Paloalto Networks Palo Alto Networks System Engineer - Cortex Professional PSE-Cortex Question # 13 Topic 2 Discussion

Paloalto Networks Palo Alto Networks System Engineer - Cortex Professional PSE-Cortex Question # 13 Topic 2 Discussion

PSE-Cortex Exam Topic 2 Question 13 Discussion:
Question #: 13
Topic #: 2

What is a benefit of user entity behavior analytics (UEBA) over security information and event management (SIEM)?


A.

SIEMs supports only agentless scanning, not agent-based workload protection across VMs, containers/Kubernetes.


B.

UEBA can add trusted signers of Windows or Mac processes to a whitelist in the Endpoint Security Manager (ESM) Console.


C.

SIEMs have difficulty detecting unknown or advanced security threats that do not involve malware, such as credential theft.


D.

UEBA establishes a secure connection in which endpoints can be routed, and it collects and forwards logs and files for analysis.


Get Premium PSE-Cortex Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.