[Dec-2021] Updated Palo Alto Networks Certification PSE-Cortex Exam Questions BUNDLE PACK [Q13-Q35]

Share

[Dec-2021] Updated Palo Alto Networks Certification PSE-Cortex Exam Questions BUNDLE PACK

Master The Palo Alto Networks Content PSE-Cortex EXAM DUMPS WITH GUARANTEED SUCCESS!

NEW QUESTION 13
How do sub-playbooks affect the Incident Context Data?

  • A. When set to global, allows parallel task execution.
  • B. When set to private, task outputs automatically get written to the root context
  • C. When set to global, sub-playbook tasks do not have access to the root context
  • D. When set to private, task outputs do not automatically get written to the root context

Answer: D

 

NEW QUESTION 14
How does an "inline" auto-extract task affect playbook execution?

  • A. Wait until the indicators are enriched and populate context data before executing the next step.
  • B. Doesn't wait until the indicators are enriched but populate context data before executing the next
  • C. Doesn't wait until the indicators are enriched and continues executing the next step
  • D. step. Wait until the indicators are enriched but doesn't populate context data before executing the next step.

Answer: A

 

NEW QUESTION 15
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types?
(Choose three.)

  • A. Drop new incidents of the same type that contain similar information
  • B. Add new fields to an incident type
  • C. Define the way that incidents of a specific type are displayed in the system
  • D. Set reminders for an incident SLA
  • E. Define whether a playbook runs automatically when an incident type is encountered

Answer: A,C,E

 

NEW QUESTION 16
Which CLI query would bring back Notable Events from Splunk?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: A

 

NEW QUESTION 17
What is the retention requirement for Cortex Data Lake sizing?

  • A. number of endpoints
  • B. logs per second
  • C. number of days
  • D. number of VM-Series NGFW

Answer: C

Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/set-log-storage-quota

 

NEW QUESTION 18
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?

  • A. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.
  • B. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
  • C. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.
  • D. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console

Answer: B

 

NEW QUESTION 19
Which two log types should be configured for firewall forwarding to the Cortex Data Lake for use by Cortex XDR? (Choose two)

  • A. HIP
  • B. Correlation
  • C. Security Event
  • D. Analytics

Answer: A,C

 

NEW QUESTION 20
How does DBot score an indicator that has multiple reputation scores?

  • A. uses the most severe score scores
  • B. the reputation as undefined
  • C. uses the average score
  • D. uses the least severe score

Answer: A

 

NEW QUESTION 21
If an anomalous process is discovered while investigating the cause of a security event, you can take immediate action to terminate the process or the whole process tree, and block processes from running by initiating which Cortex XDR capability?

  • A. Live Terminal
  • B. Log Stitching
  • C. Live Sensors
  • D. File Explorer

Answer: A

 

NEW QUESTION 22
Given the integration configuration and error in the screenshot what is the cause of the problem?

  • A. incorrect Username and Password
  • B. incorrect server URL
  • C. incorrect instance name
  • D. incorrect appliance port

Answer: A

 

NEW QUESTION 23
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

  • A. /invite Bob
  • B. @Bob
  • C. !invite Bob
  • D. #Bob

Answer: B

 

NEW QUESTION 24
Cortex XDR can schedule recurring scans of endpoints for malware. Identify two methods for initiating an on-demand malware scan (Choose two )

  • A. Endpoint > Endpoint Management
  • B. the local console
  • C. Response > Action Center
  • D. Telnet

Answer: C,D

 

NEW QUESTION 25
Which Cortex XDR capability extends investigations to an endpoint?

  • A. Live Terminal
  • B. Causality Chain
  • C. Log Stitching
  • D. Sensors

Answer: C

Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-concepts

 

NEW QUESTION 26
An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?

  • A. SOC manager
  • B. operations manager
  • C. SOC analyst IT
  • D. desktop engineer

Answer: A

 

NEW QUESTION 27
If a customer activates a TMS tenant and has not purchased a Cortex Data Lake instance.
Palo Alto Networks will provide the customer with a free instance
What size is this free Cortex Data Lake instance?

  • A. 100 GB
  • B. 10 TB
  • C. 10 GB
  • D. 1 TB

Answer: A

 

NEW QUESTION 28
Which option is required to prepare the VDI Golden Image?

  • A. Install the Cortex XOR Agent on the local machine
  • B. Use the Cortex XDR VDI tool to obtain verdicts for all PE files
  • C. Configure the Golden Image as a persistent VDI
  • D. Run the Cortex VDI conversion tool

Answer: D

 

NEW QUESTION 29
Cortex XDR can schedule recurring scans of endpoints for malware. Identify two methods for initiating an on-demand malware scan (Choose two )

  • A. the local console
  • B. Response > Action Center
  • C. Telnet
  • D. Endpoint > Endpoint Management

Answer: B,D

 

NEW QUESTION 30
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;

What is the remaining configuration?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: A

 

NEW QUESTION 31
When analyzing logs for indicators, which are used for only BIOC identification'?

  • A. error messages
  • B. techniques
  • C. artifacts
  • D. observed activity

Answer: D

 

NEW QUESTION 32
Which step is required to prepare the VDI Golden Image?

  • A. Review any PE files that WildFire determined to be malicious
  • B. Ensure the latest content updates are installed
  • C. Set the memory dumps to manual setting
  • D. Run the VDI conversion tool

Answer: C

 

NEW QUESTION 33
What are two manual actions allowed on War Room entries? (Choose two.)

  • A. Mark as evidence
  • B. Mark as artifact
  • C. Mark as note
  • D. Mark as scheduled entry

Answer: B

 

NEW QUESTION 34
Which process in the causality chain does the Cortex XDR agent identify as triggering an event sequence?

  • A. The causality group owner
  • B. the adversary's remote process
  • C. the chain's alert initiator
  • D. the relevant shell

Answer: A

 

NEW QUESTION 35
......

Pass Palo Alto Networks PSE-Cortex Exam – Experts Are Here To Help You: https://www.trainingdump.com/Palo-Alto-Networks/PSE-Cortex-practice-exam-dumps.html

Get Latest Palo Alto Networks Certification PSE-Cortex Practice Test For Quick Preparation: https://drive.google.com/open?id=1uTw-MH-gwL_N295p9KvQAxhI1gGUICGQ

0
0
0
0