In incident-related widgets, how would you filter the display to only show incidents that were ''starred''?
Let's briefly discuss the other options to provide a comprehensive explanation:
In conclusion, clicking the star in the widget is the simplest and easiest way to filter the display to only show incidents that were ''starred''. By using this feature, you can quickly identify and focus on the most critical or relevant incidents in your environment.
Which built-in dashboard would be the best option for an executive, if they were looking for the Mean Time to Resolution (MTTR) metric?
The Incident Management Dashboard provides a high-level overview of the incident response process, including the Mean Time to Resolution (MTTR) metric. This metric measures the average time it takes to resolve an incident from the moment it is created to the moment it is closed. The dashboard also shows the number of incidents by status, severity, and assigned analyst, as well as the top alerts by category, source, and destination. The Incident Management Dashboard is designed for executives and managers who want to monitor the performance and efficiency of their security teams.Reference: [PCDRA Study Guide], page 18.
To create a BIOC rule with XQL query you must at a minimum filter on which field in order for it to be a valid BIOC rule?
To create a BIOC rule with XQL query, you must at a minimum filter on theevent_typefield in order for it to be a valid BIOC rule. The event_type field indicates the type of event that triggered the alert, such as PROCESS, FILE, REGISTRY, NETWORK, or USER_ACCOUNT. Filtering on this field helps you narrow down the scope of your query and focus on the relevant events for your use case. Other fields, such as causality_chain, endpoint_name, threat_event, are optional and can be used to further refine your query or display additional information in the alert.Reference:
Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) Study Guide, page 9
Palo Alto Networks Cortex XDR Documentation, BIOC Rule Query Syntax
Which two types of exception profiles you can create in Cortex XDR? (Choose two.)
Cortex XDR allows you to create two types of exception profiles: agent exception profiles and global exception profiles. Agent exception profiles apply to specific endpoints that are assigned to the profile. Global exception profiles apply to all endpoints in your network. You can use exception profiles to configure different types of exceptions, such as process exceptions, support exceptions, behavioral threat protection rule exceptions, local analysis rules exceptions, advanced analysis exceptions, or digital signer exceptions. Exception profiles help you fine-tune the security policies for your endpoints and reduce false positives.Reference:
Create an Agent Exception Profile
Create a Global Exception Profile
What license would be required for ingesting external logs from various vendors?
To ingest external logs from various vendors, you need a Cortex XDR Pro per TB license. This license allows you to collect and analyze logs from Palo Alto Networks and third-party sources, such as firewalls, proxies, endpoints, cloud services, and more. You can use the Log Forwarding app to forward logs from the Logging Service to an external syslog receiver. The Cortex XDR Pro per Endpoint license only supports logs from Cortex XDR agents installed on endpoints. The Cortex XDR Vendor Agnostic Pro and Cortex XDR Cloud per Host licenses do not exist.Reference:
Features by Cortex XDR License Type
Log Forwarding App for Cortex XDR Analytics
Alonzo
5 days agoKristal
12 days agoTomoko
20 days agoDean
27 days agoCassi
1 month agoStaci
1 month agoMalinda
2 months agoShalon
2 months agoNichelle
2 months agoTwila
2 months agoCarmen
3 months agoBen
3 months agoSue
3 months agoMichael
3 months agoChu
4 months agoAlton
4 months agoTish
4 months agoFreeman
4 months agoTien
5 months agoLilli
5 months agoMarget
5 months agoAretha
5 months agoEmeline
6 months agoFredric
6 months agoEun
6 months agoFrank
6 months agoMirta
7 months agoLonny
7 months agoRoxane
7 months agoCarolann
7 months agoCaprice
9 months agoTanja
9 months agoBettina
10 months agoLino
10 months agoDevorah
11 months agoBlondell
11 months agoShannon
12 months agoTiera
1 year agoKrissy
1 year agoViola
1 year agoMiesha
1 year agoLynsey
1 year agoRaylene
1 year agoLavonna
1 year agoAnnice
1 year agoVenita
1 year agoAvery
1 year agoMaia
1 year agoLezlie
1 year agoNguyet
1 year agoRenato
1 year agoSabrina
1 year agoAmira
1 year agoBreana
1 year agoLauran
1 year agoMalika
1 year agoDemetra
1 year agoAleta
1 year agoMarnie
1 year agoSabra
1 year agoKaycee
2 years agoYoulanda
2 years agoJess
2 years agoRhea
2 years agoColetta
2 years agoElmer
2 years agoVirgilio
2 years agoCiara
2 years agoAlbina
2 years agoAleta
2 years agoTarra
2 years agoJoaquin
2 years agoGenevive
2 years agoDudley
2 years agoRebbecca
2 years agoFrance
2 years agoJeniffer
2 years ago