PALO ALTO EDU-160 CORTEX XDR
QUESTIONS WITH CORRECT ANSWERS
Which ffentity ffcan ffbe ffidentified ffas ffevery ffimmediate ffchild ffprocess ff(and ffthread) ffof
ffa ffspawner?
A. fffinal ffinstance
B. fffinal ffspawner
C. ffcausality ffinstance
D. ffcausality ffgroup ffowner ff- ffAnswer ffD
Which ffcomponent ffis ffrequired ffin ffagentless ffCortex ffXDR ffdeployments?
A. ffDirectory ffSync ffApp
B. ffPanorama
C. ffPathFinder
D. ffBroker ff- ffAnswer ffC
Which fftactic ffdoes ffCortex ffXDR ffblock ffby ffdetecting ffchanges ffin ffconnectivity
ffpatterns ffsuch ffas ffincreased ffrates ffof ffconnections, fffailed ffconnections, ffand ffport
ffscans?
A. ffdiscovery
B. ffexfiltration
C. fflateral ffmovement
D. ffcommand ffand ffcontrol ff- ffAnswer ffA
Which ffentity ffis ffcreated ffbased ffon ffthe ffresult ffof ffrunning ffa ffquery?
A. ffa fftable
B. ffan ffalert
C. ffan ffincident
D. ffa ffreport ffin ffPDF ff- ffAnswer ffA
Which ffoption ffdescribes ffthe ffattacks ffor ffthreats ffthat ffhave ffalready ffevaded ffnetwork
ffdefenses ffbut ffhaven't ffyet ffdone fftheir fffull ffdamage?
A. ffinsider ffthreats
B. ffpost-intrusion ffthreats
C. ffstealthy ffattacks
D. fffileless ffattacks ff- ffAnswer ffB
, Which ffgenerator ffcan ffappear ffin ffthe ffALERT ffSOURCE fffield ffof ffalerts ffin ffthe
ffmanagement ffconsole?
A. ffPAN ffNGFW
B. ffWildFire
C. ffXDR ffCausality
D. ffAutoFocus ff- ffAnswer ffA
Which ffoption ffcan ffbe ffconsidered ffas ffa ffuse ffcase ffof ffthe ffrule ffexceptions?
A. ffto ffexclude ffthe fflog fffrom ffthe fflog ffstitching
B. ffto ffprevent fffalse ffpositives
C. ffto ffreduce ffnetwork ffcongestion
D. ffto ffcreate ffalerts ffof ffthe ffException fftype ff- ffAnswer ffB
How ffoften ffin ffminutes ffis ffthe ffenhanced ffendpoint ffdata ffuploaded?
A. ff5
B. ff10
C. ff60
D. ff1 ff- ffAnswer ffA
Which fftwo ffoptions ffoccur ffduring ffthe ffCortex ffXDR fflog ffstitching ffprocess? ff(Choose
fftwo.)
A. ffcorrelation
B. ffdetection
C. ffinvestigation
D. ffcausation ff- ffAnswer ffAD
After ffyou ffselect ffa ffnode ffin ffthe ffCI ffchain ffon ffthe ffCausality ffView ffpage, ffwhich fftwo
fftabs ffcan ffyou ffclick? ff(Choose fftwo)
A. ffNETWORK
B. ffPROCESS
C. ffVERDICT
D. ffINSIGHT ff- ffAnswer ffAB
Which ffprofile ffcontains ffthe ffsetting ffto ffenable ffor ffdisable ffthe ffcollection ffof ffenhanced
ffendpoint ffdata?
A. ffexploit
B. ffglobal
C. ffmalware
D. ffagent ffsettings ff- ffAnswer ffD
Which fftwo ffengines ffdoes ffCortex ffXDR ffPro ffper ffendpoint ffhave? ff(Choose fftwo.)
A. ffLog ffStitching
B. ffAnalytics
C. ffCorrelation
D. ffCausality ffAnalysis ff- ffAnswer ffBD
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller LucieLucky. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.99. You're not tied to anything after your purchase.