<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26468" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/paloalto-edu-262" lastchanged="2026-03-10T08:45:59+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Cortex XDR: Investigation and Response</title><productcode>EDU-262</productcode><vendorcode>PA</vendorcode><vendorname>PaloAlto</vendorname><fullproductcode>PA-EDU-262</fullproductcode><version>3.6</version><objective>&lt;p&gt;Successful completion of this instructor-led course with hands-on lab activities should enable the students to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Investigate and manage incidents&lt;/li&gt;&lt;li&gt;Describe the Cortex XDR causality and analytics concepts&lt;/li&gt;&lt;li&gt;Analyze alerts using the Causality and Timeline Views&lt;/li&gt;&lt;li&gt;Work with Cortex XDR Pro actions such as remote script execution&lt;/li&gt;&lt;li&gt;Create and manage on-demand and scheduled search queries in the Query Center&lt;/li&gt;&lt;li&gt;Create and manage the Cortex XDR rules BIOC and IOC&lt;/li&gt;&lt;li&gt;Working with Cortex XDR assets and inventories&lt;/li&gt;&lt;li&gt;Write XQL queries to search datasets and visualize the result sets&lt;/li&gt;&lt;li&gt;Work with Cortex XDR&amp;rsquo;s external-data collection&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;Participants must have completed the &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/paloalto-edu-260&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Cortex XDR: Prevention and Deployment &lt;span class=&quot;fl-prod-pcode&quot;&gt;(EDU-260)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt; course.&lt;/p&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;Cybersecurity analysts and engineers&lt;/li&gt;&lt;li&gt;Security operations specialists&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;ul&gt;
&lt;li&gt;1 - Cortex XDR Incidents&lt;/li&gt;&lt;li&gt;2 - Causality and Analytics Concepts&lt;/li&gt;&lt;li&gt;3 - Causality Analysis of Alerts&lt;/li&gt;&lt;li&gt;4 - Advanced Response Actions&lt;/li&gt;&lt;li&gt;5 - Building Search Queries&lt;/li&gt;&lt;li&gt;6 - Building XDR Rules&lt;/li&gt;&lt;li&gt;7 - Cortex XDR Assets&lt;/li&gt;&lt;li&gt;8 - Introduction to XQL&lt;/li&gt;&lt;li&gt;9 - External Data Collection&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>Successful completion of this instructor-led course with hands-on lab activities should enable the students to:



- Investigate and manage incidents
- Describe the Cortex XDR causality and analytics concepts
- Analyze alerts using the Causality and Timeline Views
- Work with Cortex XDR Pro actions such as remote script execution
- Create and manage on-demand and scheduled search queries in the Query Center
- Create and manage the Cortex XDR rules BIOC and IOC
- Working with Cortex XDR assets and inventories
- Write XQL queries to search datasets and visualize the result sets
- Work with Cortex XDR’s external-data collection</objective_plain><essentials_plain>Participants must have completed the Cortex XDR: Prevention and Deployment (EDU-260) course.</essentials_plain><audience_plain>- Cybersecurity analysts and engineers
- Security operations specialists</audience_plain><outline_plain>- 1 - Cortex XDR Incidents
- 2 - Causality and Analytics Concepts
- 3 - Causality Analysis of Alerts
- 4 - Advanced Response Actions
- 5 - Building Search Queries
- 6 - Building XDR Rules
- 7 - Cortex XDR Assets
- 8 - Introduction to XQL
- 9 - External Data Collection</outline_plain><duration unit="d" days="2">2 days</duration><pricelist><price country="SI" currency="EUR">1395.00</price><price country="GR" currency="EUR">1395.00</price><price country="MK" currency="EUR">1395.00</price><price country="HU" currency="EUR">1395.00</price><price country="DE" currency="EUR">1980.00</price><price country="AT" currency="EUR">1980.00</price><price country="AU" currency="USD">1995.00</price><price country="SG" currency="USD">1595.00</price><price country="IN" currency="USD">1195.00</price><price country="CH" currency="CHF">1980.00</price></pricelist><miles><milesvalue country="DE" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue><milesvalue country="AT" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue><milesvalue country="CH" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue><milesvalue country="SE" vendorcurrency="LTC" vendorcurrencyname="Palo Alto Networks Training Credits">20.00</milesvalue></miles></course>