Palo Alto Networks : Cortex XDR 3.2: Investigation and Response (EDU-262)

4.6 out of 5 rating

Jump to dates


2 Days

12 CPD hours

This course is intended for

Cybersecurity analysts and engineers and security operations specialists, as well as administrators and product deployers.


Successful completion of this instructor-led course with hands-on lab activities should enable you to:
Describe the architecture and components of the Cortex XDR family
Use the Cortex XDR management console
Create Cortex XDR agent installation packages, endpoint groups, and policies
Deploy Cortex XDR agents on endpoints
Create and manage exploit and malware prevention profiles
Investigate alerts and prioritize them using starring and exclusion policies
Tune Security profiles using Cortex XDR exceptions
Perform and track response actions in the Action Center
Perform basic troubleshooting related to Cortex XDR agents
Deploy a Broker VM and activate the Local Agents Settings applet
Understand Cortex XDR deployment concepts and activation requirements
Work with the Customer Support Portal and Cortex XDR Gateway for authentication and authorization


This instructor-led training enables you to prevent attacks on your endpoints. After an overview of the Cortex XDR components, the training introduces the Cortex XDR management console and demonstrates how to install agents on your endpoints and how to create Security profiles and policies. The training enables you to perform and track response actions, tune profiles, and work with Cortex XDR alerts. The training concludes with discussions about basic troubleshooting of the agent, the on-premises Broker VM component, and Cortex XDR deployment.

Course Outline
  • This class is comprised of the following modules:
  • Module 1 - Cortex XDR Family Overview
  • Module 2 - Cortex XDR Main Components
  • Module 3 - Cortex XDR Mangement Components
  • Module 4 - Profiles and Policy Rules
  • Module 5 - Malware Protection
  • Module 6 - Exploit Protection
  • Module 7 - Cortex XDR Alerts
  • Module 8 - Tuning Policies using Exceptions
  • Module 9 - - Response Actions
  • Module 10 - Basic Agent Troubleshooting
  • Module 11 - Broker VM Overview
  • Module 12 - Deployment Consideration
Training Insurance Included!

When you organise training, we understand that there is a risk that some people may fall ill, become unavailable. To mitigate the risk we include training insurance for each delegate enrolled on our public schedule, they are welcome to sit on the same Public class within 6 months at no charge, if the case arises.

What people say about us

Find out more about this course

Interested in alternative dates? Would like to book a private session of this course for your company? Or for any other queries please simply fill out the form below.