Question 81
When a newly installed agent is not reporting telemetry to Cortex XSIAM, which two steps should you check first? (Choose two)
Question 82
An XSIAM engineer is tasked with optimizing a correlation rule that triggers on 'Multiple Failed Login Attempts followed by Successful Login from a New Device'. This rule is generating an excessive number of alerts for legitimate user password resets. Which of the following modifications to the XSIAM correlation rule logic would best optimize its performance and accuracy while minimizing false positives for this specific scenario?
Question 83
An organization is deploying a new web application and wants to ensure robust detection of common web-based attacks using XSIAM.
They have observed several attempts of SQL Injection and Cross-Site Scripting (XSS) during pre-production testing. To optimize their detection content, which of the following XSIAM content management strategies would be most effective for creating high-fidelity detection rules for these attack types, leveraging both IOCs and BIOCs?
Question 84
A Cortex XSIAM tenant is experiencing intermittent data ingestion failures from a critical endpoint protection platform (EPP) integration. The integration status in XSIAM UI shows 'Connected', but no new security events are appearing in the 'All Incidents' view for the past 2 hours. Checking the EPP's native console confirms events are being generated. Which of the following is the MOST LIKELY initial step to diagnose this issue, considering minimal disruption?
Question 85
A vulnerability analyst asks a Cortex XSIAM engineer to identify assets vulnerable to newly reported zero- day CVE affecting the "ai_app" application and versions 12.1, 12.2, 12.4, and 12.5.
Which XQL query will provide the required result?
