Which sensor does Cortex XSIAM use to detect and collect DNS queries, HTTP headers, and DHCP information?
AWindows Event Collector logs
BDirectory Sync logs
CPathfinder data collector
DEnhanced application logs
Which task is mainly handled by Identity Analytics?
APolicy enforcement
BThreat intelligence ingestion
CCredential phishing detection
DSuspicious login identification
An incident response team must correlate suspicious events across NGFW logs, cloud-workload alerts, and compromised user-account activity reported by the identity provider (IdP).
Which capability makes Cortex XDR the superior tool for these investigations compared with endpoint detection and response (EDR) solutions offered elsewhere?
AAbility to perform forensic data collection directly on the host
BUnified ingestion and normalization of data from non-endpoint sources like network and cloud platforms
CReliance on signature-based prevention for known malware
DRequirement for a separate Security Information and Event Management (SIEM) solution for speed and efficiency
An organization needs a security solution that provides comprehensive threat visibility across its full digital ecosystem—including firewalls, cloud environments, and user-authentication logs—rather than only endpoint data.
Which Palo Alto Networks solution is best suited to satisfy this expanded requirement?
ACortex endpoint protection platform (EPP)
BCortex XDR
CCortex Cloud Identity Engine
DCortex XSIAM
QuestionQ6
Threat Intelligence and Incident Response
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Cortex XSOAR
QuestionQ8
Cortex XSOAR
QuestionQ9
Cortex XDR
QuestionQ10
Cortex XDR
QuestionQ11
Cortex XDR
QuestionQ12
Cortex XDR
QuestionQ13
Cortex XSOAR
QuestionQ14
Cortex XSOAR
QuestionQ15
Cortex XDR
QuestionQ16
Cortex XSOAR
QuestionQ17
Cortex XSIAM
QuestionQ18
Cortex XDR
QuestionQ19
Cortex XSOAR
QuestionQ20
Security Operations Fundamentals
QuestionQ21
Security Operations Fundamentals
QuestionQ22
Security Operations Fundamentals
QuestionQ23
Threat Intelligence and Incident Response
QuestionQ24
Cortex XSOAR
QuestionQ25
Cortex XDR
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which incident should a responder give priority to based on its overall functional and informational impact on the company?
AA user in the accounting department receives a pop-up message after visiting a website.
BA public-facing web server has multiple failed login attempts over a short period of time.
CAn external-facing company website is currently unavailable.
DA large upload of user data from an internal file server to a public website occurs.
Which Cortex XSOAR capability enables the sourcing, downloading, and management of curated collections of security orchestration content?
ADeployment Wizard
BCortex Marketplace
CContent contribution interface
DContent version control
What is the role of incident types in Cortex XSOAR?
AThey categorize manual and automated incidents, trigger playbooks automatically, and require predefined fields and integrations.
BThey assist in mapping manual incidents, assign default playbooks, and require inline auto-extraction of indicators.
CThey classify events ingested through integrations or the REST API, can trigger specific playbooks, and include customizable layouts and service-level agreement (SLA) parameters.
DThey manually create incidents, configure universal playbooks, and enforce strict adherence to preset service-level agreement (SLA) reminders.
A security analyst is examining a high-priority alert involving a sequence of connected, low-severity events. The alert was generated because this composite activity substantially departed from the network’s normal, established behavior patterns.
Which Cortex XDR component correlates these events and generates an alert?
AAnalytics Engine
BXQL Query Engine
CCloud Identity Engine
DCausality Analysis Engine
What distinguishes cold storage from hot storage in Cortex?
ACold storage is required, while hot storage is optional.
BCold storage and hot storage can be stored in different cloud locations.
CLogs in cold storage have more details than logs stored in hot storage.
DQuerying logs in cold storage takes more time than querying logs in hot storage.
An organization needs a particular user to investigate alerts and carry out remediation actions, such as terminating malicious processes and isolating compromised hosts, without granting full administrative control of the tenant settings.
Which predefined Cortex XDR role should be assigned to this user?
AViewer
BInvestigator
CDeployment Admin
DResponder
Which query language performs a deep investigation into a series of potential endpoint attacks by searching all collected event data with Cortex XDR Query Builder?
AXQL
BSQL
CKQL
DSPL
Which action should an administrator perform to create automated response actions when a user account has been compromised?
AMap the events as a type of Cortex XSOAR incident, then run a playbook.
BCreate playbook triggers in Cortex XSIAM and run playbooks for each alert.
CCreate a script in Cortex XSOAR that will run a playbook based on the scenario.
DRun a custom script from the Cortex XDR script library.
Which indicator types does Cortex XSOAR support out of the box?
AMAC addresses, URLs, file paths, and extended validation certificates
BIP addresses, domain names, URLs, and file hashes
CRegistry keys, file paths, file hashes, and wild card certificates
DEmail addresses, domain names, SSL certificates, and natural language indicators
What is needed to enable the ingestion of on-premises firewall logs into Cortex XDR?
ABroker VM
BAPI
CPAN-OS content pack
DCloud Identity Engine
Which activities does the War Room in Cortex XSOAR facilitate?
ACreating, editing, and deleting tasks in the workplan
BRunning security playbooks, scripts, and commands
CConducting initial investigation of incident data and threat intelligence
DViewing a summary of case details and alerts
Which two roles are able to access data model rules in Cortex XSIAM?
Choose two
AAccount admin
BDeployment admin
CInstance administrator
DIT administrator
What should an account administrator configure when granting a Cortex XDR user access only to a particular endpoint group?
AIdentity provider (IdP) account placed in the appropriate group
BRole-Based Access Control (RBAC) with a predefined role
CCustomer Support Portal account with the appropriate role
DScope-Based Access Control (SBAC) with specific tags
Which function removes the need for manual analysis in an organization that has multiple data sensors?
ALog stitching
BLog correlation
CLog forwarding
DEvent log query
What is a primary benefit of data protection?
AImproving accessibility to data
BStreamlining data onboarding process
CStreamlining business processes
DAbiding by compliance regulations
Which SOC tool enables an organization to aggregate logs from multiple sources for compliance, reporting, dashboarding, and threat hunting?
AEndpoint detection and response (EDR)
BAttack surface management (ASM)
CSecurity orchestration, automation, and response (SOAR)
DSecurity Information and Event Management (SIEM)
Which security operations center (SOC) role examines a newly generated low-severity alert?
ASOC manager
BThreat hunter
CIncident responder
DTriage specialist
An analyst observes a threat actor using the Remote Desktop Protocol (RDP) to log on interactively to a domain controller with credentials stolen from a compromised workstation.
Which MITRE Enterprise tactic includes this technique?
ALateral Movement
BCollection
CCommand and Control
DDefense Evasion
Which Cortex XSOAR feature can run a particular integration command to enrich an IP address without leaving the incident view, while ensuring that the action is recorded in the incident's history?
AWar Room
BWork plan
CPlayground
DEvidence board
What task should a threat hunter include in the investigation when a Cortex XDR incident contains alerts about a malicious process?
AImmediately isolate the endpoint and delete the identified file.
BSearch for the SHA256 file hash on other endpoints in the environment.
CAdd the SHA256 file hash to the Cortex XDR global block list.
DDisable the account of the user responsible for initiating the process.
Community Discussion