Paloalto Networks Related Exams
PSE-Cortex Exam

An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?
When initiated, which Cortex XDR capability allows immediate termination of the process-or entire process tree-on an anomalous process discovered during investigation of a security event?
An Administrator is alerted to a Suspicious Process Creation security event from multiple users.
The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )