New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks PSE-Cortex Exam - Topic 1 Question 27 Discussion

Actual exam question for Palo Alto Networks's PSE-Cortex exam
Question #: 27
Topic #: 1
[All PSE-Cortex Questions]

Which two types of lOCs are available for creation in Cortex XDR? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A, C

Contribute your Thoughts:

0/2000 characters
Nenita
4 months ago
Not sure about that, sounds off to me.
upvoted 0 times
...
Dorothy
4 months ago
Yup, IP and domain are the go-tos.
upvoted 0 times
...
Iesha
4 months ago
Wait, can you really create a registry entry as an IOC?
upvoted 0 times
...
Caren
4 months ago
Definitely endpoint hostname too!
upvoted 0 times
...
Renea
4 months ago
I think it's IP and domain.
upvoted 0 times
...
Shala
5 months ago
I’m leaning towards IP and registry entry, but I might be mixing it up with another topic.
upvoted 0 times
...
Emilio
5 months ago
I practiced a question similar to this, and I think registry entry was not one of the correct answers.
upvoted 0 times
...
Scarlet
5 months ago
I'm not completely sure, but I feel like endpoint hostname could be one of the options too.
upvoted 0 times
...
Whitley
5 months ago
I think I remember that IP and domain were mentioned in the study materials as types of lOCs.
upvoted 0 times
...
Marvel
5 months ago
Okay, let's think this through. The tester needs to remove any evidence of their presence, so the spawned shells and server logs are definitely important. I'd also say the ARP cache should be cleared to hide network activity.
upvoted 0 times
...
Madonna
5 months ago
This looks like a tricky question, but I think I can handle it. I'll need to carefully read through the options and think about the key actions required to configure the solution.
upvoted 0 times
...
Letha
5 months ago
Hmm, this one seems tricky. I'll need to carefully review the Audience subtab options to figure out which one is the default for a public Saved Search.
upvoted 0 times
...

Save Cancel