Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PSE-Cortex Practice Exam with Questions & Answers

Questions 1

What is the requirement for enablement of endpoint and network analytics in Cortex XDR?

Options:
A.

Cloud Identity Engine configured and enabled

B.

Network Mapper applet on the Broker VM configured and enabled

C.

Logs from at least 30 endpoints over a minimum of two weeks

D.

Windows DHCP logs ingested via a Cortex XDR collector

Paloalto Networks PSE-Cortex Premium Access
Questions 2

Why is reputation scoring important in the Threat Intelligence Module of Cortex XSOAR?

Options:
A.

It allows for easy comparison between open-source intelligence and paid services.

B.

It deconflicts prioritization when two vendors give different scores for the same indicator.

C.

It provides a mathematical model for combining scores from multiple vendors.

D.

It helps identify threat intelligence vendors with substandard content.

Questions 3

Cortex XDR external data ingestion processes ingest data from which sources?

Options:
A.

windows event logs only

B.

syslogs only

C.

windows event logs, syslogs, and custom external sources

D.

windows event logs and syslogs only

Questions 4

How many use cases should a POC success criteria document include?

Options:
A.

only 1

B.

3 or more

C.

no more than 5

D.

no more than 2

Questions 5

What is the function of reputation scoring in the Threat Intelligence Module of Cortex XSIAM?

Options:
A.

It provides a statistical model for combining scores from multiple vendors

B.

It resolves conflicting scores from different vendors with the same indicator.

C.

It allows for comparison between open-source intelligence and paid services.

D.

It helps identify threat feed vendors with invalid content.

Questions 6

What is the size of the free Cortex Data Lake instance provided to a customer who has activated a TMS tenant, but has not purchased a Cortex Data Lake instance?

Options:
A.

10 GB

B.

1 TB

C.

10 TB

D.

100 GB

Questions 7

Which two statements apply to widgets? (Choose two.)

Options:
A.

All widgets are customizable.

B.

Dashboards cannot be shared across an organization.

C.

A widget can have its own time range that is different from the rest of the dashboard.

D.

Some widgets cannot be changed

Questions 8

An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?

Options:
A.

desktop engineer

B.

SOC manager

C.

SOC analyst IT

D.

operations manager

Questions 9

What are two manual actions allowed on War Room entries? (Choose two.)

Options:
A.

Mark as artifact

B.

Mark as scheduled entry

C.

Mark as note

D.

Mark as evidence

Questions 10

Which solution profiles network behavior metadata, not payloads and files, allowing effective operation regardless of encrypted or unencrypted communication protocols, like HTTPS?

Options:
A.

endpoint protection platform (EPP)

B.

Security Information and Event Management (SIEM)

C.

endpoint detection and response (EDR)

D.

Network Detection and Response (NDR)

Exam Code: PSE-Cortex
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks System Engineer - Cortex Professional
Last Update: Jul 15, 2025
Questions: 168