PSE-Cortex Palo Alto Networks System Engineer - Cortex Professional Questions and Answers
In addition to migration and go-live, what are two best-practice steps for migrating from SIEM to Cortex XSIAM? (Choose two.)
A Cortex XSOAR customer wants to ingest emails from a single mailbox. The mailbox brings in reported phishing emails and email requests from human resources (HR) to onboard new users. The customer wants to run two separate workflows from this mailbox, one for phishing and one for onboarding.
What will allow Cortex XSOAR to accomplish this in the most efficient way?
In the DBotScore context field, which context key would differentiate between multiple entries for the same indicator in a multi-TIP environment?
What is the primary mechanism for the attribution of attack surface data in Cortex Xpanse?
The prospect is deciding whether to go with a phishing or a ServiceNow use case as part of their POC We have integrations for both but a playbook for phishing only Which use case should be used for the POC?
An adversary is attempting to communicate with malware running on your network for the purpose of controlling malware activities or for ex filtrating data from your network. Which Cortex XDR Analytics alert is this activity most likely to trigger ' ?
Which deployment type supports installation of an engine on Windows, Mac OS. and Linux?
When preparing the golden image in a Cortex XDR Virtual Desktop Infrastructure (VDI) deployment, which step is required?
Which two troubleshooting steps should be taken when an integration is failing to connect? (Choose two.)
The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?
A customer has 2700 endpoints. There is currently concern about recent attacks in their industry and threat intelligence from a third-party subscription. In an attempt to be proactive, phishing simulations have been prioritized, but the customer wants to gain more visibility and remediation capabilities specific to their network traffic.
Which Cortex product provides these capabilities?
Which product enables the discovery, exchange, and contribution of security automation playbooks, built into Cortex XSOAR?
A customer has purchased Cortex XSOAR and has a need to rapidly stand up the product in their environment. The customer has stated that their internal staff are currently occupied with other projects.
Which Palo Alto Networks service offering should be recommended to the customer?
What are two reasons incident investigation is needed in Cortex XDR? (Choose two.)
When preparing for a Cortex XSOAR proof of value (POV), which task should be performed before the evaluation is requested?
Which task allows the playbook to follow different paths based on specific conditions?
Why is Premium Customer Success an important part of any Cortex bill of materials?
" Bob " is a Demisto user. Which command is used to add ' Bob " to an investigation from the War Room CLI?
Which Cortex XDR license is required for a customer that requests endpoint detection and response (EDR) data collection capabilities?
Which technology allows a customer to integrate Cortex Xpanse with third-party applications or services, assets, and IP ranges while leveraging investigation capabilities?
What allows the use of predetermined Palo Alto Networks roles to assign access rights to Cortex XDR users?
A customer wants the main Cortex XSOAR server installed in one site and wants to integrate with three other technologies in a second site.
What communications are required between the two sites if the customer wants to install a Cortex XSOAR engine in the second site?
In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)
Which two areas of Cortex XDR are used for threat hunting activities? (Choose two.)
Which Cortex XDR capability allows for the immediate termination of a process discovered during investigation of a security event?
When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?
The Cortex XDR management service requires which other Palo Alto Networks product?
A test for a Microsoft exploit has been planned. After some research Internet Explorer 11 CVE-2016-0189 has been selected and a module in Metasploit has been identified
(exploit/windows/browser/ms16_051_vbscript)
The description and current configuration of the exploit are as follows;

What is the remaining configuration?
A)

B)

C)

D)

Which Cortex XSIAM license is required if an organization needs to protect a cloud Kubernetes host?
How does the integration between Cortex Xpanse and Cortex XSOAR benefit security teams?
When running a Cortex XSIAM proof of value (POV), why is it important to deploy the Cortex XDR agent?
In addition to incident volume, which four critical factors must be evaluated to determine effectiveness and ROI on cybersecurity planning and technology?
Within Cortex XSIAM, how does the integration of Attack Surface Management (ASM) provide a unified approach to security event management that traditional SIEMs typically lack?
Why is reputation scoring important in the Threat Intelligence Module of Cortex XSOAR?
When initiated, which Cortex XDR capability allows immediate termination of the process-or entire process tree-on an anomalous process discovered during investigation of a security event?
Which resource can a customer use to ensure that the Cortex XDR agent will operate correctly on their CentOS 07 servers?



Correct