[Nov-2021] PSE-Cortex Exam Dumps Pass with Updated 2021 Palo Alto Networks System Engineer - Cortex Professional
Free PSE-Cortex Exam Dumps to Pass Exam Easily
NEW QUESTION 14
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)
- A. Domain/workgroup membership
- B. attack threat intelligence tag
- C. OS
- D. quarantine status
- E. hostname
Answer: A,C,E
NEW QUESTION 15
Which two formats are supported by Whitelist? (Choose two)
- A. CSV
- B. STIX
- C. Regex
- D. CIDR
Answer: C,D
NEW QUESTION 16
Which deployment type supports installation of an engine on Windows, Mac OS. and Linux?
- A. DEB
- B. RPM
- C. SH
- D. ZIP
Answer: D
Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-0/cortex-xsoar-admin/engines/install-deploy-and-configure-demisto-engines/create-a-new-engine.html
NEW QUESTION 17
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;
What is the remaining configuration?
A)
B)
C)
D)
- A. Option B
- B. Option C
- C. Option A
- D. Option D
Answer: D
NEW QUESTION 18
Cortex XDR can schedule recurring scans of endpoints for malware. Identify two methods for initiating an on-demand malware scan (Choose two )
- A. the local console
- B. Telnet
- C. Response > Action Center
- D. Endpoint > Endpoint Management
Answer: C,D
NEW QUESTION 19
Which two filter operators are available in Cortex XDR? (Choose two.)
- A. < >
- B. !*
- C. =>
- D. not Contains
Answer: B,D
Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/use-c
NEW QUESTION 20
An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?
- A. SOC manager
- B. operations manager
- C. SOC analyst IT
- D. desktop engineer
Answer: A
NEW QUESTION 21
Which four types of Traps logs are stored within Cortex Data Lake?
- A. Threat, Config, Authentication, Analytic
- B. Threat, Monitor. System, Analytic
- C. Threat, Config, System, Analytic
- D. Threat, Config, System, Data
Answer: C
NEW QUESTION 22
Rearrange the steps into the correct order for modifying an incident layout.
Answer:
Explanation:
1 - Navigate to Settings > Advanced > Incident Types
2 - Select the incident type you want to customize the layout view for
3 - Edit the layout
4 - Select the Edit Layout option
5 - Navigate to Settings > Layout Builder
NEW QUESTION 23
An adversary is attempting to communicate with malware running on your network for the purpose of controlling malware activities or for ex filtrating data from your network. Which Cortex XDR Analytics alert is this activity most likely to trigger'?
- A. Malware
- B. DNS Tunneling
- C. Uncommon Local Scheduled Task Creation
- D. New Administrative Behavior
Answer: A
NEW QUESTION 24
What is the retention requirement for Cortex Data Lake sizing?
- A. logs per second
- B. number of days
- C. number of endpoints
- D. number of VM-Series NGFW
Answer: B
Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-corte
NEW QUESTION 25
How can you view all the relevant incidents for an indicator?
- A. Linked Incidents column in Indicator Screen
- B. Related Incidents column in Indicator Screen
- C. Related Indicators column in Incident Screen
- D. Linked Indicators column in Incident Screen
Answer: B
NEW QUESTION 26
What is the difference between an exception and an exclusion?
- A. An exception does not exist
- B. An exclusion does not exist
- C. An exception is based on rules and exclusions are on alerts
- D. An exclusion is based on rules and exceptions are based on alerts.
Answer: C
NEW QUESTION 27
Which step is required to prepare the VDI Golden Image?
- A. Run the VDI conversion tool
- B. Review any PE files that WildFire determined to be malicious
- C. Set the memory dumps to manual setting
- D. Ensure the latest content updates are installed
Answer: B
NEW QUESTION 28
The customer has indicated they need EDR data collection capabilities, which Cortex XDR license is required?
- A. Cortex XDR Pro per TB
- B. Cortex XDR Pro Per Endpoint
- C. Cortex XDR Endpoint
- D. Cortex XDR Prevent
Answer: B
Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/migrate-your-cortex-xdr-license
NEW QUESTION 29
An administrator has a critical group of systems running Windows XP SP3 that cannot be upgraded The administrator wants to evaluate the ability of Traps to protect these systems and the word processing applications running on them How should an administrator perform this evaluation?
- A. Prepare the latest version of Windows VM Gather information about the word processing applications, determine if some of them are vulnerable and prepare a working exploit for at least one of them Execute with an exploitation tool
- B. Run word processing exploits in a latest version of Windows VM in a controlled and isolated environment. Document indicators of compromise and compare to Traps protection capabilities
- C. Run a known 2015 flash exploit on a Windows XP SP3 VM. and run an exploitation tool that acts as a listener Use the results to demonstrate Traps capabilities
- D. Gather information about the word processing applications and run them on a Windows XP SP3 VM Determine if any of the applications are vulnerable and run the exploit with an exploitation tool
Answer: C
NEW QUESTION 30
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)
- A. quarantine status
- B. Domain/workgroup membership
- C. attack threat intelligence tag
- D. OS
- E. hostname
Answer: A,D,E
NEW QUESTION 31
What are two manual actions allowed on War Room entries? (Choose two.)
- A. Mark as scheduled entry
- B. Mark as note
- C. Mark as evidence
- D. Mark as artifact
Answer: B,C
NEW QUESTION 32
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types? (Choose three.)
- A. Define whether a playbook runs automatically when an incident type is encountered
- B. Define the way that incidents of a specific type are displayed in the system
- C. Add new fields to an incident type
- D. Set reminders for an incident SLA
- E. Drop new incidents of the same type that contain similar information
Answer: A,B,D
NEW QUESTION 33
Which two items are stitched to the Cortex XDR causality chain'' (Choose two)
- A. SIEM alert
- B. registry set value
- C. full URL
- D. firewall alert
Answer: C,D
NEW QUESTION 34
The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?
- A. enable SSL decryption
- B. reinstall the root CA certificate
- C. disable SSL decryption
- D. add paloaltonetworks com to the SSL Decryption Exclusion list
Answer: B
NEW QUESTION 35
How do sub-playbooks affect the Incident Context Data?
- A. When set to global, allows parallel task execution.
- B. When set to private, task outputs do not automatically get written to the root context
- C. When set to global, sub-playbook tasks do not have access to the root context
- D. When set to private, task outputs automatically get written to the root context
Answer: B
NEW QUESTION 36
......
PSE-Cortex Exam Dumps, PSE-Cortex Practice Test Questions: https://examcollection.prep4sureguide.com/PSE-Cortex-prep4sure-exam-guide.html