PSE-CORTEX Exam Questions
169 real PSE-CORTEX exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
Which option is required to prepare the VDI Golden Image?
- Question #2
An administrator has a critical group of systems running Windows XP SP3 that cannot be upgraded The administrator wants to evaluate the ability of Traps to protect these systems an...
- Question #3
If an anomalous process is discovered while investigating the cause of a security event, you can take immediate action to terminate the process or the whole process tree, and block...
- Question #4
Which four types of Traps logs are stored within Cortex Data Lake?
- Question #5
During the TMS instance activation, a tenant (Customer) provides the following information for the fields in the Activation-Step 2 of 2 window. During the service instance provisio...
- Question #6
Which Cortex XDR Agent capability prevents loading malicious files from USB-connected removable equipment?
- Question #7
An Administrator is alerted to a Suspicious Process Creation security event from multiple users. The users believe that these events are false positives Which two steps should the...
- Question #8
Which Cortex XDR capability extends investigations to an endpoint?
- Question #9
Which two types of lOCs are available for creation in Cortex XDR? (Choose two.)
- Question #10
A customer wants to modify the retention periods of their Threat logs in Cortex Data Lake. Where would the user configure the ratio of storage for each log type?
- Question #11
An adversary is attempting to communicate with malware running on your network for the purpose of controlling malware activities or for ex filtrating data from your network. Which...
- Question #12
What are process exceptions used for?
- Question #13
If a customer activates a TMS tenant and has not purchased a Cortex Data Lake instance. Palo Alto Networks will provide the customer with a free instance What size is this free Cor...
- Question #14
The customer has indicated they need EDR data collection capabilities, which Cortex XDR license is required?
- Question #15
An antivirus refresh project was initiated by the IT operations executive. Who is the best source for discussion about the project's operational considerations?
- Question #16
An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?
- Question #17
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three )
- Question #18
Which two methods does the Cortex XDR agent use to identify malware during a scheduled scan? (Choose two.)
- Question #19
Which two filter operators are available in Cortex XDR? (Choose two.)
- Question #20
Cortex XDR can schedule recurring scans of endpoints for malware. Identify two methods for initiating an on-demand malware scan? (Choose two )
- Question #22
Which two filter operators are available in Cortex XDR? (Choose two.)
- Question #23
An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit. What is the safest way to do it...
- Question #24
Which two entities can be created as a BIOC? (Choose two.)
- Question #25
What is the difference between an exception and an exclusion?
- Question #26
Which step is required to prepare the VDI Golden Image?
- Question #27
When a Demisto Engine is part of a Load-Balancing group it?
- Question #28
When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?
- Question #29
What are two manual actions allowed on War Room entries? (Choose two.)
- Question #31
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types? (Choose three.)
- Question #32
How many use cases should a POC success criteria document include?
- Question #33
In the DBotScore context field, which context key would differentiate between multiple entries for the same indicator in a multi-TIP environment?
- Question #34
How does an "inline" auto-extract task affect playbook execution?
- Question #35
Which two formats are supported by Whitelist? (Choose two)
- Question #36
The prospect is deciding whether to go with a phishing or a ServiceNow use case as part of their POC We have integrations for both but a playbook for phishing only Which use case s...
- Question #37
The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What actio...
- Question #38
A General Purpose Dynamic Section can be added to which two layouts for incident types? (Choose two)
- Question #39
If you have a playbook task that errors out. where could you see the output of the task?
- Question #40
The images show two versions of the same automation script and the results they produce when executed in Demisto. What are two possible causes of the exception thrown in the second...
- Question #41
How do sub-playbooks affect the Incident Context Data?
- Question #42
A prospect has agreed to do a 30-day POC and asked to integrate with a product that Demisto currently does not have an integration with. How should you respond?
- Question #43
Which option describes a Load-Balancing Engine Group?
- Question #44
Which task allows the playbook to follow different paths based on specific conditions?
- Question #45
Given the integration configuration and error in the screenshot what is the cause of the problem?
- Question #46
"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?
- Question #47
How can you view all the relevant incidents for an indicator?
- Question #48
Which deployment type supports installation of an engine on Windows, Mac OS, and Linux?
- Question #49
What does DBot use to score an indicator that has multiple reputation scores?
- Question #50
In an Air-Gapped environment where the Docker package was manually installed after the Cortex XSOAR installation which action allows Cortex XSOAR to access Docker?
- Question #51
Given the exception thrown in the accompanying image by the Demisto REST API integration, which action would most likely solve the problem? Which two playbook functionalities allow...
- Question #52
A Cortex XSOAR customer wants to ingest from a single mailbox. The mailbox brings in reported phishing emails and email requests from human resources (HR) to onboard new users. The...