> Formations > Palo Alto Networks - Cortex™ XDR 3.6: Investigation and Response (EDU-262)

Course : Palo Alto Networks - Cortex™ XDR 3.6: Investigation and Response (EDU-262)

Official course, preparation for Palo Alto Networks exams

Practical course - 2d - 14h00 - Ref. PA5
Price : 1790 € E.T.

Palo Alto Networks - Cortex™ XDR 3.6: Investigation and Response (EDU-262)

Official course, preparation for Palo Alto Networks exams


New course

With the training, you'll learn how to investigate attacks via Cortex XDR's incident pages. You'll see causal chains, alerts, logs, log stitching and the Causality and Chronology views. You'll use advanced response actions (remediation, EDL, remote scripting), create simple search queries, XDR rules and explore specialized views (IP, Hash). An introduction to the XQL language and integrations via the Cortex XDR API is also included.


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class
Available in English on request

Ref. PA5
  2d - 14h00
1790 € E.T.
En option :
Dynamique.Model.Bean_FormationOption
Certification : 260 € HT




With the training, you'll learn how to investigate attacks via Cortex XDR's incident pages. You'll see causal chains, alerts, logs, log stitching and the Causality and Chronology views. You'll use advanced response actions (remediation, EDL, remote scripting), create simple search queries, XDR rules and explore specialized views (IP, Hash). An introduction to the XQL language and integrations via the Cortex XDR API is also included.


Teaching objectives
At the end of the training, the participant will be able to:
Investigating and managing incidents
Describe Cortex XDR's concepts of causality and analysis
Analyze alerts with Causality and Chronology views
Use Cortex XDR Pro actions such as remote script execution
Create and manage on-demand or scheduled search queries in the Query Center
Create and manage Cortex XDR BIOC and IOC rules
Working with Cortex XDR assets and inventories
Write XQL queries to interrogate data sets and visualize results
Using Cortex XDR external data collection

Intended audience
Cybersecurity analysts and engineers, security operations specialists.

Prerequisites
Completion of EDU-260 (Cortex XDR: Prevention and Deployment).

Practical details
Teaching methods
Training in French. Official course material in digital format and in English. Good understanding of written English.

Course schedule

1
Module 1: Cortex XDR incidents


2
Module 2: Concepts of causality and analytics


3
Module 3: Causal analysis of alerts


4
Module 4: Advanced response actions


5
Module 5: Creating search queries


6
Module 6: Creating XDR rules


7
Module 7: Cortex XDR assets


8
Module 8 : Introduction à XQL


9
Module 9: External data collection



Options
Certification : 260 € HT
Cette formation est recommandée dans le cadre du parcours de préparation aux certifications suivantes : Security Operations Professional, XDR Engineer.
Comment passer votre examen ?
The certification option comes in the form of a voucher or invitation that will allow you to take the exam at the end of the training course.

Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 24 Mar., 16 June, 29 Sep., 8 Dec.

PARIS LA DÉFENSE
2026 : 24 Mar., 26 Mar., 8 Dec.