Question 16

What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?
  • Question 17

    When using the "File Search and Destroy" feature, which of the following search hash type is supported?
  • Question 18

    While working the alerts involved in a Cortex XDR incident, an analyst has found that every alert in this incident requires an exclusion. What will the Cortex XDR console automatically do to this incident if all alerts contained have exclusions?
  • Question 19

    In the deployment of which Broker VM applet are you required to install a strong cipher SHA256-based SSL certificate?
  • Question 20

    Which of the following represents the correct relation of alerts to incidents?