Exam: Palo Alto Networks: XDR Analyst (PAN-XDRA)
- Price: eur215.00
- Code: PAN-XDRA
Description
TopThe Palo Alto Networks Certified XDR Analyst certification validates the job-ready skills required to demonstrate understanding of the basic architecture, components, and operation of Cortex XDR.
This exam is designed for current or aspiring security operations center (SOC) analysts, security operations specialists, incident responders, threat researchers, or anyone who wants to validate their knowledge and skills in the areas of incident investigation and response, alert handling, threat hunting, vulnerability assessment, reporting, and compliance by using the Cortex XDR platform within a SOC.
Further Information
TopObjectives
TopCandidates should be able to demonstrate:
- Working knowledge of network security
- Working knowledge of TCP/IP and how traffic is directed within a network
- Working knowledge of networking infrastructure, protocols, and topology
- Working knowledge of troubleshooting methodologies
- Knowledge of OS fundamentals and security hardening methods
- Working knowledge of security automation technology
- Working knowledge of information security control technologies (e.g., access control, cryptography, vulnerability management, SIEM / log management)
- Working knowledge of security models / architectures (e.g., Defense in Depth, Zero Trust
- Tier 2+ level user competency in Cortex XDR
- Basic understanding of programming and scripting languages (i.e., Python, PowerShell, SQL, XQL
- Knowledge of current and emergent trends in information security
- Working knowledge of XDR-related components, console management, alerts, incidents, response actions, analysis, alert causality, queries, and asset management
- Working knowledge of common security operations processes and procedures (i.e., MITRE ATT&CK Framework, IR plans, investigative lifecycle
- Working knowledge of Cortex XDR in the SOC
- Ability to review dashboards and generate reports to support efforts such as compliance, incident summaries, security coverage status, and leadership briefings
- Proficiency in query language proficiency for searching and correlating events
- Identification of key components of incidents
- Ability to tune and manage alerts
- Ability to identify and hunt for indicators of compromise (IOCs)
- Basic understanding of policies and profiles
- Proficiency in the use of Cortex XDR for incident detection, analysis, and response actions
- Analytical ability to perform forensic investigations, threat intelligence analysis, and asset management
Content
TopAlerting and Detection Processes 23%
- 1.1 Identify and explain different types of alerts and alert sources
- 1.2 Explain the alert prioritization handling process
- 1.2.1 Incident scoring
- 1.2.2 Alert starring
- 1.2.3 Featured fields
- 1.2.4 Custom prioritization configuration
- 1.3 Explain the incident creation process
- 1.4 Explain the concepts of alert grouping and data stitching
Incident Handling and Response 34%
- 2.1 Review and investigate alert evidence
- 2.1.1 Forensics
- 2.1.2 Identity Threat Detection and Response (ITDR)
- 2.1.3 Causality chain
- 2.1.4 Timeline
- 2.2 Identify and analyze security events and incidents
- 2.3 Respond to incidents
- 2.3.1 Available response actions
- 2.3.2 Remediation suggestions
- 2.3.3 Automated responses
- 2.4 Identify and explain exclusions and exceptions
Data Analysis 28%
- 3.1 Use XQL to query datasets
- 3.2 Identify and explain components of XQL data structure
- 3.2.1 Syntax and schema
- 3.2.2 Data Sources
- 3.3 Identify and explain data query options
- 3.3.1 Pre-defined query builder template
- 3.3.2 Query Library
- 3.3.3 Schedule Query
- 3.4 Use lookup tables
- 3.5 Identify, hunt, and investigate leads and indicators of compromise (IOCs)
- 3.6 Demonstrate understanding of Cortex XDR dashboards and reports
- 3.7 Identify and explain the data retention options in Cortex XDR
- 3.8 Explain the use of Host Insights information
Endpoint Security Management 15%
- 4.1 Demonstrate understanding of endpoint prevention and extension profiles and policies
- 4.2 Identify and validate the impact of agent operational states
- 4.3 Identify and validate the impact of agent version and content update
Pre-requisites
TopIt is recommended that you have previously attended:
- Cortex XDR: Investigation and Analysis
Related Courses
Top