In Cortex XDR Prevent, which three matching criteria can be used to dynamically group endpoints? (Choose three.)
A. Domain/workgroup membership
B. attack threat intelligence tag
C. quarantine status
D. OS
E. hostname
正解:C,D,E
質問 2:
A customer agrees to do a 30-day proof of concept (POC) and wants to integrate with a product with which Cortex XSOAR is not currently integrated.
What is the appropriate response to this customer?
A. Explain that custom integrations are not included in the POC.
B. Explain that it can be built by Professional Services, but it will take an additional 30 days.
C. Extend the POC window to allow the solution architects to build it.
D. Agree to build the integration as part of the POC.
正解:A
質問 3:
Which statement applies to the malware protection flow in Cortex XDR Prevent?
A. Hash comparisons come after local static analysis.
B. Local static analysis happens before a WildFire verdict check.
C. A trusted signed file is exempt from local static analysis.
D. In the final step, the block list is verified.
正解:C
質問 4:
How many use cases should a POC success criteria document include?
A. 3 or more
B. no more than 5
C. only 1
D. no more than 2
正解:C
質問 5:
Cortex XSOAR has extracted a malicious Internet Protocol (IP) address involved in command- and-control (C2) traffic.
What is the best method to block this IP from communicating with endpoints without requiring a configuration change on the firewall?
A. Have XSOAR automatically add the IP address to a deny rule in the firewall.
B. Have XSOAR automatically create a NetOps ticket requesting a configuration change to the firewall to block the IP.
C. Have XSOAR automatically add the IP address to an external dynamic list (EDL) used by the firewall.
D. Have XSOAR automatically add the IP address to a threat intelligence management (TIM) malicious IP list to elevate priority of future alerts.
正解:C
質問 6:
An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?
A. operations manager
B. SOC manager
C. SOC analyst IT
D. desktop engineer
正解:B
青山** -
PSE-Cortexにおける重要な知識を整理している。ありがたい。
素晴らしい問題集に出会いさせてもらったPass4Testに感謝しかないです。