Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Security Operations XSIAM-Engineer Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which cytool command will look up the policy being applied to a Cortex XDR agent?

Options:

A.

cytool adaptive_policy interval 0


B.

cytool payload_execution query


C.

cytool adaptive_policy recalc


D.

cytool persist print agent_settings.db


Expert Solution
Questions # 2:

Which action is required to enable use of a custom script in an alert layout?

Options:

A.

Tag the script with "dynamic-section," add a general purpose dynamic section, and edit the section settings to add the automation script.


B.

Tag the script with "general-purpose-dynamic-section," add a custom script section, and edit the section settings to add the automation script.


C.

Add a general purpose dynamic section and edit the section settings to add the automation script.


D.

Tag the script with "general-purpose-dynamic-section." add a general purpose dynamic section, and edit the section settings to add the automation script.


Expert Solution
Questions # 3:

A Cortex XSIAM engineer plans to add Kafka and Syslog Collectors to a Broker VM cluster.

What are two expected behaviors of the applets when they are added to the cluster? (Choose two.)

Options:

A.

Syslog Collector applet is automatically initiated, enters an active state on the primary node, and is on standby on the standby nodes.


B.

Kafka Collector applet is automatically initiated, enters an active state on the primary node, and is on standby on the standby nodes.


C.

Syslog Collector applet is active on all cluster nodes, including primary and standby.


D.

Kafka Collector applet is active on all cluster nodes, including primary and standby.


Expert Solution
Questions # 4:

What is the function of the "MODEL" section when creating a data model rule?

Options:

A.

To make a list of all the relevant fields to be mapped from the logs to XDM


B.

To define the mapping between a single dataset and XDM


C.

To finalize rule definition with all XQL statements


D.

To map log fields to corresponding Cortex XSIAM Data Model (XDM) fields


Expert Solution
Questions # 5:

Which two alert notification options can be configured without creating a playbook? (Choose two.)

Which two alert notification options can be configured without creating a playbook? (Choose two.)

Options:

A.

Pager Duty


B.

Email


C.

Slack


D.

SMS


Expert Solution
Questions # 6:

Which field is automatically mapped from the dataset to the data model when creating a data model rule?

Options:

A.

_event_type


B.

_insert_time


C.

_host_name


D.

_cloud_id


Expert Solution
Questions # 7:

What should be considered when creating a custom incident domain?

Options:

A.

Alert grouping will not apply, but SmartScore will.


B.

Alert grouping will apply, but SmartScore will not.


C.

Alert grouping and SmartScore will not be applied to incidents.


D.

Alert grouping and SmartScore will be applied to incidents.


Expert Solution
Questions # 8:

An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file.

Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?

An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file.

Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?

Options:

A.

Install a Broker VM in the environment, and configure the CSV Collector to collect the files of interest.


B.

Install a Cortex XDR agent on the Ubuntu server, and configure the agent to collect the files of interest.


C.

Install a Broker VM in the environment, and migrate the application to the Broker VM.


D.

Install XDR Collector on the Ubuntu server, and configure the agent to collect the files of interest.


Expert Solution
Questions # 9:

Which installer type should be used when upgrading a non-Linux Kubernetes cluster?

Options:

A.

Standalone


B.

Helm


C.

Upgrade from ESM


D.

Kubernetes


Expert Solution
Questions # 10:

How must Cloud Identity Engine be deployed and activated on Cortex XSIAM?

Options:

A.

In a different region than Cortex XSIAM; logs can be verified using pan_dss_raw dataset


B.

In a different region than Cortex XSIAM; logs can be verified using endpoints dataset


C.

In the same region as Cortex XSIAM; logs can be verified using pan_dss_raw dataset


D.

In the same region as Cortex XSIAM; logs can be verified using endpoints dataset


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions