Cortex XDR 2: Prevention, Analysis, and Response (EDU-260)
Online Technical Training | 23-25 November

Due to the Corona measures all trainings will be organised online.

Date: 23-25/11/2020
Duration: 3 days
Timing: every day from 9am to 5pm
Format: Interactive online instructor-led training
Price: €1990 excl. VAT

Course Description
This course is three days of instructor-led training that will help you to:

  • Differentiate the architecture and components of the Cortex XDR family
  • Describe Cortex, Cortex Data Lake, the Customer Support Portal, and the hub
  • Activate Cortex XDR, deploy the agents, and work with the management console
  • Work with the Cortex XDR management console, describe a typical management page, and work with the tables and filters
  • Create Cortex XDR agent installation packages, endpoint groups, policies, and profiles
  • Create and manage exploit and malware profiles, and perform response actions
  • Describe detection challenges with behavioral threats
  • Differentiate the Cortex XDR rules BIOC and IOC, and create and manage them
  • Describe the Cortex XDR causality analysis and analytics concepts
  • Triage and investigate alerts and incidents, and create alert starring and exclusion policies
  • Work with the Causality and Timeline Views and investigate threats in the Query Center


  • Module 1: Cortex XDR Family Overview
  • Module 2: Working with the Cortex Apps
  • Module 3: Getting Started with Endpoint Protection
  • Module 4: Malware Protection
  • Module 5: Exploit Protection
  • Module 6: Exceptions and Response Actions
  • Module 7: Behavioral Threat Analysis
  • Module 8: Cortex XDR Rules
  • Module 9: Incident Management
  • Module 10: Alert Analysis Views
  • Module 11: Search and Investigate
  • Module 12: Basic Troubleshooting


  • Course level: Advanced
  • Course duration: 3 days
  • Course format: Lecture and hands-on labs
  • Platform support: Palo Alto Networks
  • Cortex XDR Pro per endpoint and Pro per TB

Target Audience

Security Engineers, Security Administrators, Security Operations Specialists, Security Analysts, Network Engineers, and Support Staff


Participants must be familiar with enterprise security concepts.


This course is given by Steven Eerdekens a certified Palo Alto Networks trainer with several years of experience and awards.

Exclusive Networks BeLux, A. Stocletlaan 202, 2570 Duffel