Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks PSE-Cortex Practice Exam with Questions & Answers | Set: 5

Questions 41

Which two filter operators are available in Cortex XDR? (Choose two.)

Options:
A.

not Contains

B.

!*

C.

=>

D.

< >

Paloalto Networks PSE-Cortex Premium Access
Questions 42

Approximately how many Cortex XSOAR marketplace integrations exist?

Options:
A.

Between 1-400

B.

Between 400-700

C.

Between 700-2000

D.

Over 2000

Questions 43

The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?

Options:
A.

add paloaltonetworks com to the SSL Decryption Exclusion list

B.

enable SSL decryption

C.

disable SSL decryption

D.

reinstall the root CA certificate

Questions 44

What are two reasons incident investigation is needed in Cortex XDR? (Choose two.)

Options:
A.

No solution will stop every attack requiring further investigation of activity.

B.

Insider Threats may not be blocked and initial activity may go undetected.

C.

Analysts need to acquire forensic artifacts of malware that has been blocked by the XDR agent.

D.

Detailed reports are needed for senior management to justify the cost of XDR.

Questions 45

What is the result of creating an exception from an exploit security event?

Options:
A.

Administrators are exempt from generating alerts for 24 hours.

B.

Process from WildFire analysis is whitelisted.

C.

Triggered exploit protection module (EPM) for the host and process involved is disabled.

D.

User is exempt from generating events for 24 hours.

Questions 46

What is the primary purpose of Cortex XSIAM’s machine learning led design?

Options:
A.

To group alerts into incidents for manual analysis

B.

To facilitate alert and log management without automation

C.

To effectively handle the bulk of incidents through automation

D.

To rely heavily on human-driven detection and remediation

Questions 47

Within Cortex XSIAM, how does the integration of Attack Surface Management (ASM) provide a unified approach to security event management that traditional SIEMs typically lack?

Options:
A.

By providing a queryable dataset of ASM data for threat hunting

B.

By offering dashboards on ASM data within the management console

C.

By manually correlating of ASM data with security events

D.

By enriching incidents with ASM data for all internet-facing assets

Questions 48

A Cortex XSOAR customer has a phishing use case in which a playbook has been implemented with one of the steps blocking a malicious URL found in an email reported by one of the users.

What would be the appropriate next step in the playbook?

Options:
A.

Email the CISO to advise that malicious email was found.

B.

Disable the user's email account.

C.

Email the user to confirm the reported email was phishing.

D.

Change the user's password.

Questions 49

What does Cortex Xpanse ingest from XDR endpoints?

Options:
A.

MAC addresses

B.

User-agent data

C.

Public IP addresses

D.

Hostnames

Questions 50

Which CLI query would bring back Notable Events from Splunk?

A)

PSE-Cortex Question 50

B)

PSE-Cortex Question 50

C)

PSE-Cortex Question 50

D)

PSE-Cortex Question 50

Options:
A.

Option A

B.

Option B

C.

Option C

D.

Option D

Exam Code: PSE-Cortex
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks System Engineer - Cortex Professional
Last Update: Jul 15, 2025
Questions: 168