Palo Alto Networks PCDRA Exam
Palo Alto Networks Certified Detection and Remediation Analyst
Updated on: 28-Jul-2025

PCDRA Exam Info

  • Certification Provider: Palo Alto Networks
  • Exam Name: Palo Alto Networks Certified Detection and Remediation Analyst
  • Exam Code: PCDRA
  • Total Questions: 96 Q&A



Share your comments for Palo Alto Networks PCDRA exam with other users:

cert 9/24/2023 4:53:00 PM

admin guide (windows) respond to malicious causality chains. when the cortex xdr agent identifies a remote network connection that attempts to perform malicious activity—such as encrypting endpoint files—the agent can automatically block the ip address to close all existing communication and block new connections from this ip address to the endpoint. when cortex xdrblocks an ip address per endpoint, that address remains blocked throughout all agent profiles and policies, including any host-firewall policy rules. you can view the list of all blocked ip addresses per endpoint from the action center, as well as unblock them to re-enable communication as appropriate. this module is supported with cortex xdr agent 7.3.0 and later. select the action mode to take when the cortex xdr agent detects remote malicious causality chains: enabled (default)—terminate connection and block ip address of the remote connection. disabled—do not block remote ip addresses. to allow specific and known s
Anonymous