Pass the Paloalto Networks Palo Alto Certifications and Accreditations PCDRA Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

The Cortex XDR console has triggered an incident, blocking a vitally important piece of software in your organization that is known to be benign. Which of the following options would prevent Cortex XDR from blocking this software in the future, for all endpoints in your organization?

Options:

A.

Create an individual alert exclusion.


B.

Create a global inclusion.


C.

Create an endpoint-specific exception.


D.

Create a global exception.


Expert Solution
Questions # 22:

Which version of python is used in live terminal?

Options:

A.

Python 2 and 3 with standard Python libraries


B.

Python 2 and 3 with specific XDR Python libraries developed by Palo Alto Networks


C.

Python 3 with specific XDR Python libraries developed by Palo Alto Networks


D.

Python 3 with standard Python libraries


Expert Solution
Questions # 23:

Why would one threaten to encrypt a hypervisor or, potentially, a multiple number of virtual machines running on a server?

Options:

A.

To extort a payment from a victim or potentially embarrass the owners.


B.

To gain notoriety and potentially a consulting position.


C.

To better understand the underlying virtual infrastructure.


D.

To potentially perform a Distributed Denial of Attack.


Expert Solution
Questions # 24:

When is the wss (WebSocket Secure) protocol used?

Options:

A.

when the Cortex XDR agent downloads new security content


B.

when the Cortex XDR agent uploads alert data


C.

when the Cortex XDR agent connects to WildFire to upload files for analysis


D.

when the Cortex XDR agent establishes a bidirectional communication channel


Expert Solution
Questions # 25:

Live Terminal uses which type of protocol to communicate with the agent on the endpoint?

Options:

A.

NetBIOS over TCP


B.

WebSocket


C.

UDP and a random port


D.

TCP, over port 80


Expert Solution
Questions # 26:

When creating a BIOC rule, which XQL query can be used?

Options:

A.

dataset = xdr_data

| filter event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"


B.

dataset = xdr_data

| filter event_type = PROCESS and

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"


C.

dataset = xdr_data

| filter action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

| fields action_process_image


D.

dataset = xdr_data

| filter event_behavior = true

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"


Expert Solution
Questions # 27:

A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?

Options:

A.

It is true positive.


B.

It is false positive.


C.

It is a false negative.


D.

It is true negative.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions