
Apr-2023 Latest Dumpexams PCDRA Exam Dumps with PDF and Exam Engine Free Updated Today!
Following are some new PCDRA Real Exam Questions!
NEW QUESTION 11
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to open a malicious Word document. You learn from the WildFire report and AutoFocus that this document is known to have been used in Phishing campaigns since 2018. What steps can you take to ensure that the same document is not opened by other users in your organization protected by the Cortex XDR agent?
- A. Enable DLL Protection on all endpoints but there might be some false positives.
- B. No step is required because Cortex shares IOCs with our fellow Cyber Threat Alliance members.
- C. Create Behavioral Threat Protection (BTP) rules to recognize and prevent the activity.
- D. No step is required because the malicious document is already stopped.
Answer: C
NEW QUESTION 12
Which of the following is an example of a successful exploit?
- A. identifying vulnerable services on a server.
- B. executing a process executable for well-known and signed software.
- C. connecting unknown media to an endpoint that copied malware due to Autorun.
- D. a user executing code which takes advantage of a vulnerability on a local service.
Answer: A
NEW QUESTION 13
Which license is required when deploying Cortex XDR agent on Kubernetes Clusters as a DaemonSet?
- A. Cortex XDR Pro per Endpoint
- B. Cortex XDR Pro per TB
- C. Host Insights
- D. Cortex XDR Cloud per Host
Answer: D
NEW QUESTION 14
To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
- A. threat_event
- B. causality_chain
- C. event_type
- D. endpoint_name
Answer: C
NEW QUESTION 15
What is the purpose of targeting software vendors in a supply-chain attack?
- A. to take advantage of a trusted software delivery method.
- B. to access source code.
- C. to steal users' login credentials.
- D. to report Zero-day vulnerabilities.
Answer: C
NEW QUESTION 16
Phishing belongs which of the following MITRE ATT&CK tactics?
- A. Reconnaissance, Initial Access
- B. Persistence, Command and Control
- C. Reconnaissance, Persistence
- D. Initial Access, Persistence
Answer: A
NEW QUESTION 17
Which type of BIOC rule is currently available in Cortex XDR?
- A. Discovery
- B. Threat Actor
- C. Network
- D. Dropper
Answer: D
NEW QUESTION 18
What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?
- A. Netflow Collector
- B. DB Collector
- C. Syslog Collector
- D. Pathfinder
Answer: C
NEW QUESTION 19
Live Terminal uses which type of protocol to communicate with the agent on the endpoint?
- A. WebSocket
- B. NetBIOS over TCP
- C. TCP, over port 80
- D. UDP and a random port
Answer: A
NEW QUESTION 20
In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?
- A. Agent Proxy
- B. CSV Collector
- C. Agent Installer and Content Caching
- D. Syslog Collector
Answer: C
NEW QUESTION 21
An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?
- A. Hot Patch Protection
- B. DDL Security
- C. Kernel Integrity Monitor (KIM)
- D. Dylib Hijacking
Answer: D
Explanation:
Reference:
%20process
NEW QUESTION 22
When is the wss (WebSocket Secure) protocol used?
- A. when the Cortex XDR agent downloads new security content
- B. when the Cortex XDR agent uploads alert data
- C. when the Cortex XDR agent connects to WildFire to upload files for analysis
- D. when the Cortex XDR agent establishes a bidirectional communication channel
Answer: D
NEW QUESTION 23
Which profiles can the user use to configure malware protection in the Cortex XDR console?
- A. Malware profile
- B. Malware Protection profile
- C. Malware Detection profile
- D. Anti-Malware profile
Answer: A
NEW QUESTION 24
Which statement best describes how Behavioral Threat Protection (BTP) works?
- A. BTP uses machine Learning to recognize malicious activity even if it is not known.
- B. BTP runs on the Cortex XDR and distributes behavioral signatures to all agents.
- C. BTP injects into known vulnerable processes to detect malicious activity.
- D. BTP matches EDR data with rules provided by Cortex XDR.
Answer: A
NEW QUESTION 25
Which of the following policy exceptions applies to the following description?
'An exception allowing specific PHP files'
- A. Support exception
- B. Process exception
- C. Local file threat examination exception
- D. Behavioral threat protection rule exception
Answer: C
NEW QUESTION 26
What is by far the most common tactic used by ransomware to shut down a victim's operation?
- A. preventing the victim from being able to access APIs to cripple infrastructure
- B. restricting access to administrative accounts to the victim
- C. encrypting certain files to prevent access by the victim
- D. denying traffic out of the victims network until payment is received
Answer: C
NEW QUESTION 27
When creating a scheduled report which is not an option?
- A. Run daily at a certain time (selectable hours and minutes).
- B. Run weekly on a certain day and time.
- C. Run monthly on a certain day and time.
- D. Run quarterly on a certain day and time.
Answer: D
NEW QUESTION 28
Which module provides the best visibility to view vulnerabilities?
- A. Device Control Violations module
- B. Forensics module
- C. Live Terminal module
- D. Host Insights module
Answer: D
Explanation:
Host Insights, an add-on module for Cortex XDR, combines vulnerability assessment, application and system visibility, and a powerful Search and Destroy feature to help you identify and contain threats. Vulnerability Assessment provides you real-time visibility into vulnerability exposure and current patch levels across your end-points. Host inventory presents detailed information about your host applications and settings whileSearch and Destroy lets you swiftly find and eradicate threats across all endpoints. Host Insights offers a holistic approach to endpoint visibility and attack containment, helping reduce your exposure to threats so you can avoid future breached.
NEW QUESTION 29
Which Type of IOC can you define in Cortex XDR?
- A. destination port
- B. full path
- C. e-mail address
- D. App-ID
Answer: B
NEW QUESTION 30
What is the standard installation disk space recommended to install a Broker VM?
- A. 1GB disk space
- B. 2GB disk space
- C. 256GB disk space
- D. 512GB disk space
Answer: D
NEW QUESTION 31
When creating a custom XQL query in a dashboard, how would a user save that XQL query to the Widget Library?
- A. This isn't supported, you have to exit the dashboard and go into the Widget Library first to create it.
- B. Click the three dots on the widget and then choose "Save" and this will link the query to the Widget Library.
- C. Click on "Save to Widget Library" in the dashboard and you will be prompted to give the query a name and description.
- D. Click on "Save to Action Center" in the dashboard and you will be prompted to give the query a name and description.
Answer: C
NEW QUESTION 32
In incident-related widgets, how would you filter the display to only show incidents that were "starred"?
- A. Create a custom XQL widget
- B. This is not currently supported
- C. Click the star in the widget
- D. Create a custom report and filter on starred incidents
Answer: C
Explanation:
Reference:
%20you%20clear%20the%20star
NEW QUESTION 33
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
- A. SHA256 hashes cannot be used in Cortex XDR Malware Protection Profiles
- B. in the macOS Malware Protection Profile to indicate allowed signers
- C. in the Linux Malware Protection Profile to indicate allowed Java libraries
- D. in the Windows Malware Protection Profile to indicate allowed executables
Answer: D
NEW QUESTION 34
......
Resources From:
- 2023 Latest Dumpexams PCDRA Exam Dumps (PDF & Exam Engine) Free Share: https://pdftorrent.dumpexams.com/PCDRA-vce-torrent.html
Free Resources from Dumpexams, We Devoted to Helping You 100% Pass All Exams!