Question 36
A security audit determines that the Windows Cortex XDR host-based firewall is not blocking outbound RDP connections for certain remote workers. The audit report confirms the following:
* All devices are running healthy Cortex XDR agents.
* A single host-based firewall rule to block all outbound RDP is implemented.
* The policy hosting the profile containing the rule applies to all Windows endpoints.
* The logic within the firewall rule is adequate.
* Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.
* Network location configuration in Agent Settings is enabled on all Windows endpoints.What is the likely reason the RDP connections are not being blocked?
* All devices are running healthy Cortex XDR agents.
* A single host-based firewall rule to block all outbound RDP is implemented.
* The policy hosting the profile containing the rule applies to all Windows endpoints.
* The logic within the firewall rule is adequate.
* Further testing concludes RDP is successfully being blocked on all devices tested at company HQ.
* Network location configuration in Agent Settings is enabled on all Windows endpoints.What is the likely reason the RDP connections are not being blocked?
Question 37
An XDR Collector is deployed onto the endpoint to collect logs for ingestion from a custom application running on a Linux endpoint, but the endpoint is not protected. How can protection be added to the endpoint?
Question 38
An engineer wants to automate the handling of alerts in Cortex XDR and defines several automation rules with different actions to be triggered based on specific alert conditions. Some alerts do not trigger the automation rules as expected. Which statement explains why the automation rules might not apply to certain alerts?
Question 39
An incident is generated from a local analysis malware alert involving install_dependencies.exe.
The hash of the same file now shows a benign verdict from WildFire when viewing the artifacts associated with the incident. Which configuration can be enabled in the Malware profile for this outcome without any additional manual effort from an administrator?
The hash of the same file now shows a benign verdict from WildFire when viewing the artifacts associated with the incident. Which configuration can be enabled in the Malware profile for this outcome without any additional manual effort from an administrator?
Question 40
A security analyst is using Cortex XDR to analyze web server logs from an Apache server and wants to build a parsing rule to structure the incoming JSON-formatted logs, with the intent to extract specific fields.
Based on the log image below, which JSON function should be used to extract remote_ip, scanned_ip, and source_log fields?

Based on the log image below, which JSON function should be used to extract remote_ip, scanned_ip, and source_log fields?

