What is required to enable ingestion of on-premises firewall logs into Cortex XDR?
What are the primary functions of the Causality Analysis Engine in Cortex XDR?
Which SOC role investigates a new low severity alert? (Choose one answer)
Which activities are facilitated through the War Room in Cortex XSOAR? (Choose one answer)
What is the function of a Causality View?
How does the "Unit 42 Intel" integration directly assist a SOC analyst within the Cortex XDR or XSIAM Incident view?
Which solution will minimize mean time to resolution (MTTR) when, as a result of previous malware infection, a company’s Windows endpoint is suffering a small amount of file corruption and modified registry keys?
What is the primary objective of a "Tier 1" analyst during the triage process?
Where can an administrator begin to grant a new non-SSO user access to a Cortex XDR tenant? (Choose one answer)
Which statement explains the difference between the Cortex Identity Threat Detection and Response (ITDR) module and Identity Analytics in Cortex XSIAM?
In the MITRE ATT & CK framework, which term describes the specific high-level "Why" or goal of an attacker, such as "Initial Access" or "Exfiltration"?
What is the role of content packs in Cortex XSOAR?
What is enabled by Role-Based Access Control (RBAC) in Cortex XDR?
Which protocol is commonly used by Cortex XSOAR to automatically pull threat intelligence indicators from external TAXII servers?
Which two statements are relevant to reports in Cortex XDR? (Choose two.)
Which two steps belong in the Cortex XSOAR incident lifecycle? (Choose two.)
Which dashboard or module in Cortex XSIAM provides visibility into unmanaged devices, unauthorized shadow IT, and cloud assets that do not currently have a Cortex agent installed?
Which two types of tasks are supported in Cortex XSIAM playbooks? (Choose two answers)