Question 1

What should you do to automatically convert leads into alerts after investigating a lead?
  • Question 2

    What is by far the most common tactic used by ransomware to shut down a victim's operation?
  • Question 3

    Cortex XDR is deployed in the enterprise and you notice a cobalt strike attack via an ongoing supply chain compromise was prevented on 1 server. What steps can you take to ensure the same protection is extended to all your servers?
  • Question 4

    What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?
  • Question 5

    An attacker tries to load dynamic libraries on macOS from an unsecure location. Which Cortex XDR module can prevent this attack?