[Dec 25, 2021] PSE-Cortex Exam Dumps 100% Same Q A In Your Real Exam PSE-Cortex Test Engine Dumps Training With 60 Questions NEW QUESTION 33 An antivirus refresh project was initiated by the IT operations executive. Who is the best source for discussion about the project's operational considerations'? A. endpoint manager B. SOC manager C. SOC analyst D. desktop engineer Answer: C NEW QUESTION 34 What [...]

[Dec 25, 2021] PSE-Cortex Exam Dumps 100% Same Q&A In Your Real Exam [Q33-Q57]

Share

[Dec 25, 2021] PSE-Cortex Exam Dumps 100% Same Q&A In Your Real Exam

PSE-Cortex Test Engine Dumps Training With 60 Questions

NEW QUESTION 33
An antivirus refresh project was initiated by the IT operations executive. Who is the best source for discussion about the project's operational considerations'?

  • A. endpoint manager
  • B. SOC manager
  • C. SOC analyst
  • D. desktop engineer

Answer: C

 

NEW QUESTION 34
What is the result of creating an exception from an exploit security event?

  • A. disables the triggered EPM for the host and process involve
  • B. White lists the process from Wild Fire analysis
  • C. exempts the user from generating events for 24 hours
  • D. exempts administrators from generating alerts for 24 hours

Answer: A

 

NEW QUESTION 35
Which two entities can be created as a BIOC? (Choose two.)

  • A. event log
  • B. alert log
  • C. registry
  • D. file

Answer: C,D

Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html

 

NEW QUESTION 36
How do sub-playbooks affect the Incident Context Data?

  • A. When set to global, allows parallel task execution.
  • B. When set to private, task outputs automatically get written to the root context
  • C. When set to global, sub-playbook tasks do not have access to the root context
  • D. When set to private, task outputs do not automatically get written to the root context

Answer: D

 

NEW QUESTION 37
The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?

  • A. enable SSL decryption
  • B. add paloaltonetworks com to the SSL Decryption Exclusion list
  • C. disable SSL decryption
  • D. reinstall the root CA certificate

Answer: D

 

NEW QUESTION 38
How does an "inline" auto-extract task affect playbook execution?

  • A. Wait until the indicators are enriched and populate context data before executing the next step.
  • B. Doesn't wait until the indicators are enriched but populate context data before executing the next
  • C. Doesn't wait until the indicators are enriched and continues executing the next step
  • D. step. Wait until the indicators are enriched but doesn't populate context data before executing the next step.

Answer: A

 

NEW QUESTION 39
When a Demisto Engine is part of a Load-Balancing group it?

  • A. Can be used separately as an engine, only if connected to the Demisto Server directly
  • B. It must have port 443 open to allow the Demisto Server to establish a connection
  • C. Must be in a Load-Balancing group with at least another 3 members
  • D. Cannot be used separately and does not appear in the in the engines drop-down menu when configuring an integration instance

Answer: C

 

NEW QUESTION 40
If an anomalous process is discovered while investigating the cause of a security event, you can take immediate action to terminate the process or the whole process tree, and block processes from running by initiating which Cortex XDR capability?

  • A. Live Terminal
  • B. Log Stitching
  • C. Live Sensors
  • D. File Explorer

Answer: A

 

NEW QUESTION 41
What method does the Traps agent use to identify malware during a scheduled scan?

  • A. Heuristic analysis
  • B. WildFire hash comparison and dynamic analysis
  • C. Local analysis
  • D. Signature comparison

Answer: B

 

NEW QUESTION 42
Which CLI query would bring back Notable Events from Splunk?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: A

 

NEW QUESTION 43
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

  • A. /invite Bob
  • B. @Bob
  • C. !invite Bob
  • D. #Bob

Answer: B

 

NEW QUESTION 44
What are two manual actions allowed on War Room entries? (Choose two.)

  • A. Mark as evidence
  • B. Mark as artifact
  • C. Mark as note
  • D. Mark as scheduled entry

Answer: B

 

NEW QUESTION 45
Which four types of Traps logs are stored within Cortex Data Lake?

  • A. Threat, Config, Authentication, Analytic
  • B. Threat, Config, System, Analytic
  • C. Threat, Config, System, Data
  • D. Threat, Monitor. System, Analytic

Answer: B

 

NEW QUESTION 46
Given the integration configuration and error in the screenshot what is the cause of the problem?

  • A. incorrect server URL
  • B. incorrect instance name
  • C. incorrect appliance port
  • D. incorrect Username and Password

Answer: B

 

NEW QUESTION 47
Cortex XDR can schedule recurring scans of endpoints for malware. Identify two methods for initiating an on-demand malware scan (Choose two )

  • A. the local console
  • B. Response > Action Center
  • C. Telnet
  • D. Endpoint > Endpoint Management

Answer: B,D

 

NEW QUESTION 48
Which two filter operators are available in Cortex XDR? (Choose two.)

  • A. =
  • B. Is Contained By
  • C. Contains
  • D. < >

Answer: A,C

 

NEW QUESTION 49
Which two log types should be configuredfor firewall forwarding to the Cortex Data Lake for use by Cortex XDR?(Choose two)

  • A. Analytics
  • B. Correlation
  • C. Security Event
  • D. HIP

Answer: A,C

 

NEW QUESTION 50
Which two items are stitched to the Cortex XDR causality chain'' (Choose two)

  • A. registry set value
  • B. SIEM alert
  • C. firewall alert
  • D. full URL

Answer: A,C

 

NEW QUESTION 51
What are two manual actions allowed on War Room entries? (Choose two.)

  • A. Mark as artifact
  • B. Mark as note
  • C. Mark as scheduled entry
  • D. Mark as evidence

Answer: B,D

 

NEW QUESTION 52
Which step is required to prepare the VDI Golden Image?

  • A. Ensure the latest content updates are installed
  • B. Set the memory dumps to manual setting
  • C. Review any PE files that WildFire determined to be malicious
  • D. Run the VDI conversion tool

Answer: C

 

NEW QUESTION 53
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

  • A. Contact support and ask for a security exception.
  • B. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments
  • C. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist
  • D. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module

Answer: A

 

NEW QUESTION 54
During the TMS instance activation, a tenant (Customer) provides the following information for the fields in the Activation - Step 2 of 2 window.

During the service instance provisioning which three DNS host names are created? (Choose three.)

  • A. hc-xnet50.traps.paloaltonetworks.com
  • B. cc.xnet50traps.paloaltonetworks.com
  • C. xnettraps.paloaltonetworks.com
  • D. cc-xnet50.traps.paloaltonetworks.com
  • E. ch-xnet.traps.paloaltonetworks.com
  • F. cc-xnet.traps.paloaltonetworks.com

Answer: D,E,F

 

NEW QUESTION 55
When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?

  • A. Cortex XSOAR TA App for Splunk
  • B. splunk-get-alerts integration command
  • C. SplunkSearch automation
  • D. SplunkGO integration

Answer: B

 

NEW QUESTION 56
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?

  • A. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.
  • B. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.
  • C. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
  • D. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console

Answer: B

 

NEW QUESTION 57
......

PSE-Cortex Practice Test Pdf Exam Material: https://www.guidetorrent.com/PSE-Cortex-pdf-free-download.html

PSE-Cortex Questions Pass on Your First Attempt Dumps for Palo Alto Networks Certification Certified: https://drive.google.com/open?id=17QGQGupqn9g0KYcmlLFg3GVbX6EjcGS_