Winter Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

PCDRA Questions and Answers

Question # 6

What does the following output tell us?

A.

There is one lowseverity incident.

B.

Host shpapy_win10 had the most vulnerabilities.

C.

There is one informational severity alert.

D.

This is an actual output of the Top 10 hosts with the most malware.

Full Access
Question # 7

When creating a BIOC rule, which XQL query can be used?

A.

dataset = xdr_data

| filterevent_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

B.

dataset = xdr_data

| filter event_type = PROCESS and

event_sub_type = PROCESS_START and

action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

C.

dataset = xdr_data

| filter action_process_image_name ~= ".*?\.(?:pdf|docx)\.exe"

| fields action_process_image

D.

dataset = xdr_data

| filter event_behavior = true

event_sub_type = PROCESS_START and

action_process_image_name ~=".*?\.(?:pdf|docx)\.exe"

Full Access
Question # 8

What is the purpose of the Cortex Data Lake?

A.

a local storage facility where your logs and alert data can be aggregated

B.

a cloud-based storage facility where your firewall logs are stored

C.

the interface between firewalls and the Cortex XDR agents

D.

the workspace for your Cortex XDR agents to detonate potential malware files

Full Access
Question # 9

Network attacks follow predictable patterns. If you interfere withany portion of this pattern, the attack will be neutralized. Which of the following statements is correct?

A.

Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the firewall.

B.

Cortex XDR Analytics does not interfere with the pattern as soon as it is observed on the endpoint.

C.

Cortex XDR Analytics does not have to interfere with the pattern as soon as it is observed on the endpoint in order to prevent the attack.

D.

Cortex XDR Analytics allows to interfere with the pattern as soon as it is observed on the endpoint.

Full Access