The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?
A. add paloaltonetworks com to the SSL Decryption Exclusion list
B. disable SSL decryption
C. reinstall the root CA certificate
D. enable SSL decryption
正解:C
質問 2:
Which two areas of Cortex XDR are used for threat hunting activities? (Choose two.)
A. host insights module
B. indicators of compromise (IOC) rules
C. query builder
D. live terminal
正解:A,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Why is reputation scoring important in the Threat Intelligence Module of Cortex XSOAR?
A. It allows for easy comparison between open-source intelligence and paid services.
B. It helps identify threat intelligence vendors with substandard content.
C. It deconflicts prioritization when two vendors give different scores for the same indicator.
D. It provides a mathematical model for combining scores from multiple vendors.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which three Demisto incident type features can be customized under Settings > Advanced > Incident Types?
(Choose three.)
A. Set reminders for an incident SLA
B. Drop new incidents of the same type that contain similar information
C. Define whether a playbook runs automatically when an incident type is encountered
D. Add new fields to an incident type
E. Define the way that incidents of a specific type are displayed in the system
正解:A,C,E
質問 5:
Which element displays an entire picture of an attack, including the root cause or delivery point?
A. Cortex XSOAR Work Plan
B. Cortex Data Lake
C. Cortex SOC Orchestrator
D. Cortex XDR Causality View
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Which two formats are supported by Whitelist? (Choose two)
A. Regex
B. STIX
C. CSV
D. CIDR
正解:A,D
質問 7:
A Cortex XSOAR customer wants to ingest emails from a single mailbox. The mailbox brings in reported phishing emails and email requests from human resources (HR) to onboard new users. The customer wants to run two separate workflows from this mailbox, one for phishing and one for onboarding.
What will allow Cortex XSOAR to accomplish this in the most efficient way?
A. Use machine learning (ML) to determine incident type.
B. Use an incident classifier based on a field in each type of email to classify those containing "Phish Alert" in the subject as phishing and those containing "Onboard Request" as onboarding.
C. Create a playbook to process and determine incident type based on content of the email.
D. Create two instances of the email integration and classify one instance as ingesting incidents of type phishing and the other as ingesting incidents of type onboarding.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
What is the primary purpose of Cortex XSIAM's machine learning led design?
A. To effectively handle the bulk of incidents through automation
B. To facilitate alert and log management without automation
C. To rely heavily on human-driven detection and remediation
D. To group alerts into incidents for manual analysis
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 9:
Which two entities can be created as a BIOC? (Choose two.)
A. alert log
B. file
C. event log
D. registry
正解:B,D
解説: (Pass4Test メンバーにのみ表示されます)
1109 お客様のコメント





Hoshino -
重要なキーワードや解説も丁寧で基礎も含めてこれPSE-Cortex一冊で十分カバー出来ます。過去問を解くことを繰り返していれば問題なくPSE-Cortex合格できると感じました。