لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Live Terminal uses which type of protocol to communicate with the agent on the endpoint?
A. ANetBIOS over TCP
B. BWebSocket
C. CUDP and a random port
D. DTCP, over port 80
عرض الإجابة
اجابة صحيحة: B
السؤال #2
What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)
A. Automatically close the connections involved in malicious traffic
B. Automatically kill the processes involved in malicious activity
C. Automatically terminate the threads involved in malicious activity
D. Automatically block the IP addresses involved in malicious traffic
عرض الإجابة
اجابة صحيحة: BD
السؤال #3
Which Type of IOC can you define in Cortex XDR?
A. destination port
B. e-mail address
C. full path
D. App-ID
عرض الإجابة
اجابة صحيحة: C
السؤال #4
What is an example of an attack vector for ransomware?
A. Performing DNS queries for suspicious domains
B. Performing SSL Decryption on an endpoint
C. Phishing emails containing malicious attachments
D. A URL filtering feature enabled on a firewall
عرض الإجابة
اجابة صحيحة: C
السؤال #5
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
A. Click the three dots on the widget and then choose "Save" and this will link the query to theWidget Library
B. This isn't supported, you have to exit the dashboard and go into the Widget Library first to create it
C. Click on "Save to Action Center" in the dashboard and you will be prompted to give the query a name and description
D. Click on "Save to Widget Library" in the dashboard and you will be prompted to give the query a name and description
عرض الإجابة
اجابة صحيحة: D
السؤال #6
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
A. Create a custom XQL widget
B. This is not currently supported
C. Create a custom report and filter on starred incidents
D. Click the star in the widget
عرض الإجابة
اجابة صحيحة: D
السؤال #7
Phishing belongs to which of the following MITRE ATT&CK tactics?
A. Initial Access, Persistence
B. Persistence, Command and Control
C. Reconnaissance, Persistence
D. Reconnaissance, Initial Access
عرض الإجابة
اجابة صحيحة: D
السؤال #8
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #9
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. Sensor Engine
B. Causality Analysis Engine
C. Log Stitching Engine
D. Causality Chain Engine
عرض الإجابة
اجابة صحيحة: B
السؤال #10
Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
A. Security Manager Dashboard
B. Data Ingestion Dashboard
C. Security Admin Dashboard
D. Incident Management Dashboard
عرض الإجابة
اجابة صحيحة: D
السؤال #11
What are two purposes of "Respond to Malicious Causality Chains" in a Cortex XDR Windows Malware profile? (Choose two.)
A. Automatically close the connections involved in malicious traffic
B. Automatically kill the processes involved in malicious activity
C. Automatically terminate the threads involved in malicious activity
D. Automatically block the IP addresses involved in malicious traffic
عرض الإجابة
اجابة صحيحة: BD
السؤال #12
What is the maximum number of agents one Broker VM local agent applet can support?
A. 5,000
B. 10,000
C. 15,000
D. 20,000
عرض الإجابة
اجابة صحيحة: B
السؤال #13
Where would you view the WildFire report in an incident?
A. next to relevant Key Artifacts in the incidents details page
B. under Response --> Action Center
C. under the gear icon --> Agent Audit Logs
D. on the HUB page at apps
عرض الإجابة
اجابة صحيحة: A
السؤال #14
To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
A. causality_chain
B. endpoint_name
C. threat_event
D. event_type
عرض الإجابة
اجابة صحيحة: D
السؤال #15
What kind of the threat typically encrypts user files?
A. ransomware
B. SQL injection attacks
C. Zero-day exploits
D. supply-chain attacks
عرض الإجابة
اجابة صحيحة: A
السؤال #16
Phishing belongs to which of the following MITRE ATT&CK tactics?
A. Initial Access, Persistence
B. Persistence, Command and Control
C. Reconnaissance, Persistence
D. Reconnaissance, Initial Access
عرض الإجابة
اجابة صحيحة: D
السؤال #17
Which Exploit Prevention Module (EPM) provides better entropy for randomization of memory locations?
A. IT Mitigation
B. ASLR
C. LL Security
D. emory Limit Heap spray check
عرض الإجابة
اجابة صحيحة: B
السؤال #18
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
A. ausality Analysis Engine
B. ensor Engine
C. ausality Chain Engine
D. og Stitching Engine
عرض الإجابة
اجابة صحيحة: A

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us