Before initiating a malware scan action on a Linux workstation, an engineer notices that the Cortex XDR agent's operational status on the workstation is reporting as "partially protected." There have been no configuration changes made from the Cortex XSIAM server.
What are two explanations for this operational status? (Choose two.)
Cortex XSIAM has not received any logs for 30 minutes from a Palo Alto Networks NGFW named "MainFW.” An engineer wants to create an alert for this scenario.
Correlation rule settings include:
Time Schedule: Every 30 minutes
Query Timeframe: 30 minutes
Action: Generate alert
Alert Name: No logs received from MainFW in the past 30 minutes
Which query should be used in the correlation rule?
A)
B)
C)
D)
A Cortex XSIAM engineer is developing a playbook that uses reputation commands such as '!ip' to enrich and analyze indicators.
Which statement applies to the use of reputation commands in this scenario?
Which cytool command will look up the policy being applied to a Cortex XDR agent?
What is the reason all Broker VM options are greyed out when a user attempts to select a Broker VM as a download source in the Agent Settings profile?
An engineer needs to migrate Cortex XDR agents without internet connection from Cortex XSIAM tenant A to Cortex XSIAM tenant B. There is a broker configured for each tenant. This is the communication flow:
XDR agents <-> Broker A <-> XSIAM tenant A
XDR agents <-> Broker B <-> XSIAM tenant B
Which two steps should be taken before moving the agents? (Choose two.)
A file for a support exception that needs to be updated locally on a Linux endpoint has been supplied.
Which cytool command will upload this support exception file to the endpoint?
In the Incident War Room, which command is used to update incident fields identified in the incident layout?
Which two alert notification options can be configured without creating a playbook? (Choose two.)
Which two alert notification options can be configured without creating a playbook? (Choose two.)
Based on the _raw_log and XQL query information below, what will be the result(s) of the temp_value?
Which type of parsing error is categorized in the dataset "parsing_rules_errors"?
Which common issue can result in sudden data ingestion loss for a data source that was previously successful?
Based on the image below, which statement applies to the ability to remove tabs when creating a new alert layout?