لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #2
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #3
If you have an isolated network that is prevented from connecting to the Cortex Data Lake, which type of Broker VM setup can you use to facilitate the communication?
A. ABroker VM Pathfinder
B. BLocal Agent Proxy
C. CLocal Agent Installer and Content Caching
D. DBroker VM Syslog Collector
عرض الإجابة
اجابة صحيحة: B
السؤال #4
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #5
Which statement is true based on the following Agent Auto Upgrade widget?
A. gent Auto Upgrade has not been enabled
B. here are a total of 689 Up To Date agents
C. here are more agents in Pending status than In Progress status
D. gent Auto Upgrade was enabled but not on all endpoints
عرض الإجابة
اجابة صحيحة: D
السؤال #6
When viewing the incident directly, what is the "assigned to" field value of a new Incident that was just reported to Cortex?
A. Pending
B. It is blank
C. Unassigned
D. New
عرض الإجابة
اجابة صحيحة: C
السؤال #7
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #8
In the Cortex XDR console, from which two pages are you able to manually perform the agent upgrade action? (Choose two.)
A. Asset Management
B. Agent Installations
C. Action Center
D. Endpoint Administration
عرض الإجابة
اجابة صحيحة: AD
السؤال #9
An attacker tries to load dynamic libraries on macOS from an unsecure location.Which Cortex XDRmodule can prevent this attack?
A. DDL Security
B. Hot Patch Protection
C. Kernel Integrity Monitor (KIM)
D. Dylib Hijacking
عرض الإجابة
اجابة صحيحة: D
السؤال #10
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #11
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #12
To stop a network-based attack, any interference with a portion of the attack pattern is enough to prevent it from succeeding. Which statement is correct regarding the Cortex XDR Analytics module?
A. t does not interfere with any portion of the pattern on the endpoint
B. t interferes with the pattern as soon as it is observed on the endpoint
C. t does not need to interfere with the any portion of the pattern to prevent the attack
D. t interferes with the pattern as soon as it is observed by the firewall
عرض الإجابة
اجابة صحيحة: B
السؤال #13
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D
السؤال #14
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D
السؤال #15
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #16
If you have an isolated network that is prevented from connecting to the Cortex Data Lake, which type of Broker VM setup can you use to facilitate the communication?
A. Broker VM Pathfinder
B. Local Agent Proxy
C. Local Agent Installer and Content Caching
D. Broker VM Syslog Collector
عرض الإجابة
اجابة صحيحة: B
السؤال #17
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #18
What is the purpose of the Unit 42 team?
A. Unit 42 is responsible for automation and orchestration of products
B. Unit 42 is responsible for the configuration optimization of the Cortex XDR server
C. Unit 42 is responsible for threat research, malware analysis and threat hunting
D. Unit 42 is responsible for the rapid deployment of Cortex XDR agents
عرض الإجابة
اجابة صحيحة: C
السؤال #19
Which statement is true for Application Exploits and Kernel Exploits?
A. The ultimate goal of any exploit is to reach the application
B. Kernel exploits are easier to prevent then application exploits
C. The ultimate goal of any exploit is to reach the kernel
D. Application exploits leverage kernel vulnerability
عرض الإجابة
اجابة صحيحة: C
السؤال #20
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #21
In Cortex XDR management console scheduled reports can be forwarded to which of the following applications/services?
A. lack
B. ervice Now
C. alesforce
D. ira
عرض الإجابة
اجابة صحيحة: A
السؤال #22
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #23
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #24
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #25
When creating a BIOC rule, which XQL query can be used?
A. dataset = xdr_data| filter event_sub_type = PROCESS_START and action_process_image_name ~= "
B. dataset = xdr_data| filter event_type = PROCESS and event_sub_type = PROCESS_START and action_process_image_name ~= "
C. dataset = xdr_data| filter action_process_image_name ~= "
D. dataset = xdr_data| filter event_behavior = true event_sub_type = PROCESS_START and action_process_image_name ~= "
عرض الإجابة
اجابة صحيحة: B
السؤال #26
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #27
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #28
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #29
Which built - in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
A. Security Manager Dashboard
B. Data Ingestion Dashboard
C. Security Admin Dashboard
D. Incident Management Dashboard
عرض الإجابة
اجابة صحيحة: D
السؤال #30
What is the difference between presets and datasets in XQL?
A. dataset is a built-in or third-party source; presets group XDR data fields
B. dataset is a third-party data source; presets are built-in data source
C. dataset is a Cortex data lake data source only; presets are built-in data source
D. dataset is a database; presets is a field
عرض الإجابة
اجابة صحيحة: A

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us