Palo Alto Networks
PSE-Endpoint-Associate
Q1:
In the Traps product, what does the term ''Service Protection'' mean?
○
A
the protection of a specified process○
B
the ability of one ESM Server to take over for another○
C
the protection of a process running on a Windows Server system○
D
the ability of the Traps agent to make itself tamper-proof
Palo Alto Networks
PSE-Endpoint-Associate
Q2:
A user receives an email that has piece of malware as an attachment. Choose the true statement.
○
A
The piece of malware can work only if a corresponding application is on the user's system.○
B
The piece of malware can do damage only if it makes a connection to a command-and-control server.○
C
The piece of malware can work only if it begins with a buffer overflow.○
D
The piece of malware can work only if the user opens the attachment.
Palo Alto Networks
PSE-Endpoint-Associate
Q3:
Which three file types will be uploaded automatically to WildFire for examination? (Choose three.)
☐
A
Application data files that trigger preventions☐
B
Executables with no previous verdict in the ESM deployment☐
C
Executables with a verdict overridden by the administrator☐
D
Executables allowed to run because their publisher is trusted☐
E
Executables allowed to run by local analysis☐
F
Application data files opened by the end user
Palo Alto Networks
PSE-Endpoint-Associate
Q4:
What can a Traps content update include? (Choose three.)
☐
A
New EPMs☐
B
Updates to the local-analysis model☐
C
New trusted root certificates☐
D
New default policy rules☐
E
New trusted publishers☐
F
New Traps endpoint drivers
Palo Alto Networks
PSE-Endpoint-Associate
Q5:
Which two statements about Local Analysis are true? (Choose two.)
☐
A
Traps endpoint agents build a local analysis model based on the executables they detect.☐
B
Local analysis is called to validate all verdicts on executable files before the files are allowed to run.☐
C
Palo Alto Networks uses machine-learning techniques in its labs to build the local analysis model.☐
D
Local analysis is called whenever an executable file would otherwise get an Unknown or No Connection verdict.