Question 31

Which components may be included in a Cortex XDR content update?
  • Question 32

    A Cortex XDR administrator wants to suppress alerts generated by a trusted internal application without creating unnecessary security blind spots. What is recommended?
  • Question 33

    An XDR engineer is creating a correlation rule to monitor login activity on specific systems. When the activity is identified, an alert is created. The alerts are being generated properly but are missing the username when viewed. How can the username information be included in the alerts?
  • Question 34

    What happens when two or more values are specified for a disable prevention rule in Cortex XDR to allow file execution?
  • Question 35

    A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appear as expected. What may be the cause of this behavior?