Question 26

A correlation rule is created to detect potential insider threats by correlating user login events from one dataset with file access events from another dataset. The rule must retain all user login events, even if there are no matching file access events, to ensure no login activity is missed.
text
Copy
dataset = x
| join (dataset = y)
Which type of join is required to maintain all records from dataset x, even if there are no matching events from dataset y?
  • Question 27

    An attacker injects malicious code into a legitimate process to evade traditional signature-based detection mechanisms. Which Cortex XDR capability addresses this technique?
  • Question 28

    A Cortex XDR agent needs to be uninstalled from two Windows machines that are no longer connected to the Cortex XDR tenant.
    The uninstall password for the machines is not known.
    Which set of actions should be taken to resolve this issue?
  • Question 29

    A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)
    [Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
  • Question 30

    Which troubleshooting step should be performed first to determine why logs from a third-party firewall do not appear in Cortex XDR?