PSE-Cortex by Palo Alto Networks Actual Free Exam Questions And Answers [UPDATED 2022]
PSE-Cortex Questions Truly Valid For Your Palo Alto Networks Exam!
NEW QUESTION 20
When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?
- A. SplunkSearch automation
- B. SplunkGO integration
- C. Cortex XSOAR TA App for Splunk
- D. splunk-get-alerts integration command
Answer: D
NEW QUESTION 21
The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?
- A. reinstall the root CA certificate
- B. add paloaltonetworks com to the SSL Decryption Exclusion list
- C. enable SSL decryption
- D. disable SSL decryption
Answer: A
NEW QUESTION 22
The customer has indicated they need EDR data collection capabilities, which Cortex XDR license is required?
- A. Cortex XDR Prevent
- B. Cortex XDR Pro per TB
- C. Cortex XDR Endpoint
- D. Cortex XDR Pro Per Endpoint
Answer: D
Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/migrate-your-cortex-xdr-license
NEW QUESTION 23
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?
- A. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
- B. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.
- C. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console
- D. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.
Answer: A
NEW QUESTION 24
Which option is required to prepare the VDI Golden Image?
- A. Use the Cortex XDR VDI tool to obtain verdicts for all PE files
- B. Configure the Golden Image as a persistent VDI
- C. Run the Cortex VDI conversion tool
- D. Install the Cortex XOR Agent on the local machine
Answer: A
NEW QUESTION 25
The customer has indicated they need EDR data collection capabilities, which Cortex XDR license is required?
- A. Cortex XDR Prevent
- B. Cortex XDR Pro per TB
- C. Cortex XDR Endpoint
- D. Cortex XDR Pro Per Endpoint
Answer: C
Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licen
NEW QUESTION 26
Which deployment type supports installation of an engine on Windows, Mac OS. and Linux?
- A. RPM
- B. ZIP
- C. SH
- D. DEB
Answer: B
Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-0/cortex-xsoar-admin/engines/install-deploy-and-configure-demisto-engines/create-a-new-engine.html
NEW QUESTION 27
How many use cases should a POC success criteria document include?
- A. only 1
- B. 3 or more
- C. no more than 5
- D. no more than 2
Answer: D
NEW QUESTION 28
Which two types of lOCs are available for creation in Cortex XDR? (Choose two.)
- A. endpoint hostname
- B. registry entry
- C. IP
- D. domain
Answer: C,D
NEW QUESTION 29
Which two items are stitched to the Cortex XDR causality chain'' (Choose two)
- A. firewall alert
- B. SIEM alert
- C. registry set value
- D. full URL
Answer: A,C
NEW QUESTION 30
In an Air-Gapped environment where the Docker package was manually installed after the Cortex XSOAR installation which action allows Cortex XSOAR to access Docker?
- A. disable the Cortex XSOAR service
- B. create a "docker" group and add the "Cortex XSOAR" or "demisto" user to this group
- C. create a "Cortex XSOAR' or "demisto" group and add the "docker" user to this group
- D. enable the docker service
Answer: C
NEW QUESTION 31
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types?
(Choose three.)
- A. Set reminders for an incident SLA
- B. Define the way that incidents of a specific type are displayed in the system
- C. Drop new incidents of the same type that contain similar information
- D. Add new fields to an incident type
- E. Define whether a playbook runs automatically when an incident type is encountered
Answer: B,C,E
NEW QUESTION 32
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?
- A. !invite Bob
- B. /invite Bob
- C. @Bob
- D. #Bob
Answer: C
NEW QUESTION 33
A prospect has agreed to do a 30-day POC and asked to integrate with a product that Demisto currently does not have an integration with. How should you respond?
- A. Agree to build the integration as part of the POC
- B. Tell them we can build it with Professional Services.
- C. Extend the POC window to allow the solution architects to build it
- D. Tell them custom integrations are not created as part of the POC
Answer: C
NEW QUESTION 34
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )
- A. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments
- B. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist
- C. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module
- D. Contact support and ask for a security exception.
Answer: A,B
NEW QUESTION 35
In the DBotScore context field, which context key would differentiate between multiple entries for the same indicator in a multi-TIP environment?
- A. Vendor
- B. Type
- C. Brand
- D. Using
Answer: A
NEW QUESTION 36
Which two entities can be created as a BIOC? (Choose two.)
- A. alert log
- B. file
- C. event log
- D. registry
Answer: B,D
Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xd
NEW QUESTION 37
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types? (Choose three.)
- A. Define the way that incidents of a specific type are displayed in the system
- B. Add new fields to an incident type
- C. Define whether a playbook runs automatically when an incident type is encountered
- D. Drop new incidents of the same type that contain similar information
- E. Set reminders for an incident SLA
Answer: A,C,E
NEW QUESTION 38
The images show two versions of the same automation script and the results they produce when executed in Demisto. What are two possible causes of the exception thrown in the second Image? (Choose two.) SUCCESS
- A. The modified script required a different parameter to run successfully.
- B. The modified scnpt was run in the wrong Docker image
- C. The modified script attempted to access a dictionary key that did not exist in the dictionary named
"data" - D. The dictionary was defined incorrectly in the second script.
Answer: B
NEW QUESTION 39
What are two manual actions allowed on War Room entries? (Choose two.)
- A. Mark as evidence
- B. Mark as note
- C. Mark as artifact
- D. Mark as scheduled entry
Answer: C
NEW QUESTION 40
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)
- A. OS
- B. Domain/workgroup membership
- C. quarantine status
- D. attack threat intelligence tag
- E. hostname
Answer: A,C,E
NEW QUESTION 41
An adversary is attempting to communicate with malware running on your network for the purpose of controlling malware activities or for ex filtrating data from your network. Which Cortex XDR Analytics alert is this activity most likely to trigger'?
- A. Uncommon Local Scheduled Task Creation
- B. New Administrative Behavior
- C. DNS Tunneling
- D. Malware
Answer: D
NEW QUESTION 42
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;
What is the remaining configuration?
A)
B)
C)
D)
- A. Option C
- B. Option A
- C. Option D
- D. Option B
Answer: C
NEW QUESTION 43
The certificate used for decryption was installed as a trusted toot CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?
- A. reinstall the root CA certificate
- B. add paloaltonetworks.com to the SSL Decryption Exclusion list
- C. enable SSL decryption
- D. disable SSL decryption
Answer: A
NEW QUESTION 44
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;
What is the remaining configuration?
A)
B)
C)
D)
- A. Option C
- B. Option A
- C. Option D
- D. Option B
Answer: C
NEW QUESTION 45
......
Get instant access of 100% real exam questions with verified answers: https://freedumps.torrentvalid.com/PSE-Cortex-valid-braindumps-torrent.html