worm

    C. Keylogger

    D. Rootkit

  • Question 5:

    In the Cortex XDR console, from which two pages are you able to manually perform the agent upgrade action? (Choose two.)

    A. Asset Management

    B. Agent Installations

    C. Action Center

    D. Endpoint Administration

  • Question 6:

    With a Cortex XDR Prevent license, which objects are considered to be sensors?

    A. Syslog servers

    B. Third-Party security devices

    C. Cortex XDR agents

    D. Palo Alto Networks Next-Generation Firewalls

  • Question 7:

    Which of the following is NOT a precanned script provided by Palo Alto Networks?

    A. delete_file

    B. quarantine_file

    C. process_kill_name

    D. list_directories

  • Question 8:

    In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?

    A. In the Restrictions Profile, add the file name and path to the Executable Files allow list.

    B. Create a new rule exception and use the singer as the characteristic.

    C. Add the signer to the allow list in the malware profile.

    D. Add the signer to the allow list under the action center page.

  • Question 9:

    When creating a scheduled report which is not an option?

    A. Run weekly on a certain day and time.

    B. Run quarterly on a certain day and time.

    C. Run monthly on a certain day and time.

    D. Run daily at a certain time (selectable hours and minutes).

  • Question 10:

    What license would be required for ingesting external logs from various vendors?

    A. Cortex XDR Pro per Endpoint

    B. Cortex XDR Vendor Agnostic Pro

    C. Cortex XDR Pro per TB

    D. Cortex XDR Cloud per Host

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Palo Alto Networks exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PCDRA exam preparations and Palo Alto Networks certification application, do not hesitate to visit our Vcedump.com to find your solutions here.