Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

A.

#Bob

B.

/invite Bob

C.

@Bob

D.

!invite Bob

In the DBotScore context field, which context key would differentiate between multiple entries for the same indicator in a multi-TIP environment?

A.

Vendor

B.

Type

C.

Using

D.

Brand

Which two log types should be configured for firewall forwarding to the Cortex Data Lake for use by Cortex XDR? (Choose two)

A.

Security Event

B.

HIP

C.

Correlation

D.

Analytics

What is the difference between an exception and an exclusion?

A.

An exception is based on rules and exclusions are on alerts

B.

An exclusion is based on rules and exceptions are based on alerts.

C.

An exception does not exist

D.

An exclusion does not exist

How does Cortex XSOAR automation save time when a phishing incident occurs?

A.

By developing an integration.

B.

By responding to management with risk scores

C.

By purging unopened phishing email from user mailboxes

D.

By emailing staff to inform them of phishing attack in advance

In addition to incident volume, which four critical factors must be evaluated to determine effectiveness and ROI on cybersecurity planning and technology?

A.

Analyst, training costs, duplicated, false positives

B.

People, staffing costs, duplicates, false positives

C.

People, security controls, mean time to detect, false positives

D.

Standard operating procedures, staffing costs, duplicates, mean time to respond

Which deployment type supports installation of an engine on Windows, Mac OS. and Linux?

A.

RPM

B.

SH

C.

DEB

D.

ZIP

What is used to display only file entries in a War Room?

A.

files from War Room CLI WW

B.

incident files section in layout builder

C.

files and attachments filters

D.

/files from War Room CLI

An EDR project was initiated by a CISO. Which resource will likely have the most heavy influence on the project?

A.

desktop engineer

B.

SOC manager

C.

SOC analyst IT

D.

operations manager

Which task allows the playbook to follow different paths based on specific conditions?

A.

Conditional

B.

Automation

C.

Manual

D.

Parallel