When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)

When selecting multiple Incidents at a time, what options are available from the menu when a user right-clicks the incidents? (Choose two.)A . Assign incidents to an analyst in bulk.B . Change the status of multiple incidents.C . Investigate several Incidents at once.D . Delete the selected Incidents. View Answer Answer: A,B Explanation: Reference:...

To create a BIOC rule with XQL query you must at a minimum filter on which field inorder for it to be a valid BIOC rule?

To create a BIOC rule with XQL query you must at a minimum filter on which field inorder for it to be a valid BIOC rule?A . causality_chainB . endpoint_nameC . threat_eventD . event_type View Answer Answer: D Explanation: Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html...

What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)

What are two purposes of “Respond to Malicious Causality Chains” in a Cortex XDR Windows Malware profile? (Choose two.)A . Automatically close the connections involved in malicious traffic.B . Automatically kill the processes involved in malicious activity.C . Automatically terminate the threads involved in malicious activity.D . Automaticallyblock the IP addresses involved in malicious...

When using the “File Search and Destroy” feature, which of the following search hash type is supported?

When using the “File Search and Destroy” feature, which of the following search hash type is supported?A . SHA256 hash of the fileB . AES256 hash of the fileC . MD5 hash of the fileD . SHA1 hash of the file View Answer Answer: A Explanation: Reference: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/search-file-and-destroy.html...