<< Prev Question Next Question >>

Question 53/73

An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (73q)
Question 1: What is the result of creating an exception from an exploit ...
Question 2: What is the difference between an exception and an exclusion...
Question 3: Which Cortex XSIAM license is required if an organization ne...
Question 4: Which three Demisto incident type features can be customized...
Question 5: Cortex XDR can schedule recurring scans of endpoints for mal...
Question 6: What should be configured for a Cortex XSIAM customer who wa...
Question 7: Which product enables the discovery, exchange, and contribut...
Question 8: An adversary is attempting to communicate with malware runni...
Question 9: Which integration allows searching and displaying Splunk res...
Question 10: Which command-line interface (CLI) query would retrieve the ...
Question 11: Which option describes a Load-Balancing Engine Group?...
Question 12: An administrator has a critical group of systems running Win...
Question 13: How can the required log ingestion license be determined whe...
Question 14: Which resource can a customer use to ensure that the Cortex ...
Question 15: The certificate used for decryption was installed as a trust...
Question 16: An adversary attempts to communicate with malware running on...
Question 17: What are two manual actions allowed on War Room entries? (Ch...
Question 18: What does the Cortex XSOAR "Saved by Dbot" widget calculate?...
Question 19: Which technology allows a customer to integrate Cortex Xpans...
Question 20: An EDR project was initiated by a CISO. Which resource will ...
Question 21: In an Air-Gapped environment where the Docker package was ma...
Question 22: Which method is used for third-party network data consumptio...
Question 23: Which feature of Cortex XSIAM helps analyst reduce the noise...
Question 24: What is the primary mechanism for the attribution of attack ...
Question 25: How does Cortex XSOAR automation save time when a phishing i...
Question 26: What is a requirement when integrating Cortex XSIAM or Corte...
Question 27: What is the primary function of an engine in Cortex XSOAR?...
Question 28: In Cortex XDR Prevent, which three matching criteria can be ...
Question 29: Which aspect of Cortex Xpanse allows for visibility over rem...
Question 30: Which two statements apply to widgets? (Choose two.)...
Question 31: Which two formats are supported by Whitelist? (Choose two)...
Question 32: Which two filter operators are available in Cortex XDR? (Cho...
Question 33: Which two methods does the Cortex XDR agent use to identify ...
Question 34: Which deployment type supports installation of an engine on ...
Question 35: Which Linux OS command will manually load Docker images onto...
Question 36: How many use cases should a POC success criteria document in...
Question 37: The customer has indicated they need EDR data collection cap...
Question 38: When initiated, which Cortex XDR capability allows immediate...
Question 39: What does Cortex Xpanse ingest from XDR endpoints?...
Question 40: Why is reputation scoring important in the Threat Intelligen...
Question 41: Which Cortex XDR capability prevents running malicious files...
Question 42: Which playbook functionality allows grouping of tasks to cre...
Question 43: What is the result of creating an exception from an exploit ...
Question 44: In addition to incident volume, which four critical factors ...
Question 45: In addition to migration and go-live, what are two best-prac...
Question 46: What is a benefit of user entity behavior analytics (UEBA) o...
Question 47: What is the difference between the intel feed's license quot...
Question 48: Which two filter operators are available in Cortex XDR? (Cho...
Question 49: Which playbook feature allows concurrent execution of tasks?...
Question 50: Which statement applies to the differentiation of Cortex XDR...
Question 51: Given the integration configuration and error in the screens...
Question 52: Which two log types should be configured for firewall forwar...
Question 53: An Administrator is alerted to a Suspicious Process Creation...
Question 54: When preparing the golden image in a Cortex XDR Virtual Desk...
Question 55: How can Cortex XSOAR save time when a phishing incident occu...
Question 56: When integrating with Splunk, what will allow you to push al...
Question 57: Cortex XSOAR has extracted a malicious Internet Protocol (IP...
Question 58: What is the size of the free Cortex Data Lake instance provi...
Question 59: The Cortex XDR management service requires which other Palo ...
Question 60: How do sub-playbooks affect the Incident Context Data?...
Question 61: How can you view all the relevant incidents for an indicator...
Question 62: A customer wants the main Cortex XSOAR server installed in o...
Question 63: A customer has purchased Cortex XSOAR and has a need to rapi...
Question 64: What is the requirement for enablement of endpoint and netwo...
Question 65: Which description applies to the features of the Cortex plat...
Question 66: What is a benefit offered by Cortex XSOAR?...
Question 67: Which Cortex XDR Agent capability prevents loading malicious...
Question 68: What is used to display only file entries in a War Room?...
Question 69: Which Cortex XDR capability allows for the immediate termina...
Question 70: Which attack method is a result of techniques designed to ga...
Question 71: When running a Cortex XSIAM proof of value (POV), why is it ...
Question 72: For which two purposes can Cortex XSOAR engines be deployed?...
Question 73: Where is the best place to find official resource material?...