What happens when the XDR Collector is uninstalled from an endpoint by using the Cortex XDR console?
Correct Answer: C
When you initiate an uninstallation of an agent or collector from the Cortex XDR management console, the action follows an asynchronous lifecycle:
Next Heartbeat Execution: The cloud management console cannot instantly force changes down to an endpoint. Instead, it creates a pending action. The next time the endpoint checks in with the cloud (its heartbeat communication), it receives the uninstallation command and executes it locally.
Console Status Change: Once the uninstallation is successfully completed and reported back, the endpoint's status in the console updates to Uninstalled.
Data Retention Window: To prevent permanent accidental data loss and to allow administrators time to audit or re-enroll the asset, Cortex XDR retains the machine's configuration data and historic telemetry metadata in the database for a standard buffer period of 90 days before completely purging it.