Palo_Alto_Networks
XSIAM-ENGINEER · Question #48
XSIAM-ENGINEER Question #48: Real Exam Question with Answer & Explanation
Sign in or unlock XSIAM-ENGINEER to reveal the answer and full explanation for question #48. The question stem and answer options stay visible for context.
Question
An engineer wants to onboard data from a third-party vendor's firewall. There is no content pack available for it, so the engineer creates custom data source integration and parsing rules to generate a dataset with the firewall data. How can the analytics capabilities of Cortex XSIAM be used on the data?
Options
- ACreate a behavioral indicator of compromise (BIOC) rule on the network fields (source IP, source
- BCreate a data model rule with network fields mapped (source IP, source port, target IP, target port,
- CCreate a correlation rule on the network fields (source IP, source port, target IP, target port, IP
- DCreate a parsing rule and ensure the network fields exist (source IP, source port, target IP, target
Unlock XSIAM-ENGINEER to see the answer
You've previewed enough free XSIAM-ENGINEER questions. Unlock XSIAM-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.