Rate this post

Go to PSE-Cortex Questions – Try PSE-Cortex dumps pdf

Dumps Practice Exam Questions Study Guide for the PSE-Cortex Exam

Q27. A prospect has agreed to do a 30-day POC and asked to integrate with a product that Demisto currently does not have an integration with. How should you respond?

 
 
 
 

Q28. If you have a playbook task that errors out. where could you see the output of the task?

 
 
 
 

Q29. During the TMS instance activation, a tenant (Customer) provides the following information for the fields in the Activation – Step 2 of 2 window.

During the service instance provisioning which three DNS host names are created? (Choose three.)

 
 
 
 
 
 

Q30. What are two manual actions allowed on War Room entries? (Choose two.)

 
 
 
 

Q31. What are two manual actions allowed on War Room entries? (Choose two.)

 
 
 
 

Q32. Which two items are stitched to the Cortex XDR causality chain” (Choose two)

 
 
 
 

Q33. Which four types of Traps logs are stored within Cortex Data Lake?

 
 
 
 

Q34. Which two log types should be configured for firewall forwarding to the Cortex Data Lake for use by Cortex XDR? (Choose two)

 
 
 
 

Q35. What method does the Traps agent use to identify malware during a scheduled scan?

 
 
 
 

Q36. If a customer activates a TMS tenant and has not purchased a Cortex Data Lake instance.
Palo Alto Networks will provide the customer with a free instance
What size is this free Cortex Data Lake instance?

 
 
 
 

Q37. Given the integration configuration and error in the screenshot what is the cause of the problem?

 
 
 
 

Q38. Which two types of lOCs are available for creation in Cortex XDR? (Choose two.)

 
 
 
 

Q39. Which Cortex XDR capability extends investigations to an endpoint?

 
 
 
 

Q40. An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?

 
 
 
 

Q41. Which Cortex XDR capability extends investigations to an endpoint?

 
 
 
 

Q42. Which two entities can be created as a BIOC? (Choose two.)

 
 
 
 

Q43. Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types?
(Choose three.)

 
 
 
 
 

Q44. In an Air-Gapped environment where the Docker package was manually installed after the Cortex XSOAR installation which action allows Cortex XSOAR to access Docker?

 
 
 
 

Q45. When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?

 
 
 
 

Q46. A customer wants to modify the retention periods of their Threat logs in Cortex Data Lake.
Where would the user configure the ratio of storage for each log type?

 
 
 
 

Q47. What is the result of creating an exception from an exploit security event?

 
 
 
 

Q48. “Bob” is a Demisto user. Which command is used to add ‘Bob” to an investigation from the War Room CLI?

 
 
 
 

Q49. An adversary is attempting to communicate with malware running on your network for the purpose of controlling malware activities or for ex filtrating data from your network. Which Cortex XDR Analytics alert is this activity most likely to trigger’?

 
 
 
 

Q50. A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified (exploit/windows/browser/ms16_051_vbscript) The description and current configuration of the exploit are as follows;

What is the remaining configuration?
A)

B)

C)

D)

 
 
 
 

Q51. The customer has indicated they need EDR data collection capabilities, which Cortex XDR license is required?

 
 
 
 

Free Palo Alto Networks Certification PSE-Cortex Exam Question: https://www.testkingit.com/Palo-Alto-Networks/latest-PSE-Cortex-exam-dumps.html

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt