[Nov-2021] Free PSE-Cortex Exam Dumps to Improve Exam Score [Q36-Q58]

Share

[Nov-2021] Free PSE-Cortex Exam Dumps to Improve Exam Score

2021 Realistic PSE-Cortex Dumps Exam Tips Test Pdf Exam Material

NEW QUESTION 36
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;

What is the remaining configuration?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: A

 

NEW QUESTION 37
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

  • A. /invite Bob
  • B. !invite Bob
  • C. #Bob
  • D. @Bob

Answer: C

 

NEW QUESTION 38
Which option is required to prepare the VDI Golden Image?

  • A. Use the Cortex XDR VDI tool to obtain verdicts for all PE files
  • B. Install the Cortex XOR Agent on the local machine
  • C. Configure the Golden Image as a persistent VDI
  • D. Run the Cortex VDI conversion tool

Answer: A

 

NEW QUESTION 39
How do sub-playbooks affect the Incident Context Data?

  • A. When set to global, allows parallel task execution.
  • B. When set to private, task outputs automatically get written to the root context
  • C. When set to global, sub-playbook tasks do not have access to the root context
  • D. When set to private, task outputs do not automatically get written to the root context

Answer: D

 

NEW QUESTION 40
Which two filter operators are available in Cortex XDR? (Choose two.)

  • A. not Contains
  • B. =>
  • C. !*
  • D. < >

Answer: A,C

Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/use-cortex-xdr/manage-tables.html

 

NEW QUESTION 41
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

  • A. /invite Bob
  • B. @Bob
  • C. !invite Bob
  • D. #Bob

Answer: B

 

NEW QUESTION 42
Which two types of lOCs are available for creation in Cortex XDR? (Choose two.)

  • A. domain
  • B. IP
  • C. endpoint hostname
  • D. registry entry

Answer: A,B

 

NEW QUESTION 43
Which option describes a Load-Balancing Engine Group?

  • A. A group of engines that use an algorithm to efficiently share the workload for automation scripts
  • B. A group of engines that ensure High Availability of Demisto backend databases.
  • C. A group of engines that use an algorithm to efficiently share the workload for integrations
  • D. A group of D2 agents that share processing power across multiple endpoints

Answer: A

 

NEW QUESTION 44
During the TMS instance activation, a tenant (Customer) provides the following information for the fields in the Activation - Step 2 of 2 window.

During the service instance provisioning which three DNS host names are created? (Choose three.)

  • A. hc-xnet50.traps.paloaltonetworks.com
  • B. cc.xnet50traps.paloaltonetworks.com
  • C. xnettraps.paloaltonetworks.com
  • D. cc-xnet50.traps.paloaltonetworks.com
  • E. ch-xnet.traps.paloaltonetworks.com
  • F. cc-xnet.traps.paloaltonetworks.com

Answer: D,E,F

 

NEW QUESTION 45
How does an "inline" auto-extract task affect playbook execution?

  • A. Wait until the indicators are enriched and populate context data before executing the next step.
  • B. Doesn't wait until the indicators are enriched but populate context data before executing the next
  • C. Doesn't wait until the indicators are enriched and continues executing the next step
  • D. step. Wait until the indicators are enriched but doesn't populate context data before executing the next step.

Answer: A

 

NEW QUESTION 46
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three )

  • A. domain/workgroup membership
  • B. OS
  • C. presence of Flash executable
  • D. hostname
  • E. alert root cause

Answer: A,C,E

 

NEW QUESTION 47
A customer wants to modify the retention periods of their Threat logs in Cortex Data Lake.
Where would the user configure the ratio of storage for each log type?

  • A. Within the TMS, create an agent settings profile and modify the Disk Quota value
  • B. Go to the Cortex Data Lake App in Cloud Services, then choose Configuration and modify the Threat Quota
  • C. It is not possible to configure Cortex Data Lake quota for specific log types.
  • D. Write a GPO for each endpoint agent to check in less often

Answer: B

 

NEW QUESTION 48
An administrator has a critical group of systems running Windows XP SP3 that cannot be upgraded The administrator wants to evaluate the ability of Traps to protect these systems and the word processing applications running on them How should an administrator perform this evaluation?

