Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Palo Alto Networks System Engineer - Cortex Professional Question and Answers

Palo Alto Networks System Engineer - Cortex Professional

Last Update May 3, 2024
Total Questions : 60

We are offering FREE PSE-Cortex Paloalto Networks exam questions. All you do is to just go and sign up. Give your details, prepare PSE-Cortex free exam questions and then go for complete pool of Palo Alto Networks System Engineer - Cortex Professional test questions that will help you more.

PSE-Cortex pdf

PSE-Cortex PDF

$35  $99.99
PSE-Cortex Engine

PSE-Cortex Testing Engine

$42  $119.99
PSE-Cortex PDF + Engine

PSE-Cortex PDF + Testing Engine

$56  $159.99
Questions 1

What are process exceptions used for?

Options:

A.  

whitelist programs from WildFire analysis

B.  

permit processes to load specific DLLs

C.  

change the WildFire verdict for a given executable

D.  

disable an EPM for a particular process

Discussion 0
Questions 2

The images show two versions of the same automation script and the results they produce when executed in Demisto. What are two possible causes of the exception thrown in the second Image? (Choose two.)

SUCCESS

Options:

A.  

The modified scnpt was run in the wrong Docker image

B.  

The modified script required a different parameter to run successfully.

C.  

The dictionary was defined incorrectly in the second script.

D.  

The modified script attempted to access a dictionary key that did not exist in the dictionary named "data”

Discussion 0
Questions 3

Which Cortex XDR Agent capability prevents loading malicious files from USB-connected removable equipment?

Options:

A.  

Agent Configuration

B.  

Device Control

C.  

Device Customization

D.  

Agent Management

Discussion 0
Questions 4

Given the exception thrown in the accompanying image by the Demisto REST API integration, which action would most likely solve the problem?

Which two playbook functionalities allow looping through a group of tasks during playbook execution? (Choose two.)

Options:

A.  

Generic Polling Automation Playbook

B.  

Playbook Tasks

C.  

Sub-Play books

D.  

Playbook Functions

Discussion 0
Questions 5

What are two manual actions allowed on War Room entries? (Choose two.)

Options:

A.  

Mark as artifact

B.  

Mark as scheduled entry

C.  

Mark as note

D.  

Mark as evidence

Discussion 0
Questions 6

In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three )

Options:

A.  

alert root cause

B.  

hostname

C.  

domain/workgroup membership

D.  

OS

E.  

presence of Flash executable

Discussion 0
Questions 7

The certificate used for decryption was installed as a trusted toot CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?

Options:

A.  

add paloaltonetworks.com to the SSL Decryption Exclusion list

B.  

enable SSL decryption

C.  

disable SSL decryption

D.  

reinstall the root CA certificate

Discussion 0
Questions 8

An administrator of a Cortex XDR protected production environment would like to test its ability to protect users from a known flash player exploit.

What is the safest way to do it?

Options:

A.  

The administrator should attach a copy of the weapomzed flash file to an email, send the email to a selected group of employees, and monitor the Events tab on the Cortex XDR console

B.  

The administrator should use the Cortex XDR tray icon to confirm his corporate laptop is fully protected then open the weaponized flash file on his machine, and monitor the Events tab on the Cortex XDR console.

C.  

The administrator should create a non-production Cortex XDR test environment that accurately represents the production environment, introduce the weaponized flash file, and monitor the Events tab on the Cortex XDR console.

D.  

The administrator should place a copy of the weaponized flash file on several USB drives, scatter them around the office and monitor the Events tab on the Cortex XDR console

Discussion 0
Questions 9

Which deployment type supports installation of an engine on Windows, Mac OS. and Linux?

Options:

A.  

RPM

B.  

SH

C.  

DEB

D.  

ZIP

Discussion 0