Leads4pass > Palo Alto Networks > Palo Alto Networks Certifications > PSE-CORTEX > PSE-CORTEX Online Practice Questions and Answers

PSE-CORTEX Online Practice Questions and Answers

Questions 4

Which two entities can be created as a BIOC? (Choose two.)

A. file

B. registry

C. event log

D. alert log

Buy Now
Questions 5

Which Cortex XDR Agent capability prevents loading malicious files from USB-connected removable equipment?

A. Agent Configuration

B. Device Control

C. Device Customization

D. Agent Management

Buy Now
Questions 6

Which task allows the playbook to follow different paths based on specific conditions?

A. Conditional

B. Automation

C. Manual

D. Parallel

Buy Now
Questions 7

In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three )

A. alert root cause

B. hostname

C. domain/workgroup membership

D. OS

E. presence of Flash executable

Buy Now
Questions 8

An Administrator is alerted to a Suspicious Process Creation security event from multiple users.

The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

A. With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module

B. Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist

C. In the Cortex XDR security event, review the specific parent process, child process, and command line arguments

D. Contact support and ask for a security exception.

Buy Now
Questions 9

In the DBotScore context field, which context key would differentiate between multiple entries for the same indicator in a multi-TIP environment?

A. Vendor

B. Type

C. Using

D. Brand

Buy Now
Questions 10

What are two manual actions allowed on War Room entries? (Choose two.)

A. Mark as artifact

B. Mark as scheduled entry

C. Mark as note

D. Mark as evidence

Buy Now
Questions 11

Which CLI query would bring back Notable Events from Splunk?

A. ! splunk-search query=" `notable` | head 3"

B. ! splunk-search query=" 'notable' | head 3"

C. ! splunk-search query="*"

D. ! splunk-search query="* | head 3"

Buy Now
Questions 12

What is the retention requirement for Cortex Data Lake sizing?

A. number of endpoints

B. number of VM-Series NGFW

C. number of days

D. logs per second

Buy Now
Questions 13

Which Cortex XDR capability extends investigations to an endpoint?

A. Log Stitching

B. Causality Chain

C. Sensors

D. Live Terminal

Buy Now
Exam Code: PSE-CORTEX
Exam Name: Palo Alto Networks System Engineer Professional - Cortex
Last Update: Jan 05, 2025
Questions: 60
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99