Question 1
[Cortex XDR Agent Configuration]
How are dynamic endpoint groups created and managed in Cortex XDR?
[Cortex XDR Agent Configuration]
How are dynamic endpoint groups created and managed in Cortex XDR?
[Detection Engineering]
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)
[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
[Detection Engineering]
During a recent internal purple team exercise, the following recommendation is given to the detection engineering team: Detect and prevent command line invocation of Python on Windows endpoints by non-technical business units. Which rule type should be implemented?
[Post-Deployment Management and Configuration]
Using the Cortex XDR console, how can additional network access be allowed from a set of IP addresses to an isolated endpoint?
[Detection Engineering]
Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?
[Detection Engineering]
A correlation rule is created to detect potential insider threats by correlating user login events from one dataset with file access events from another dataset. The rule must retain all user login events, even if there are no matching file access events, to ensure no login activity is missed.
text
Copy
dataset = x
| join (dataset = y)
Which type of join is required to maintain all records from dataset x, even if there are no matching events from dataset y?