Palo_Alto_Networks
SECOPS-PRO · Question #4
A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating
The correct answer is D. Analytics. The Analytics component correlates endpoint data and firewall logs to detect complex attack patterns and suspicious activity.
Logging and Monitoring
Question
A customer is investigating a security incident in which unusual network traffic is observed and a malicious process is identified on an endpoint. Which Cortex XDR capability assists with correlating firewall network logs and endpoint data in this environment?
Options
- ALog stitching
- BUser authentication management
- CIndicator of compromise (IOC) rule
- DAnalytics
How the community answered
(38 responses)- A16% (6)
- B3% (1)
- C5% (2)
- D76% (29)
Explanation
The Analytics component correlates endpoint data and firewall logs to detect complex attack patterns and suspicious activity.
Topics
#Cortex XDR#log stitching#firewall logs#endpoint correlation
Community Discussion
No community discussion yet for this question.