ExamGecko
Question list
Search
Search

Question 47 - PCSAE discussion

Report
Export

An engineer’s organization system is registered in the following manner: <SiteName-SystemIDUsername>.

The engineer created a new indicator type for detecting systems using regex. The engineer would now like the username to be created as a separate ‘User’ indicator automatically once a system is found.

What is the most efficient way for the engineer to achieve this?

A.
Create a custom indicator field named ‘username’ and link it to the internal system indicator
Answers
A.
Create a custom indicator field named ‘username’ and link it to the internal system indicator
B.
Change the reputation command for the internal system indicator type
Answers
B.
Change the reputation command for the internal system indicator type
C.
Create a new indicator type of the internal username and set a formatting script to extract only the username
Answers
C.
Create a new indicator type of the internal username and set a formatting script to extract only the username
D.
Create a new indicator type of the internal username and have the regex included on any string that has dash at the beginning
Answers
D.
Create a new indicator type of the internal username and have the regex included on any string that has dash at the beginning
Suggested answer: C

Explanation:

Reference: https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-0/cortex-xsoar-threat-intelmanagement-guide/manage-indicators/understand-indicators/indicator-types/indicator-typeprofile

asked 23/09/2024
Konstantinos Lagoudakis
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first