Loading questions...
Updated
In incident-related widgets, how would you filter the display to only show incidents that were “starred”?
Where would you view the WildFire report in an incident?
What does the following output tell us?
Which engine, of the following, in Cortex XDR determines the most relevant artifacts in each alert and aggregates all alerts related to an event into an incident?
Which type of BIOC rule is currently available in Cortex XDR?
In Windows and macOS you need to prevent the Cortex XDR Agent from blocking execution of a file based on the digital signer. What is one way to add an exception for the singer?
As a Malware Analyst working with Cortex XDR you notice an alert suggesting that there was a prevented attempt to download Cobalt Strike on one of your servers. Days later, you learn about a massive ongoing supply chain attack. Using Cortex XDR you recognize that your server was compromised by the attack and that Cortex XDR prevented it. What steps can you take to ensure that the same protection is extended to all your servers?
Which statement is true based on the following Agent Auto Upgrade widget?
What is the purpose of targeting software vendors in a supply-chain attack?
When creating a BIOC rule, which XQL query can be used?
What is the standard installation disk space recommended to install a Broker VM?
Where can SHA256 hash values be used in Cortex XDR Malware Protection Profiles?
How does Cortex XDR agent for Windows prevent ransomware attacks from compromising the file system?
What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?
In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?
When is the wss (WebSocket Secure) protocol used?
With a Cortex XDR Prevent license, which objects are considered to be sensors?
Create a free account to unlock all questions for this exam.
Log In / Sign UpPhishing belongs which of the following MITRE ATT&CK tactics?
When viewing the incident directly, what is the “assigned to” field value of a new Incident that was just reported to Cortex?