Cortex Practice Questions
Prepare for PSE-CORTEX with more than an answer.
- Exam fee
- $250 USD
- Time limit
- 80 minutes
- Questions on the exam
- 60
- Passing score
- Not publicly disclosed (scale Not publicly disclosed)
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 4
- Business Value and Competitive Differentiators27%
- Architecture and Planning38%
- Demonstration and Evaluation20%
- Deployment/Implementation Best Practices15%
- 1
A systems engineer is preparing a demo environment to showcase Cortex XDR's investigation capabilities. To tell a compelling story, the engineer needs to simulate a 'living-off-the-land' attack where an adversary uses PowerShell to perform reconnaissance. Which feature within Cortex XDR is best suited to manually execute this test script on a target endpoint for the demo?
Show answer details
Correct answer: B
Live Terminal is the correct feature for this purpose. It provides a remote shell (Command Prompt on Windows, bash on Linux/macOS) directly to the endpoint from the Cortex XDR console. The engineer can use this session to execute the PowerShell reconnaissance script, which will then trigger the appropriate behavioral alerts in XDR. This allows for a controlled and effective demonstration of XDR's detection and investigation capabilities for fileless attacks.
- 2
A customer has successfully deployed Cortex XSOAR and has automated several key incident response processes. They now want to measure the ROI of the platform. The 'Saved by Dbot' widget shows a time savings of 400 hours over the last quarter. If the average fully-loaded cost of a SOC analyst is $75/hour, what is the calculated cost savings for the quarter?
Show answer details
Correct answer: B
The calculation is a straightforward multiplication of the time saved by the analyst's hourly cost. 400 hours * $75/hour = $30,000. This is a direct measure of the operational expense savings achieved through automation with Cortex XSOAR.
- 3
When designing a playbook in Cortex XSOAR, an engineer needs to perform the same sequence of three tasks (e.g., check indicator reputation, tag indicator, create a note) on a list of multiple IP addresses found in an incident. What is the most efficient and scalable method to implement this logic?
Show answer details
Correct answer: B
The best practice for executing a set of repetitive tasks on a list of items is to use a looping sub-playbook. The three tasks are built into a sub-playbook. In the main playbook, this sub-playbook is called and configured with the 'For each input' loop setting, using the array of IP addresses as the input. This creates a clean, reusable, and scalable design, avoiding cluttered and unmanageable main playbooks.
- 4
A customer is implementing Cortex XDR and has a business-critical, internally developed application that exhibits unusual process behavior, causing it to be frequently flagged by the Behavioral Threat Protection module. What is the recommended best practice to prevent false positives without broadly disabling protection?
Show answer details
Correct answer: C
The best practice is to create the most specific and targeted exception possible. Directly from the alert generated by the Behavioral Threat Protection (BTP) module, an administrator can create an exception. This exception should be scoped to the specific BTP rule that is firing, the application's process path/signer, and applied only to the group of endpoints that run this application. This approach resolves the false positive issue while maintaining maximum security visibility and protection for all other activities on those endpoints.
- 5
An organization is deploying Cortex XDR agents to servers in a secure, isolated network segment that has no direct internet access. To ensure agents can receive policy updates and send security event data to the Cortex XDR tenant, what architectural component must be deployed?
graph TD subgraph Cloud["Cortex XDR Tenant"] XDR_Console[Console] end subgraph DMZ Proxy[Broker VM] end subgraph IsolatedNetwork["Isolated Segment"] Server1[Server 1] Server2[Server 2] Server3[Server 3] end Internet((Internet)) --> Proxy Proxy --> XDR_Console Server1 --> Proxy Server2 --> Proxy Server3 --> ProxyShow answer details
Correct answer: C
The Cortex XDR Broker VM is designed specifically for this use case. It acts as a secure proxy and message broker for agents in isolated or air-gapped networks. The agents are configured to communicate with the Broker VM, which then forwards their data to the Cortex XDR cloud tenant and relays policy updates back to the agents. This allows for full agent functionality without requiring direct internet access from each protected server.
- 6
A global financial institution is planning a Cortex XSOAR deployment to serve three distinct regional SOCs (AMER, EMEA, APAC), each with its own regulatory and data sovereignty requirements. The goal is to maintain centralized playbook management and threat intelligence sharing while ensuring that incident data from one region is not accessible by analysts in another. Which architectural design best meets these requirements?
Show answer details
Correct answer: C
The optimal solution is to use XSOAR's multi-tenancy feature. A main (master) tenant can be used for central content management (playbooks, integrations) and threat intelligence, which can then be propagated to the child tenants. Each regional SOC operates within its own child tenant, ensuring strict data isolation and meeting sovereignty requirements. RBAC alone on a single instance does not provide true data segregation. Fully separate instances create significant management overhead for content synchronization.
- 7
A prospective customer is comparing Cortex XDR to a traditional EDR solution that relies solely on signature-based and known-indicator-of-compromise (IOC) detection. To highlight the superiority of Cortex XDR, which feature should a systems engineer emphasize as the primary differentiator for detecting novel, fileless attacks?
Show answer details
Correct answer: B
While WildFire is a powerful tool, it is primarily for file-based threats. Fileless attacks, such as living-off-the-land techniques, do not involve traditional malware files. The key differentiator for Cortex XDR in this context is its Behavioral Threat Protection engine. This engine analyzes chains of events (causality) and uses machine learning to detect anomalous behaviors indicative of an attack, even when no single event or file is inherently malicious. This is crucial for identifying sophisticated, fileless techniques that evade signature and IOC-based detection.
- 8
During a Proof of Value (POV) for Cortex XSOAR, a customer wants to automate the response to a high-fidelity phishing alert from their email security gateway. The agreed-upon success criterion is: "Automatically detonate suspicious URLs in a sandbox, and if malicious, block the URL on the firewall and quarantine the original email." Which TWO XSOAR components are essential to build and validate this specific workflow? (Select TWO)
Show answer details
Correct answer: B, C
To achieve the customer's goal, two core components are necessary. First, you need configured Integrations for each third-party tool involved: the email gateway (to fetch the email), the sandbox (to detonate the URL), and the firewall (to block the URL). Second, you need a Playbook to define the logic and sequence of operations: parse the alert, extract the URL, send it to the sandbox, evaluate the result, and execute conditional actions on the firewall and email gateway. Dashboards and Threat Intelligence Management are valuable but not essential for executing this core automated workflow.
- 9
A systems engineer has completed a successful Cortex XDR deployment for a manufacturing company. The project is now moving into the operational phase. To ensure a smooth transition and long-term customer success, what is the most critical step in the handoff process?
Show answer details
Correct answer: B
The most critical step is the knowledge transfer session. This ensures the customer's operational team fully understands their specific deployment, including the configured security policies, alert investigation procedures, and daily management tasks. This direct engagement is far more effective than just providing documentation or support numbers, as it empowers the customer to successfully manage the solution, leading to higher satisfaction and adoption.
- 10
A university is deploying Cortex XDR across a diverse environment that includes administrative workstations, student computer labs with non-persistent virtual desktops (VDI), and research servers running Linux. To ensure optimal performance and proper data collection, which Cortex XDR agent deployment strategy is most appropriate?
Show answer details
Correct answer: B
This is the correct approach because it uses the appropriate agent type for each environment. The standard Windows agent is for persistent workstations. For non-persistent VDI environments, Cortex XDR has a specific agent and installation method (using the
--vdi_nameflag) designed to be installed on the golden image. This prevents endpoint identity duplication and licensing issues when new desktops are spun up. The standard Linux agent is correct for the research servers.
