XSIAM-Engineer Exam Question 21
Using the integrationContext object, how is data stored and retrieved between integration command runs in Cortex XSIAM?
XSIAM-Engineer Exam Question 22
Cortex XSIAM has not received any logs for 30 minutes from a Palo Alto Networks NGFW named
"MainFW." An engineer wants to create an alert for this scenario.
Correlation rule settings include:
- Time Schedule: Every 30 minutes
- Query Timeframe: 30 minutes
- Action: Generate alert
- Alert Name: No logs received from MainFW in the past 30 minutes
Which query should be used in the correlation rule?
"MainFW." An engineer wants to create an alert for this scenario.
Correlation rule settings include:
- Time Schedule: Every 30 minutes
- Query Timeframe: 30 minutes
- Action: Generate alert
- Alert Name: No logs received from MainFW in the past 30 minutes
Which query should be used in the correlation rule?
XSIAM-Engineer Exam Question 23
A CISO has asked an engineer to create a custom dashboard in Cortex XSIAM that can be filtered to show incidents assigned to a specific user.
Which feature should be used to filter the incident data in the dashboard?
Which feature should be used to filter the incident data in the dashboard?
XSIAM-Engineer Exam Question 24
A Behavioral Threat Protection (BTP) alert is triggered with an action of "Prevented (Blocked)" on one of several application servers running Windows Server 2022. The investigation determines the involved processes to be legitimate core OS binaries, and the description from the triggered BTP rule is an acceptable risk for the company to allow the same activity in the future.
This type of activity is only expected on the endpoints that are members of the endpoint group
"AppServers," which already has a separate prevention policy rule with an exceptions profile named "Exceptions-AppServers" and a malware profile named "Malware-AppServers." The CGO that was terminated has the following properties:
- SHA256:
eb71ea69dd19f728ab9240565e8c7efb59821e19e3788e289301e1e74940c208
- File path: C:\Windows\System32\cmd.exe
- Digital Signer: Microsoft Corporation
How should the exception be created so that it is scoped as narrowly as possible to minimize the security gap?
This type of activity is only expected on the endpoints that are members of the endpoint group
"AppServers," which already has a separate prevention policy rule with an exceptions profile named "Exceptions-AppServers" and a malware profile named "Malware-AppServers." The CGO that was terminated has the following properties:
- SHA256:
eb71ea69dd19f728ab9240565e8c7efb59821e19e3788e289301e1e74940c208
- File path: C:\Windows\System32\cmd.exe
- Digital Signer: Microsoft Corporation
How should the exception be created so that it is scoped as narrowly as possible to minimize the security gap?
XSIAM-Engineer Exam Question 25
An engineer needs to migrate Cortex XDR agents without internet connection from Cortex XSIAM tenant A to Cortex XSIAM tenant B.
There is a broker configured for each tenant. This is the communication flow:
XDR agents <-> Broker A <-> XSIAM tenant A
XDR agents <-> Broker B <-> XSIAM tenant B
Which two steps should be taken before moving the agents? (Choose two.)
There is a broker configured for each tenant. This is the communication flow:
XDR agents <-> Broker A <-> XSIAM tenant A
XDR agents <-> Broker B <-> XSIAM tenant B
Which two steps should be taken before moving the agents? (Choose two.)
