What is required to enable ingestion of on-premises firewall logs into Cortex XDR?
An administrator needs to prevent users from connecting unauthorized USB flash drives to their corporate workstations to reduce the risk of data exfiltration. Which Cortex XDR feature should be configured?
Which action should an administrator take to create automated response actions when a user account is compromised? (Choose one answer)
In the MITRE ATT & CK framework, which term describes the specific high-level "Why" or goal of an attacker, such as "Initial Access" or "Exfiltration"?
Which two types of tasks are supported in Cortex XSIAM playbooks? (Choose two.)
Which process in Cortex XSIAM ensures that raw logs from different vendors (e.g., Check Point, Cisco, and Microsoft) are converted into a standardized format for unified analysis?
How does the "Unit 42 Intel" integration directly assist a SOC analyst within the Cortex XDR or XSIAM Incident view?
What is the Cortex XSOAR Marketplace?
Which two types of content can be installed or upgraded through a Cortex XSIAM content pack? (Choose two.)
What can be used to triage and determine if an artifact in Cortex XDR is malicious? (Choose one answer)
Which Cortex XSIAM component uses machine learning to automatically build a baseline of "normal" behavior for every user and host in the network, and then provides a searchable profile of their historical activity and risk level?
Which dashboard or module in Cortex XSIAM provides visibility into unmanaged devices, unauthorized shadow IT, and cloud assets that do not currently have a Cortex agent installed?
Where in Cortex XSOAR are analysts able to collaborate and converse with others for joint real-time investigations?
What is the primary objective of a "Tier 1" analyst during the triage process?
A company has a highly segmented network where the Cortex XSOAR server cannot directly communicate with an on-premises mail server. Which component should be deployed in the mail server's segment to facilitate integration?
Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
Which two statements are relevant to reports in Cortex XDR? (Choose two.)