100% Free PSE-Cortex Exam Dumps Use Real Palo Alto Networks Certification Dumps With 60 Questions!
Pass Your PSE-Cortex Exam Easily With 100% Exam Passing Guarantee [2021]
NEW QUESTION 34
How many use cases should a POC success criteria document include?
- A. only 1
- B. 3 or more
- C. no more than 5
- D. no more than 2
Answer: A
NEW QUESTION 35
What are process exceptions used for?
- A. permit processes to load specific DLLs
- B. change the WildFire verdict for a given executable
- C. disable an EPM for a particular process
- D. whitelist programs from WildFire analysis
Answer: D
NEW QUESTION 36
When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?
- A. SplunkSearch automation
- B. Cortex XSOAR TA App for Splunk
- C. SplunkGO integration
- D. splunk-get-alerts integration command
Answer: B
NEW QUESTION 37
What method does the Traps agent use to identify malware during a scheduled scan?
- A. Heuristic analysis
- B. WildFire hash comparison and dynamic analysis
- C. Local analysis
- D. Signature comparison
Answer: B
NEW QUESTION 38
Which two log types should be configured for firewall forwarding to the Cortex Data Lake for use by Cortex XDR? (Choose two)
- A. HIP
- B. Correlation
- C. Security Event
- D. Analytics
Answer: A,C
NEW QUESTION 39
When a Demisto Engine is part of a Load-Balancing group it?
- A. Cannot be used separately and does not appear in the in the engines drop-down menu when configuring an integration instance
- B. Can be used separately as an engine, only if connected to the Demisto Server directly
- C. It must have port 443 open to allow the Demisto Server to establish a connection
- D. Must be in a Load-Balancing group with at least another 3 members
Answer: A
NEW QUESTION 40
In an Air-Gapped environment where the Docker package was manually installed after the Cortex XSOAR installation which action allows Cortex XSOAR to access Docker?
- A. disable the Cortex XSOAR service
- B. create a "Cortex XSOAR' or "demisto" group and add the "docker" user to this group
- C. create a "docker" group and add the "Cortex XSOAR" or "demisto" user to this group
- D. enable the docker service
Answer: B
NEW QUESTION 41
How does DBot score an indicator that has multiple reputation scores?
- A. uses the most severe score scores
- B. the reputation as undefined
- C. uses the average score
- D. uses the least severe score
Answer: A
NEW QUESTION 42
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )
- A. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist
- B. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments
- C. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module
- D. Contact support and ask for a security exception.
Answer: A,B
NEW QUESTION 43
How does an "inline" auto-extract task affect playbook execution?
- A. Wait until the indicators are enriched and populate context data before executing the next step.
- B. Doesn't wait until the indicators are enriched but populate context data before executing the next
- C. Doesn't wait until the indicators are enriched and continues executing the next step
- D. step. Wait until the indicators are enriched but doesn't populate context data before executing the next step.
Answer: A
NEW QUESTION 44
Given the exception thrown in the accompanying image by the Demisto REST API integration, which action would most likely solve the problem?
Which two playbook functionalities allow looping through a group of tasks during playbook execution? (Choose two.)
- A. Playbook Tasks
- B. Sub-Play books
- C. Generic Polling Automation Playbook
- D. Playbook Functions
Answer: B,C
NEW QUESTION 45
What is the result of creating an exception from an exploit security event?
- A. disables the triggered EPM for the host and process involve
- B. White lists the process from Wild Fire analysis
- C. exempts the user from generating events for 24 hours
- D. exempts administrators from generating alerts for 24 hours
Answer: A
NEW QUESTION 46
An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?
- A. SOC manager
- B. operations manager
- C. SOC analyst IT
- D. desktop engineer
Answer: A
NEW QUESTION 47
How can you view all the relevant incidents for an indicator?
- A. Related Incidents column in Indicator Screen
- B. Linked Indicators column in Incident Screen
- C. Linked Incidents column in Indicator Screen
- D. Related Indicators column in Incident Screen
Answer: B
NEW QUESTION 48
An antivirus refresh project was initiated by the IT operations executive. Who is the best source for discussion about the project's operational considerations'?
- A. endpoint manager
- B. SOC manager
- C. SOC analyst
- D. desktop engineer
Answer: C
NEW QUESTION 49
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;
What is the remaining configuration?
A)
B)
C)
D)
- A. Option D
- B. Option B
- C. Option A
- D. Option C
Answer: A
NEW QUESTION 50
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?
- A. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.
- B. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
- C. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.
- D. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console
Answer: B
NEW QUESTION 51
......
Study resources for the Valid PSE-Cortex Braindumps: https://www.test4sure.com/PSE-Cortex-pass4sure-vce.html
PSE-Cortex Dumps are Available for Instant Access: https://drive.google.com/open?id=16XE2PIkG2l0U4r8-CcJJyFdyO3LLZxSD