Administrators from Building 3 were added to Cortex XSIAM to perform limited functions on a subset of endpoints. Custom roles were created and assigned to the administrators to limit their permissions, but their access must also be restricted through the principle of least privilege based on the endpoints they are permitted to manage.
All endpoints belong to an endpoint group named "Building3," and some endpoints might also belong to other endpoint groups.
Which technical control will limit the administrators' ability to manage endpoints outside their area of responsibility while retaining visibility of Building 3's endpoints?
ASBAC enabled in Building 3's IP range with the "EG:Building3" tag assigned to each administrator's scope
BSBAC enabled in Permissive Mode with the "EG:Building3" tag assigned to each administrator's scope
CSBAC enabled in Restrictive Mode with the "EG:Building3" tag assigned to each administrator's scope
DSBAC enabled globally with the "EG:Building3" tag assigned to each administrator's scope
0
Community Discussion
No comments yet. Be the first to start the discussion!
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Before starting a malware scan on a Linux workstation, an engineer observes that the Cortex XDR agent's operational status is reported as "partially protected." No configuration changes have been made from the Cortex XSIAM server.
What are two possible explanations for this operational status?
Choose two
AThe Linux endpoint is currently running 4.0 kernel version.
BThe Linux endpoint's kernel modules failed to load due to unsupported kernel versions.
CThe agent is outdated and requires an upgrade to the latest version to regain full protection.
DThe agent was manually disabled on the endpoint by the user or an administrator.
An application that ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server and logs locally to a .csv file.
Which set of actions enables ingestion of the .csv logs into Cortex XSIAM directly from the server?
AInstall a Broker VM in the environment, and configure the CSV Collector to collect the files of interest.
BInstall a Cortex XDR agent on the Ubuntu server, and configure the agent to collect the files of interest.
CInstall a Broker VM in the environment, and migrate the application to the Broker VM.
DInstall XDR Collector on the Ubuntu server, and configure the agent to collect the files of interest.
What is the principal purpose of the URL https://<region>-docker.pkg.dev within a Palo Alto Networks infrastructure?
AIt downloads Docker content updates.
BIt downloads Kubernetes images for agent installation.
CIt imports Docker licensing.
DIt downloads Engine Docker containers.
Based on the images below, which command allows the context data to display as a table while troubleshooting a playbook task?
An engineer needs to onboard data from a third-party vendor's firewall. Because no content pack is available, the engineer creates a custom data-source integration and parsing rules that generate a dataset containing the firewall data.
How can Cortex XSIAM analytics capabilities be applied to this data?
ACreate a behavioral indicator of compromise (BIOC) rule on the network fields (source IP, source port, target IP, target port, IP protocol).
BCreate a data model rule with network fields mapped (source IP, source port, target IP, target port, IP protocol).
CCreate a correlation rule on the network fields (source IP, source port, target IP, target port, IP protocol).
DCreate a parsing rule and ensure the network fields exist (source IP, source port, target IP, target port, IP protocol).
Which cytool command will look up the policy applied to a Cortex XDR agent?
Acytool adaptive_policy interval 0
Bcytool payload_execution query
Ccytool adaptive_policy recalc
Dcytool persist print agent_settings.db
The following string is the value of a key named Data2 in the context:
Based on the image below, what will be shown in the Test result field when the Test button is clicked?
A1
B"1
C2
D"2
Based on the following _raw_log and XQL query details, what will be the result(s) of temp_value?
A123192.168.10.1
B20
C10.120.80.2
D149.235.219.20859977
Which option should you use when customizing a dashboard in Cortex XSIAM to add a widget that displays data filtered by more than one dynamic value?
AFree text/number
BMulti-select
CFixed filter
DSingle-select
During a new Cortex XSIAM deployment, a user repeatedly encounters session timeouts when attempting to connect to the agent through Live Terminal, although the firewall engineer has confirmed that all source IP addresses, port 443, and destinations are allowed.