  • A. Run a known 2015 flash exploit on a Windows XP SP3 VM. and run an exploitation tool that acts as a listener Use the results to demonstrate Traps capabilities
  • B. Gather information about the word processing applications and run them on a Windows XP SP3 VM Determine if any of the applications are vulnerable and run the exploit with an exploitation tool
  • C. Prepare the latest version of Windows VM Gather information about the word processing applications, determine if some of them are vulnerable and prepare a working exploit for at least one of them Execute with an exploitation tool
  • D. Run word processing exploits in a latest version of Windows VM in a controlled and isolated environment. Document indicators of compromise and compare to Traps protection capabilities

Answer: A

 

NEW QUESTION 49
Rearrange the steps into the correct order for modifying an incident layout.

Answer:

Explanation:

1 - Navigate to Settings > Advanced > Incident Types
2 - Select the incident type you want to customize the layout view for
3 - Edit the layout
4 - Select the Edit Layout option
5 - Navigate to Settings > Layout Builder

 

NEW QUESTION 50
An adversary is attempting to communicate with malware running on your network for the purpose of controlling malware activities or for ex filtrating data from your network. Which Cortex XDR Analytics alert is this activity most likely to trigger'?

  • A. Malware
  • B. DNS Tunneling
  • C. New Administrative Behavior
  • D. Uncommon Local Scheduled Task Creation

Answer: A

 

NEW QUESTION 51
Which Cortex XDR Agent capability prevents loading malicious files from USB-connected removable equipment?

  • A. Device Customization
  • B. Device Control
  • C. Agent Management
  • D. Agent Configuration

Answer: B

Explanation:
Explanation
https://live.paloaltonetworks.com/t5/blogs/cortex-xdr-features-introduced-in-december-2019/ba-p/302231

 

NEW QUESTION 52
Cortex XDR can schedule recurring scans of endpoints for malware. Identify two methods for initiating an on-demand malware scan (Choose two )

  • A. Endpoint > Endpoint Management
  • B. the local console
  • C. Response > Action Center
  • D. Telnet

Answer: C,D

 

NEW QUESTION 53
Which two log types should be configured for firewall forwarding to the Cortex Data Lake for use by Cortex XDR? (Choose two)

  • A. HIP
  • B. Correlation
  • C. Security Event
  • D. Analytics

Answer: A,C

 

NEW QUESTION 54
Which two filter operators are available in Cortex XDR? (Choose two.)

  • A. not Contains
  • B. =>
  • C. !*
  • D. < >

Answer: A,C

Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/use-c

 

NEW QUESTION 55
A prospect has agreed to do a 30-day POC and asked to integrate with a product that Demisto currently does not have an integration with. How should you respond?

  • A. Tell them custom integrations are not created as part of the POC
  • B. Tell them we can build it with Professional Services.
  • C. Agree to build the integration as part of the POC
  • D. Extend the POC window to allow the solution architects to build it

Answer: D

 

NEW QUESTION 56
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?

  • A. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.
  • B. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.
  • C. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
  • D. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console

Answer: B

 

NEW QUESTION 57
If you have a playbook task that errors out. where could you see the output of the task?

  • A. War Room of the incident
  • B. /var/log/messages
  • C. Demisto Audit log
  • D. Playbook Editor

Answer: A

 

NEW QUESTION 58
......

Powerful PSE-Cortex PDF Dumps for PSE-Cortex Questions: https://www.exam4labs.com/PSE-Cortex-practice-torrent.html

Authentic PSE-Cortex Dumps - Free PDF Questions to Pass: https://drive.google.com/open?id=1fjFhsbvUU0rHzkZ4wzK0gJgrLW8mPJXb