Skip to main Content

Exam: Palo Alto Networks: XDR Analyst (PAN-XDRA)

  • Price: eur215.00
  • Code: PAN-XDRA

eur215.00

excl. VAT

Add to Cart Add to Cart

Description

Top

The Palo Alto Networks Certified XDR Analyst certification validates the job-ready skills required to demonstrate understanding of the basic architecture, components, and operation of Cortex XDR.

This exam is designed for current or aspiring security operations center (SOC) analysts, security operations specialists, incident responders, threat researchers, or anyone who wants to validate their knowledge and skills in the areas of incident investigation and response, alert handling, threat hunting, vulnerability assessment, reporting, and compliance by using the Cortex XDR platform within a SOC.

Further Information

Top
Palo Alto Networks certification exam items are developed and approved by exam development experts in conjunction with subject matter experts (SMEs) who represent a broad spectrum of roles relevant to each certification. Each item is referenced to a publicly available technical or scholarly source.

Objectives

Top

Candidates should be able to demonstrate:

  • Working knowledge of network security
  • Working knowledge of TCP/IP and how traffic is directed within a network
  • Working knowledge of networking infrastructure, protocols, and topology
  • Working knowledge of troubleshooting methodologies
  • Knowledge of OS fundamentals and security hardening methods
  • Working knowledge of security automation technology
  • Working knowledge of information security control technologies (e.g., access control, cryptography, vulnerability management, SIEM / log management)
  • Working knowledge of security models / architectures (e.g., Defense in Depth, Zero Trust
  • Tier 2+ level user competency in Cortex XDR
  • Basic understanding of programming and scripting languages (i.e., Python, PowerShell, SQL, XQL
  • Knowledge of current and emergent trends in information security
  • Working knowledge of XDR-related components, console management, alerts, incidents, response actions, analysis, alert causality, queries, and asset management
  • Working knowledge of common security operations processes and procedures (i.e., MITRE ATT&CK Framework, IR plans, investigative lifecycle
  • Working knowledge of Cortex XDR in the SOC
    • Ability to review dashboards and generate reports to support efforts such as compliance, incident summaries, security coverage status, and leadership briefings
    • Proficiency in query language proficiency for searching and correlating events
    • Identification of key components of incidents
    • Ability to tune and manage alerts
    • Ability to identify and hunt for indicators of compromise (IOCs)
    • Basic understanding of policies and profiles
    • Proficiency in the use of Cortex XDR for incident detection, analysis, and response actions
  • Analytical ability to perform forensic investigations, threat intelligence analysis, and asset management

Content

Top

Alerting and Detection Processes 23%

  • 1.1 Identify and explain different types of alerts and alert sources
  • 1.2 Explain the alert prioritization handling process
    • 1.2.1 Incident scoring
    • 1.2.2 Alert starring
    • 1.2.3 Featured fields
    • 1.2.4 Custom prioritization configuration
  • 1.3 Explain the incident creation process
  • 1.4 Explain the concepts of alert grouping and data stitching

Incident Handling and Response 34%

  • 2.1 Review and investigate alert evidence
    • 2.1.1 Forensics
    • 2.1.2 Identity Threat Detection and Response (ITDR)
    • 2.1.3 Causality chain
    • 2.1.4 Timeline
  • 2.2 Identify and analyze security events and incidents
  • 2.3 Respond to incidents
    • 2.3.1 Available response actions
    • 2.3.2 Remediation suggestions
    • 2.3.3 Automated responses
  • 2.4 Identify and explain exclusions and exceptions

Data Analysis 28%

  • 3.1 Use XQL to query datasets
  • 3.2 Identify and explain components of XQL data structure
    • 3.2.1 Syntax and schema
    • 3.2.2 Data Sources
  • 3.3 Identify and explain data query options
    • 3.3.1 Pre-defined query builder template
    • 3.3.2 Query Library
    • 3.3.3 Schedule Query
  • 3.4 Use lookup tables
  • 3.5 Identify, hunt, and investigate leads and indicators of compromise (IOCs)
  • 3.6 Demonstrate understanding of Cortex XDR dashboards and reports
  • 3.7 Identify and explain the data retention options in Cortex XDR
  • 3.8 Explain the use of Host Insights information

Endpoint Security Management 15%

  • 4.1 Demonstrate understanding of endpoint prevention and extension profiles and policies
  • 4.2 Identify and validate the impact of agent operational states
  • 4.3 Identify and validate the impact of agent version and content update

Pre-requisites

Top

It is recommended that you have previously attended:

  • Cortex XDR: Investigation and Analysis
Cookie Control toggle icon