최신 Palo Alto Networks Certification XSIAM-Analyst 무료샘플문제:
1. You're investigating a compromised device and want to perform remote forensics. Which live terminal options would be effective?
(Choose two)
Response:
A) Retrieve registry hives
B) Enable USB ports
C) Run endpoint file retrieval
D) Deactivate local firewall
2. What is the primary benefit of using playbooks in Cortex XSIAM for incident response?
Response:
A) To manually document investigation steps
B) To score alerts manually
C) To automate repetitive analyst tasks and responses
D) To create static alert profiles
3. Matching - ASM Use Case to Feature
Use Case
A) Identify exposed CVEs
B) Review vulnerable asset details
C) Investigate active threat paths
D) Monitor evolving service risks
Feature
1. Attack surface rules
2. Asset inventory
3. Threat response center
4. Continuous ASM scans
Response:
A) A-1, B-4, C-3, D-2
B) A-4, B-2, C-3, D-1
C) A-1, B-3, C-2, D-4
D) A-1, B-2, C-3, D-4
4. An analyst is investigating suspicious lateral movement. Which two types of forensic evidence are most helpful?
Response:
A) Browser cache
B) Font configuration files
C) Remote login event logs
D) PowerShell command history
5. You notice a sudden spike in alerts from multiple endpoints. Cortex XSIAM automatically creates an incident. What are the two most likely factors that triggered this?
Response:
A) Predefined incident scoring threshold
B) Aggregated alerts with common indicators
C) Matching a high-priority threat intelligence feed
D) Manual case creation by analyst
질문과 대답:
질문 # 1 정답: A,C | 질문 # 2 정답: C | 질문 # 3 정답: D | 질문 # 4 정답: C,D | 질문 # 5 정답: B,C |