PSE-CORTEX Exam Questions
169 real PSE-CORTEX exam questions with expert-verified answers and explanations. Page 2 of 4.
- Question #53
What allows the use of predetermined Palo Alto Networks roles to assign access rights to Cortex XDR users?
- Question #54
What integration allows searching and displaying Splunk results within Cortex XSOAR?
- Question #55
How can Cortex XSOAR save time when a phishing incident occurs?
- Question #56
Which two types of indicators of compromise (IOCs) are available for creation in Cortex XDR? (Choose two.)
- Question #58
What is the result of creating an exception from an exploit security event?
- Question #59
What is the retention requirement for Cortex Data Lake sizing?
- Question #60
The certificate used for decryption was installed as a trusted toot CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What acti...
- Question #61
Which two log types should be configured for firewall forwarding to the Cortex Data Lake for use by Cortex XDR? (Choose two)
- Question #62
Which two items are stitched to the Cortex XDR causality chain? (Choose two.)
- Question #63
Which process in the causality chain does the Cortex XDR agent identify as triggering an event sequence?
- Question #64
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)
- Question #65
When analyzing logs for indicators, which are used for only BIOC identification'?
- Question #66
What does the Cortex XSOAR "Saved by Dbot" widget calculate?
- Question #67
Which type of log is ingested natively in Cortex XDR Pro per TB?
- Question #68
An adversary attempts to communicate with malware running on a network in order to control malware activities or to exfiltrate data from the network. Which Cortex XDR Analytics ale...
- Question #69
Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command- and-control (C2) traffic. What is the best method to block this IP from communicating wit...
- Question #70
Which two types of indicators of compromise (IOCs) are available for creation in Cortex XDR? (Choose two.)
- Question #71
A Cortex XSOAR customer has a phishing use case in which a playbook has been implemented with one of the steps blocking a malicious URL found in an email reported by one of the use...
- Question #72
Which two actions are required to add indicators to the whitelist? (Choose two.)
- Question #73
Which playbook feature allows concurrent execution of tasks?
- Question #74
Which two Cortex XSOAR incident type features can be customized under Settings > Advanced > Incident Types? (Choose two.)
- Question #75
What are two reasons incident investigation is needed in Cortex XDR? (Choose two.)
- Question #76
Which two statements apply to widgets? (Choose two.)
- Question #77
Which source provides data for Cortex XDR?
- Question #78
Which two manual actions are allowed on War Room entries? (Choose two.)
- Question #79
Which statement applies to a Cortex XSOAR engine that is part of a load-balancing group?
- Question #80
Which attack method is a result of techniques designed to gain access through vulnerabilities in the code of an operating system (OS) or application?
- Question #81
What are two capabilities of a War Room? (Choose two.)
- Question #82
On a multi-tenanted v6.2 Cortex XSOAR server, which path leads to the server.log for "Tenant1"?
- Question #83
What is used to display only file entries in a War Room?
- Question #84
Which two areas of Cortex XDR are used for threat hunting activities? (Choose two.)
- Question #85
Where can all the relevant incidents for an indicator be viewed?
- Question #86
Which statement applies to the malware protection flow in Cortex XDR Prevent?
- Question #87
When initiated, which Cortex XDR capability allows immediate termination of the process or whole process tree on an anomalous process discovered during investigation of a security...
- Question #88
What is the size of the free Cortex Data Lake instance provided to a customer who has activated a TMS tenant, but has not purchased a Cortex Data Lake instance?
- Question #89
What is a benefit offered by Cortex XSOAR?
- Question #90
Which action allows Cortex XSOAR to access Docker in an air-gapped environment where the Docker page was manually installed after the Cortex XSOAR installation?
- Question #91
The Cortex XDR management service requires which other Palo Alto Networks product?
- Question #92
Which command-line interface (CLI) query would retrieve the last three Splunk events?
- Question #93
Which Linux OS command will manually load Docker images onto the Cortex XSOAR server in an air-gapped environment?
- Question #94
Which solution profiles network behavior metadata, not payloads and files, allowing effective operation regardless of encrypted or unencrypted communication protocols, like HTTPS?
- Question #95
A customer wants the main Cortex XSOAR server installed in one site and wants to integrate with three other technologies in a second site. What communications are required between...
- Question #96
Why is reputation scoring important in the Threat Intelligence Module of Cortex XSOAR?
- Question #97
Where is the output of the task visible when a playbook task errors out?
- Question #98
Which command is used to add Cortex XSOAR "User1" to an investigation from the War Room command-line interface (CLI)?
- Question #99
A Cortex XSOAR customer wants to send a survey to users asking them to input their manager's email for a training use case so the manager can receive status reports on the employee...
- Question #100
Which playbook functionality allows grouping of tasks to create functional building blocks?
- Question #101
Cortex XDR external data ingestion processes ingest data from which sources?
- Question #102
A customer agrees to do a 30-day proof of concept (POC) and wants to integrate with a product with which Cortex XSOAR is not currently integrated. What is the appropriate response...
- Question #103
Which two entities can be created as a behavioral indicator of compromise (BIOC)? (Choose two.)