[2022年最新] 最高のPSE-Cortex試験問題集を使って実際の試験問題と解答を解こう [Q28-Q51]

Share

[2022年最新] 最高のPSE-Cortex試験問題集を使って- 実際の試験問題と解答を解こう

テストエンジンを練習してPSE-Cortexテスト問題

質問 28
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)

  • A. quarantine status
  • B. attack threat intelligence tag
  • C. OS
  • D. hostname
  • E. Domain/workgroup membership

正解: C,D,E

 

質問 29
Which Cortex XDR Agent capability prevents loading malicious files from USB-connected removable equipment?

  • A. Device Customization
  • B. Agent Configuration
  • C. Agent Management
  • D. Device Control

正解: D

解説:
https://live.paloaltonetworks.com/t5/blogs/cortex-xdr-features-introduced-in-december-2019/ba-p/302231

 

質問 30
What is the retention requirement for Cortex Data Lake sizing?

  • A. number of VM-Series NGFW
  • B. number of days
  • C. logs per second
  • D. number of endpoints

正解: B

解説:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-corte

 

質問 31
How can you view all the relevant incidents for an indicator?

  • A. Linked Incidents column in Indicator Screen
  • B. Linked Indicators column in Incident Screen
  • C. Related Indicators column in Incident Screen
  • D. Related Incidents column in Indicator Screen

正解: B

 

質問 32
Which two items are stitched to the Cortex XDR causality chain'' (Choose two)

  • A. firewall alert
  • B. SIEM alert
  • C. registry set value
  • D. full URL

正解: A,C

 

質問 33
Which process in the causality chain does the Cortex XDR agent identify as triggering an event sequence?

  • A. the relevant shell
  • B. The causality group owner
  • C. the adversary's remote process
  • D. the chain's alert initiator

正解: B

 

質問 34
What is the result of creating an exception from an exploit security event?

  • A. disables the triggered EPM for the host and process involve
  • B. exempts the user from generating events for 24 hours
  • C. exempts administrators from generating alerts for 24 hours
  • D. White lists the process from Wild Fire analysis

正解: A

 

質問 35
The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?

  • A. enable SSL decryption
  • B. reinstall the root CA certificate
  • C. add paloaltonetworks com to the SSL Decryption Exclusion list
  • D. disable SSL decryption

正解: B

 

質問 36
Given the integration configuration and error in the screenshot what is the cause of the problem?

  • A. incorrect instance name
  • B. incorrect Username and Password
  • C. incorrect appliance port
  • D. incorrect server URL

正解: A

 

質問 37
Which task allows the playbook to follow different paths based on specific conditions?

  • A. Parallel
  • B. Automation
  • C. Conditional
  • D. Manual

正解: C

 

質問 38
An antivirus refresh project was initiated by the IT operations executive. Who is the best source for discussion about the project's operational considerations'?

  • A. endpoint manager
  • B. SOC manager
  • C. SOC analyst
  • D. desktop engineer

正解: C

 

質問 39
When a Demisto Engine is part of a Load-Balancing group it?

  • A. Must be in a Load-Balancing group with at least another 3 members
  • B. Can be used separately as an engine, only if connected to the Demisto Server directly
  • C. Cannot be used separately and does not appear in the in the engines drop-down menu when configuring an integration instance
  • D. It must have port 443 open to allow the Demisto Server to establish a connection

正解: C

 

質問 40
Which two formats are supported by Whitelist? (Choose two)

  • A. Regex
  • B. CIDR
  • C. STIX
  • D. CSV

正解: A,B

 

質問 41
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

  • A. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments
  • B. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module
  • C. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist
  • D. Contact support and ask for a security exception.

正解: D

 

質問 42
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?

  • A. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
  • B. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.
  • C. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console
  • D. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.

正解: A

 

質問 43
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types? (Choose three.)

  • A. Define the way that incidents of a specific type are displayed in the system
  • B. Add new fields to an incident type
  • C. Define whether a playbook runs automatically when an incident type is encountered
  • D. Drop new incidents of the same type that contain similar information
  • E. Set reminders for an incident SLA

正解: A,C,E

 

質問 44
Which two entities can be created as a BIOC? (Choose two.)

  • A. event log
  • B. file
  • C. registry
  • D. alert log

正解: B,C

解説:
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html

 

質問 45
How does DBot score an indicator that has multiple reputation scores?

  • A. uses the most severe score scores
  • B. the reputation as undefined
  • C. uses the least severe score
  • D. uses the average score

正解: A

 

質問 46
A prospect has agreed to do a 30-day POC and asked to integrate with a product that Demisto currently does not have an integration with. How should you respond?

  • A. Agree to build the integration as part of the POC
  • B. Tell them we can build it with Professional Services.
  • C. Tell them custom integrations are not created as part of the POC
  • D. Extend the POC window to allow the solution architects to build it

正解: C

 

質問 47
Which four types of Traps logs are stored within Cortex Data Lake?

  • A. Threat, Config, System, Data
  • B. Threat, Monitor. System, Analytic
  • C. Threat, Config, System, Analytic
  • D. Threat, Config, Authentication, Analytic

正解: C

 

質問 48
An administrator has a critical group of systems running Windows XP SP3 that cannot be upgraded The administrator wants to evaluate the ability of Traps to protect these systems and the word processing applications running on them How should an administrator perform this evaluation?

  • A. Gather information about the word processing applications and run them on a Windows XP SP3 VM Determine if any of the applications are vulnerable and run the exploit with an exploitation tool
  • B. Run word processing exploits in a latest version of Windows VM in a controlled and isolated environment. Document indicators of compromise and compare to Traps protection capabilities
  • C. Run a known 2015 flash exploit on a Windows XP SP3 VM. and run an exploitation tool that acts as a listener Use the results to demonstrate Traps capabilities
  • D. Prepare the latest version of Windows VM Gather information about the word processing applications, determine if some of them are vulnerable and prepare a working exploit for at least one of them Execute with an exploitation tool

正解: C

 

質問 49
Which CLI query would bring back Notable Events from Splunk?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

正解: A

 

質問 50
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)

  • A. attack threat intelligence tag
  • B. OS
  • C. Domain/workgroup membership
  • D. hostname
  • E. quarantine status

正解: B,D,E

 

質問 51
......

PSE-Cortex実際の問題アンサーPDFには100%カバー率リアルな試験問題:https://www.passtest.jp/Palo-Alto-Networks/PSE-Cortex-shiken.html

PSE-Cortexリアルな試験問題テストエンジン問題集トレーニング60問題:https://drive.google.com/open?id=17T97OHsZEseJVPcdfVfOin2QnIUCr0_I