لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
A. n the Restrictions Profile, add the file name and path to the Executable Files allow list
B. dd the signer to the allow list in the malware profile
C. reate a new rule exception and use the singer as the characteristic
D. dd the signer to the allow list under the action center page
عرض الإجابة
اجابة صحيحة: B
السؤال #2
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #3
A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?
A. It is true positive
B. It is false positive
C. It is a false negative
D. It is true negative
عرض الإجابة
اجابة صحيحة: B
السؤال #4
Which type of BIOC rule is currently available in Cortex XDR?
A. Threat Actor
B. Discovery
C. Network
D. Dropper
عرض الإجابة
اجابة صحيحة: B
السؤال #5
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
A. Click the three dots on the widget and then choose “Save” and this will link the query to the Widget Library
B. This isn’t supported, you have to exit the dashboard and go into the Widget Library first to create it
C. Click on “Save to Action Center” in the dashboard and you will be prompted to give the query a name and description
D. Click on “Save to Widget Library” in the dashboard and you will be prompted to give the query a name and description
عرض الإجابة
اجابة صحيحة: D
السؤال #6
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #7
What license would be required for ingesting external logs from various vendors?
A. Cortex XDR Pro per Endpoint
B. Cortex XDR Vendor Agnostic Pro
C. Cortex XDR Pro per TB
D. Cortex XDR Cloud per Host
عرض الإجابة
اجابة صحيحة: C
السؤال #8
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D
السؤال #9
When reaching out to TAC for additional technical support related to a Security Event; what are two critical pieces of information you need to collect from the Agent? (Choose Two)
A. The agent technical support file
B. The prevention archive from the alert
C. The distribution id of the agent
D. A list of all the current exceptions applied to the agent
E. The unique agent id
عرض الإجابة
اجابة صحيحة: AB
السؤال #10
Live Terminal uses which type of protocol to communicate with the agent on the endpoint?
A. ebSocket
B. etBIOS over TCP
C. CP, over port 80
D. DP and a random port
عرض الإجابة
اجابة صحيحة: A
السؤال #11
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #12
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #13
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #14
Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?
A. AUASLR
B. BJIT Mitigation
C. CMemory Limit Heap Spray Check
D. DDLL Security
عرض الإجابة
اجابة صحيحة: B
السؤال #15
Which of the following best defines the Windows Registry as used by the Cortex XDR agent?
A. a hierarchical database that stores settings for the operating system and for applications
B. a system of files used by the operating system to commit memory that exceeds the available hardware resources
C. a central system, available via the internet, for registering officially licensed versions of software to prove ownership
D. a ledger for maintaining accurate and up-to-date information on total disk usage and disk space remaining available to the operating system
عرض الإجابة
اجابة صحيحة: A
السؤال #16
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D
السؤال #17
What is an example of an attack vector for ransomware?
A. APerforming DNS queries for suspicious domains
B. BPerforming SSL Decryption on an endpoint
C. CPhishing emails containing malicious attachments
D. DA URL filtering feature enabled on a firewall
عرض الإجابة
اجابة صحيحة: C
السؤال #18
Which of the following Live Terminal options are available for Android systems?
A. ive Terminal is not supported
B. top an app
C. un Android commands
D. un APK scripts
عرض الإجابة
اجابة صحيحة: C
السؤال #19
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #20
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #21
Which statement is true for Application Exploits and Kernel Exploits?
A. he ultimate goal of any exploit is to reach the application
B. ernel exploits are easier to prevent then application exploits
C. pplication exploits leverage kernel vulnerability
D. he ultimate goal of any exploit is to reach the kernel
عرض الإجابة
اجابة صحيحة: D
السؤال #22
What is the purpose of targeting software vendors in a supply-chain attack?
A. Ato take advantage of a trusted software delivery method
B. Bto steal users' login credentials
C. Cto access source code
D. Dto report Zero-day vulnerabilities
عرض الإجابة
اجابة صحيحة: A
السؤال #23
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D
السؤال #24
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #25
Which search methods is supported by File Search and Destroy?
A. File Seek and Destroy
B. File Search and Destroy
C. File Seek and Repair
D. File Search and Repair
عرض الإجابة
اجابة صحيحة: B
السؤال #26
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D
السؤال #27
What kind of malware uses encryption, data theft, denial of service, and possibly harassment to take advantage of a victim?
A. Ransomware
B. Worm
C. Keylogger
D. Rootkit
عرض الإجابة
اجابة صحيحة: A
السؤال #28
What does the following output tell us?
A. There is one low severity incident
B. Host shpapy_win10 had the most vulnerabilities
C. There is one informational severity alert
D. This is an actual output of the Top 10 hosts with the most malware
عرض الإجابة
اجابة صحيحة: D

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us