XSIAM-ENGINEER · Question #37
Before updating the XDR Collector, what should an administrator verify to avoid disruption?
The correct answer is C. The health and connectivity status of the collector. Verifying the health and connectivity status of the XDR Collector before an update is essential because updating a collector that is already degraded or disconnected can compound the problem - leaving gaps in telemetry collection and making it impossible to distinguish…
Question
Before updating the XDR Collector, what should an administrator verify to avoid disruption?
Options
- AThe number of ingestion pipelines
- BThat the device is marked as 'untrusted'
- CThe health and connectivity status of the collector
- DThe number of playbooks running
How the community answered
(47 responses)- A4% (2)
- C94% (44)
- D2% (1)
Explanation
Verifying the health and connectivity status of the XDR Collector before an update is essential because updating a collector that is already degraded or disconnected can compound the problem - leaving gaps in telemetry collection and making it impossible to distinguish pre-existing issues from update-caused ones. A healthy, connected collector ensures a clean baseline so any post-update disruption is immediately attributable to the update itself.
Why the distractors are wrong:
- A (ingestion pipelines): Pipeline count doesn't affect whether an update is safe to perform; pipelines resume after a successful update regardless of how many there are.
- B (untrusted device): Marking a device as "untrusted" is a security posture decision, not a pre-update prerequisite - an untrusted device shouldn't be receiving updates at all.
- D (running playbooks): Playbooks operate at the SOAR/orchestration layer, not at the collector level; their count has no bearing on update safety.
Memory tip: Think of it like updating a server - you'd never patch a box that's already showing red on the monitoring dashboard. "Check health before you change" maps directly to verifying collector health and connectivity before any maintenance action.
Topics
Community Discussion
No community discussion yet for this question.