Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which endpoint(s) data will be accessible?

A.

E1 only

B.

E2 only

C.

E1, E2, and E3

D.

E1, E2, E3, and E4

An administrator wants to employ reusable rules within custom parsing rules to apply consistent log field extraction across multiple data sources. Which section of the parsing rule should the administrator use to define those reusable rules in Cortex XDR?

A.

RULE

B.

INGEST

C.

FILTER

D.

CONST

A new parsing rule is created, and during testing and verification, all the logs for which field data is to be parsed out are missing. All the other logs from this data source appear as expected. What may be the cause of this behavior?

A.

The Broker VM is offline

B.

The parsing rule corrupted the database

C.

The filter stage is dropping the logs

D.

The XDR Collector is dropping the logs

How can a customer ingest additional events from a Windows DHCP server into Cortex XDR with minimal configuration?

A.

Activate Windows Event Collector (WEC)

B.

Install the XDR Collector

C.

Enable HTTP collector integration

D.

Install the Cortex XDR agent

What will be the output of the function below?

L_TRIM("a* aapple", "a")

A.

' aapple'

B.

" aapple"

C.

"pple"

D.

" aapple-"