
POST TEST CORTEX XDR
Authored by Mohammad Nugroho
Other
Professional Development
Used 2+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
10 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Which license is required to import external logs from different vendors?
Cortex XDR Pro per Endpoint
Cortex XDR Vendor Pro Per Host
Cortex XDR Pro Per TB
Cortex XDR Cloud Per Host
2.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
When viewing events directly, what is the value of the 'assigned to' field for a new event just reported to Cortex?
New
New Incident
Unassigned
Pending
3.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
In incident-related widgets, how would you filter the display to only show incidents that were “starred”?
Create a custom XQL widget
Click the star in the widget
This is not currently supported
Create a custom report and filter on starred incidents
4.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Where would you view the WildFire report in an incident?
In the WildFire Analysis report at related Artifacts in the incidents details page
Under Response --> Action Center
under the gear icon --> Agent Audit Logs
on the HUB page at apps paloaltonetwork
5.
MULTIPLE SELECT QUESTION
1 min • 1 pt
What are the three actions available from the Cortex XDR interface?
Dashboard & Reports
Endpoint
Alert
Incident Response
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the function of the Action Center?
This is used to create a profiles and policy rules
This is used to track progress of all actions initiated from various points on the interface.
This is used to view a causality chain
This is used to manage an incident
7.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
False or True: Cortex XDR supports two types of rules, namely IOC and BIOC rules.
TRUE
FALSE
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?