2024 Latest PSE-Cortex dumps - Instant Download PDF [Q28-Q52]

Share

2024 Latest PSE-Cortex dumps - Instant Download PDF

Updated Verified PSE-Cortex Downloadable Printable Exam Dumps


Palo Alto Networks PSE-Cortex certification exam is designed to test the knowledge and skills of system engineers who work with the Cortex platform. Palo Alto Networks System Engineer - Cortex Professional certification is intended for professionals who have already gained experience in deploying and managing Palo Alto Networks security solutions, and who are interested in expanding their expertise to include the Cortex platform.


Palo Alto Networks PSE-Cortex (Palo Alto Networks System Engineer - Cortex Professional) Exam is a certification test that validates an individual's knowledge and skills in the field of cybersecurity. It is designed for professionals who work with the Palo Alto Networks Cortex platform, which provides an integrated approach to threat intelligence, detection, and response. PSE-Cortex exam covers topics such as Cortex XDR, Cortex Data Lake, and Cortex Analytics, among others.

 

NEW QUESTION # 28
The certificate used for decryption was installed as a trusted toot CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?

  • A. enable SSL decryption
  • B. reinstall the root CA certificate
  • C. disable SSL decryption
  • D. add paloaltonetworks.com to the SSL Decryption Exclusion list

Answer: B


NEW QUESTION # 29
When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?

  • A. SplunkSearch automation
  • B. SplunkGO integration
  • C. splunk-get-alerts integration command
  • D. Cortex XSOAR TA App for Splunk

Answer: D


NEW QUESTION # 30
Which deployment type supports installation of an engine on Windows, Mac OS. and Linux?

  • A. ZIP
  • B. RPM
  • C. SH
  • D. DEB

Answer: A

Explanation:
https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-0/cortex-xsoar-admin/engines/install-deploy-and-configure-demisto-engines/create-a-new-engine.html


NEW QUESTION # 31
A General Purpose Dynamic Section can be added to which two layouts for incident types? (Choose two)

  • A. "Close" Incident Form
  • B. Incident Summary
  • C. "New"/Edit" Incident Form
  • D. Incident Quick View

Answer: B,D


NEW QUESTION # 32
If you have a playbook task that errors out. where could you see the output of the task?

  • A. Demisto Audit log
  • B. /var/log/messages
  • C. Playbook Editor
  • D. War Room of the incident

Answer: C


NEW QUESTION # 33
Which Cortex XDR capability extends investigations to an endpoint?

  • A. Sensors
  • B. Live Terminal
  • C. Log Stitching
  • D. Causality Chain

Answer: C

Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-conc


NEW QUESTION # 34
How do sub-playbooks affect the Incident Context Data?

  • A. When set to global, sub-playbook tasks do not have access to the root context
  • B. When set to private, task outputs automatically get written to the root context
  • C. When set to global, allows parallel task execution.
  • D. When set to private, task outputs do not automatically get written to the root context

Answer: A


NEW QUESTION # 35
How can you view all the relevant incidents for an indicator?

  • A. Linked Indicators column in Incident Screen
  • B. Related Incidents column in Indicator Screen
  • C. Related Indicators column in Incident Screen
  • D. Linked Incidents column in Indicator Screen

Answer: A


NEW QUESTION # 36
When analyzing logs for indicators, which are used for only BIOC identification'?

  • A. techniques
  • B. error messages
  • C. artifacts
  • D. observed activity

Answer: D


NEW QUESTION # 37
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.
What is the safest way to do it?

  • A. The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.
  • B. The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console
  • C. The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console
  • D. The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.

Answer: C


NEW QUESTION # 38
Which step is required to prepare the VDI Golden Image?

  • A. Review any PE files that WildFire determined to be malicious
  • B. Set the memory dumps to manual setting
  • C. Run the VDI conversion tool
  • D. Ensure the latest content updates are installed

Answer: B


NEW QUESTION # 39
Which four types of Traps logs are stored within Cortex Data Lake?

  • A. Threat, Monitor. System, Analytic
  • B. Threat, Config, System, Data
  • C. Threat, Config, System, Analytic
  • D. Threat, Config, Authentication, Analytic

Answer: C


NEW QUESTION # 40
Which two filter operators are available in Cortex XDR? (Choose two.)

  • A. < >
  • B. !*
  • C. =>
  • D. not Contains

Answer: B,D

Explanation:
Explanation
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/use-c


NEW QUESTION # 41
Which task allows the playbook to follow different paths based on specific conditions?

  • A. Parallel
  • B. Manual
  • C. Conditional
  • D. Automation

Answer: C


NEW QUESTION # 42
Given the exception thrown in the accompanying image by the Demisto REST API integration, which action would most likely solve the problem?

Which two playbook functionalities allow looping through a group of tasks during playbook execution?
(Choose two.)

  • A. Sub-Play books
  • B. Generic Polling Automation Playbook
  • C. Playbook Functions
  • D. Playbook Tasks

Answer: A,C


NEW QUESTION # 43
Given the exception thrown in the accompanying image by the Demisto REST API integration, which action would most likely solve the problem?

Which two playbook functionalities allow looping through a group of tasks during playbook execution? (Choose two.)

  • A. Sub-Play books
  • B. Playbook Functions
  • C. Playbook Tasks
  • D. Generic Polling Automation Playbook

Answer: A,D


NEW QUESTION # 44
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

  • A. Contact support and ask for a security exception.
  • B. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments
  • C. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module
  • D. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist

Answer: B,D


NEW QUESTION # 45
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types?
(Choose three.)

  • A. Add new fields to an incident type
  • B. Drop new incidents of the same type that contain similar information
  • C. Define the way that incidents of a specific type are displayed in the system
  • D. Define whether a playbook runs automatically when an incident type is encountered
  • E. Set reminders for an incident SLA

Answer: B,C,D


NEW QUESTION # 46
Which two filter operators are available in Cortex XDR? (Choose two.)

  • A. < >
  • B. Is Contained By
  • C. Contains
  • D. =

Answer: C,D


NEW QUESTION # 47
What are process exceptions used for?

  • A. whitelist programs from WildFire analysis
  • B. disable an EPM for a particular process
  • C. permit processes to load specific DLLs
  • D. change the WildFire verdict for a given executable

Answer: B


NEW QUESTION # 48
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

  • A. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module
  • B. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist
  • C. Contact support and ask for a security exception.
  • D. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments

Answer: C


NEW QUESTION # 49
If a customer activates a TMS tenant and has not purchased a Cortex Data Lake instance.
Palo Alto Networks will provide the customer with a free instance
What size is this free Cortex Data Lake instance?

  • A. 100 GB
  • B. 1 TB
  • C. 10 TB
  • D. 10 GB

Answer: B


NEW QUESTION # 50
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

  • A. #Bob
  • B. /invite Bob
  • C. !invite Bob
  • D. @Bob

Answer: D


NEW QUESTION # 51
What are two manual actions allowed on War Room entries? (Choose two.)

  • A. Mark as note
  • B. Mark as artifact
  • C. Mark as evidence
  • D. Mark as scheduled entry

Answer: A,C


NEW QUESTION # 52
......

The Ultimate Palo Alto Networks PSE-Cortex Dumps PDF Review: https://www.prep4pass.com/PSE-Cortex_exam-braindumps.html

Achieve The Utmost Performance In PSE-Cortex Exam Pass Guaranteed: https://drive.google.com/open?id=1edPylMctTzODrl7HRsN0d7o-PYXVpmrJ