Question 116
An XSIAM engineer is observing that a specific custom log source, which frequently contains corrupted or malformed log entries (e.g., incomplete JSON, truncated strings), is causing downstream XQL queries to fail or return inconsistent results, even though the Data Flow parser is designed to handle common cases. This impacts the reliability of security analytics. Which combination of Data Flow practices would best mitigate the impact of these malformed entries on data quality and query reliability, while ensuring valid data is still processed?
Question 117
A security architect is planning to deploy a specialized security use case using a Marketplace content pack in Cortex XSIAM.
Which set of components is bundled within these content packs for end-to-end automation and detection?
Question 118
Consider an XSIAM environment where network flow data from a Palo Alto Networks NGFW is being ingested. After a recent firewall upgrade, the 'app_id' field in XSIAM is showing 'unknown' for many previously correctly identified applications. Raw logs viewed on the firewall confirm the 'app_id' is present and correct. Which of the following is the most probable cause?
Question 119
During a planned XDR Agent update rollout for a critical server group, a pre-check script fails on a significant number of Windows servers with the error 'Pending reboot detected. Agent update blocked.' The XDR Agent update policy for this group is configured with 'Allow updates with pending reboot: No'. You need to proceed with the update as quickly as possible without immediate reboots. Which of the following approaches is the most efficient and least disruptive to achieve this, assuming the pending reboots are not critical OS updates?