What could be responsible for these persistent timeout issues?
AUser does not have administrative privileges on the managed endpoint.
BSSL Decryption is currently being used to inspect the underlying traffic.
CNTP is not synchronized with the server time.
DLive Terminal feature is not supported on the current OS.
Cortex XSIAM has received no logs for 30 minutes from a Palo Alto Networks NGFW named "MainFW." An engineer wants to create an alert for this condition.
Correlation rule settings include:
Time Schedule: Every 30 minutes
Query Timeframe: 30 minutes
Action: Generate alert
Alert Name: No logs received from MainFW in the past 30 minutes
Which query should be used in the correlation rule?
A
B
C
D
A vulnerability analyst asks a Cortex XSIAM engineer to identify assets vulnerable to a newly reported zero-day CVE affecting the ai_app application and versions 12.1, 12.2, 12.4, and 12.5.
Which XQL query provides the required result?
A
B
C
D
Which action prevents automatic extraction of indicators, such as IP addresses and URLs, from a script’s output?
AAdd 'ExtractIndicators': False to the script.
BAdd 'IgnoreAutoExtract': True to the script.
CUse 'AutoExtract': False in the script.
DSet 'IndicatorExtraction': None in the script.
A Cortex XSIAM engineer is creating a playbook that uses reputation commands, such as !ip, to enrich and analyze indicators.
Which statement applies to using reputation commands in this scenario?
AIf no reputation integration instance is configured, the '!ip' command will execute but will return no results.
BReputation commands such as '!ip' will fail if the required reputation integration instance is not configured and enabled.
CThe mapping flow for enrichment commands is disabled if extraction is set to "None."
DEnrichment data will not be saved to the indicator unless the extraction setting is manually configured in the playbook task.
How must Cloud Identity Engine be deployed and activated for Cortex XSIAM?
AIn a different region than Cortex XSIAM; logs can be verified using pan_dss_raw dataset
BIn a different region than Cortex XSIAM; logs can be verified using endpoints dataset
CIn the same region as Cortex XSIAM; logs can be verified using pan_dss_raw dataset
DIn the same region as Cortex XSIAM; logs can be verified using endpoints dataset
A Cortex XDR agent is installed on an endpoint, but it cannot download content updates and has not registered with the Cortex XSIAM server. While troubleshooting the network connection, an engineer determines that this endpoint is intentionally designed without direct internet access to the required network destinations for Cortex XDR agent traffic.
A reachable Broker VM has the Local Agent Settings applet enabled and Agent Proxy configured. The Broker VM details are:
FQDN: crtxbroker01.company.net
Proxy listening port: 8888
How should the engineer configure the Cortex XDR agent to use the existing Broker VM as a proxy for agent network traffic?
Acytool proxy set "crtxbroker01. company.net: 8888"
A sub-playbook is configured to loop using For Each Input. The following inputs are provided to the sub-playbook:
Input x: W,X,Y,Z -
Input y: a,b,c,d -
Input z: 9 -
Which inputs are used for the second iteration of the loop?
Aa,b,c,d
BX,b,9
CX,b
DX,b,c
What is the purpose of the MODEL section when creating a data model rule?
ATo make a list of all the relevant fields to be mapped from the logs to XDM
BTo define the mapping between a single dataset and XDM
CTo finalize rule definition with all XQL statements
DTo map log fields to corresponding Cortex XSIAM Data Model (XDM) fields
An engineer is performing a threat-actor emulation test to identify which Cortex XDR module would protect against or alert on a real-world attack. The initial test was prevented.
Which action must the engineer take to continue the testing?
ARemove the hash from the restrictions profile.
BAdd an indicator exclusion.
CAdd a prevention rule.
DChange the profile from "alert" to "prevent" for the BTP module.
Which common problem can cause an abrupt loss of data ingestion from a data source that had previously been successful?
AData source is using an unsupported data format.
BData source has reached its maximum storage capacity.
CData source has reached its end of life for support.
Community Discussion