A. To manage multiple Cortex XSOAR tenants
B. To provide a user interface for security analysts
C. To execute playbooks, scripts, commands, and integrations
D. To store and manage incident data, remediation plans, and documentation
A. RADIUS
B. Secure Shell (SSH)
C. Customer Support Portal (CSP)
D. SAML
A. attack threat intelligence tag
B. OS
C. quarantine status
D. Domain/workgroup membership
E. hostname
A. It automatically runs a copilot playbook to troubleshoot and resolve ingestion issues.
B. The tenant's compute units consumption will change dramatically, indicating a collection issue.
C. The Data Ingestion Health page identifies deviations from normal patterns of log collection
D. The Cortex XSIAM Command Center dashboard will display a red icon if a data source is having issues.
A. number of VM-Series NGFW
B. number of endpoints
C. logs per second
D. number of days
A. 10 GB
B. 1 TB
C. 10 TB
D. 100 GB
A. the chain's alert initiator
B. the relevant shell
C. the adversary's remote process
D. the causality group owner
A. Security Event
B. Correlation
C. Analytics
D. HIP
A. Can be used separately as an engine, only if connected to the Demisto Server directly
B. It must have port 443 open to allow the Demisto Server to establish a connection
C. Must be in a Load-Balancing group with at least another 3 members
D. Cannot be used separately and does not appear in the in the engines drop-down menu when configuring an integration instance
A. incorrect server URL
B. incorrect Username and Password
C. incorrect appliance port
D. incorrect instance name