<< Prev Question Next Question >>

Question 18/38

Which two log types should be configuredfor firewall forwarding to the Cortex Data Lake for use by Cortex XDR?(Choose two)

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (38q)
Question 1: If a customer activates a TMS tenant and has not purchased a...
Question 2: Which option is required to prepare the VDI Golden Image?...
Question 3: Which CLI query would bring back Notable Events from Splunk?...
Question 4: The certificate used for decryption was installed as a trust...
Question 5: What are two manual actions allowed on War Room entries? (Ch...
Question 6: Which deployment type supports installation of an engine on ...
Question 7: A customer wants to modify the retention periods of their Th...
Question 8: In Cortex XDR Prevent, which three matching criteria can be ...
Question 9: How can you view all the relevant incidents for an indicator...
Question 10: What is the retention requirement for Cortex Data Lake sizin...
Question 11: In the DBotScore context field, which context key would diff...
Question 12: Which task allows the playbook to follow different paths bas...
Question 13: An adversary is attempting to communicate with malware runni...
Question 14: Which two filter operators are available in Cortex XDR? (Cho...
Question 15: Which Cortex XDR Agent capability prevents loading malicious...
Question 16: An administrator has a critical group of systems running Win...
Question 17: In Cortex XDR Prevent, which three matching criteria can be ...
Question 18: Which two log types should be configuredfor firewall forward...
Question 19: The certificate used for decryption was installed as a trust...
Question 20: Which two items are stitched to the Cortex XDR causality cha...
Question 21: The customer has indicated they need EDR data collection cap...
Question 22: How do sub-playbooks affect the Incident Context Data?...
Question 23: What are process exceptions used for?...
Question 24: A prospect has agreed to do a 30-day POC and asked to integr...
Question 25: Which Cortex XDR capability extends investigations to an end...
Question 26: An administrator of a Cortex XDR protected production enviro...
Question 27: The images show two versions of the same automation script a...
Question 28: What are two manual actions allowed on War Room entries? (Ch...
Question 29: If you have a playbook task that errors out. where could you...
Question 30: An EDR project was initiated by a CISO. Which resource will ...
Question 31: How many use cases should a POC success criteria document in...
Question 32: Which two items are stitched to the Cortex XDR causality cha...
Question 33: An Administrator is alerted to a Suspicious Process Creation...
Question 34: How does an "inline" auto-extract task affect playbook execu...
Question 35: In an Air-Gapped environment where the Docker package was ma...
Question 36: The prospect is deciding whether to go with a phishing or a ...
Question 37: A General Purpose Dynamic Section can be added to which two ...
Question 38: Which step is required to prepare the VDI Golden Image?...