nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #4

A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating

The correct answer is D. Analytics. The Analytics component correlates endpoint data and firewall logs to detect complex attack patterns and suspicious activity.

Logging and Monitoring

Question

A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?

Options

  • ALog stitching
  • BUser authentication management
  • CIndicator of compromise (IOC) rule
  • DAnalytics

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    3% (1)
  • C
    5% (2)
  • D
    76% (29)

Explanation

The Analytics component correlates endpoint data and firewall logs to detect complex attack patterns and suspicious activity.

Topics

#Cortex XDR#log stitching#firewall logs#endpoint correlation

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice