QUESTIONS AND ANSWERS
Which two advantages does endpoint protection technology have over network traffic analysis?
(Choose two.)
Ability to identify most common attacks by their symptoms.
Deployed and managed centrally.
Easier to deploy endpoint protection when people work from home.
Detects command and control channels.
Can easily identify worms.
Ability to identify most common attacks by their symptoms.
Easier to deploy endpoint protection when people work from home.
What does Cortex XSOAR use to automate security processes?
bash scripts
Windows PowerShell
playbooks
Python scripts
Playbooks
Which three options partially comprise the six elements of SecOps? (Choose three.)
People
Networking
Data storage
Technology
Processes
People
Technology
Processes
What is the relationship between SIEM and SOAR?
SIEM products implement the SOAR business process.
SIEM and SOAR are different names for the same product category.
SIEM systems collect information to identify issues that SOAR products help mitigate.
SOAR systems collect information to identify issues that SIEM products help mitigate.
SIEM systems collect information to identify issues that SOAR products help mitigate.
Which three operating systems are supported by Cortex XDR? (Choose three.)
, z/OS
Linux
macOS
Minix
Android
Linux
MacOS
Android
Of the endpoint checks, what is bypassed for known programs?
WildFire query
behavioral threat protection
local analysis
Firewall analysis
Local analysis
Which three options partially comprise the six elements of SecOps? (Choose three.)
Visibility
Disaster recovery
Business
Interfaces
Regular audits
Visibility
Business
Interfaces
Which Palo Alto Networks NGFW subscription service enables you to identify and control access to
websites that host malware and phishing pages?
Threat Prevention
URL Filtering
DNS Security
WildFire
URL Filtering
Which technique changes protocols at random during a session?
port hopping
use of non-standard ports
tunneling within commonly used services
hiding within SSL encryption