exam questions

Exam PSE-Cortex All Questions

View all questions & answers for the PSE-Cortex exam

Exam PSE-Cortex topic 1 question 60 discussion

Actual exam question from Palo Alto Networks's PSE-Cortex
Question #: 60
Topic #: 1
[All PSE-Cortex Questions]

What is a benefit of user entity behavior analytics (UEBA) over security information and event management (SIEM)?

  • A. SIEMs supports only agentless scanning, not agent-based workload protection across VMs, containers/Kubernetes.
  • B. UEBA can add trusted signers of Windows or Mac processes to a whitelist in the Endpoint Security Manager (ESM) Console.
  • C. SIEMs have difficulty detecting unknown or advanced security threats that do not involve malware, such as credential theft.
  • D. UEBA establishes a secure connection in which endpoints can be routed, and it collects and forwards logs and files for analysis.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DargorPT
3 weeks ago
Selected Answer: C
C is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...