Which action is required to enable use of a custom script in an alert layout?
To use a custom script in an alert layout, the script must be tagged with 'general-purpose-dynamic-section', then a general purpose dynamic section is added to the layout, and finally the section settings are edited to attach the automation script. This ensures the script executes and displays results dynamically within the alert layout.
An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file.
Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?
An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file.
Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?
The correct approach is to install a Broker VM in the environment and configure its CSV Collector applet to ingest the .csv log files directly from the Ubuntu server. This enables secure ingestion of custom application logs into Cortex XSIAM without modifying the application or requiring an XDR agent on the server.
A Behavioral Threat Protection (BTP) alert is triggered with an action of "Prevented (Blocked)" on one of several application servers running Windows Server 2022. The investigation determines the involved processes to be legitimate core OS binaries, and the description from the triggered BTP rule is an acceptable risk for the company to allow the same activity in the future.
This type of activity is only expected on the endpoints that are members of the endpoint group "AppServers," which already has a separate prevention policy rule with an exceptions profile named "Exceptions-AppServers" and a malware profile named "Malware-AppServers."
The CGO that was terminated has the following properties:
SHA256: eb71ea69dd19f728ab9240565e8c7efb59821e19e3788e289301e1e74940c208
File path: C:\Windows\System32\cmd.exe
Digital Signer: Microsoft Corporation
How should the exception be created so that it is scoped as narrowly as possible to minimize the security gap?
The most secure approach is to create a Disable Prevention Rule via Exceptions Configuration, scoped specifically to the Exceptions-AppServers profile. This rule should include the hash (SHA256), signer (Microsoft Corporation), and file path (C:\Windows\System32\cmd.exe). This ensures the exception is applied only to the trusted, legitimate process on the AppServers group while minimizing the security gap.
A file for a support exception that needs to be updated locally on a Linux endpoint has been supplied.
Which cytool command will upload this support exception file to the endpoint?
The correct command is cytool import suex -path </local/file/path>, which imports a supplied support exception (suex) file onto a Linux endpoint, ensuring the exception is applied locally.
How must Cloud Identity Engine be deployed and activated on Cortex XSIAM?
Cloud Identity Engine must be deployed in the same region as Cortex XSIAM to ensure compliance and proper data handling. Once integrated, the ingestion can be verified by checking the pan_dss_raw dataset, which records the raw directory synchronization logs.
Joshua Garcia
16 days agoJeffrey Rogers
22 days agoOlivia Allen
2 months agoRobert Carter
2 months agoBrenda Harris
2 months agoMichelle Scott
3 months agoRichard Hernandez
3 months agoBarbara Morris
2 months agoGary Evans
2 months agoJoseph Rogers
2 months agoRoselle
3 months agoHarris
4 months agoSonia
4 months agoAdelaide
4 months agoLeonida
4 months agoDelila
5 months agoAmie
5 months agoDominga
5 months agoKenia
5 months agoFannie
6 months agoLuisa
6 months agoNiesha
6 months agoThad
6 months agoMargart
7 months agoFredric
7 months agoHolley
7 months agoWillard
7 months agoNicolette
8 months agoVallie
8 months agoOdette
8 months agoDorsey
8 months agoJustine
9 months agoVeronika
9 months ago